Skip to content
Hack InvasionCybersecurity Knowledge Hub

About

Investigation · Leadership · Continuous learning

Amit Vijayan

Cybersecurity professional focused on incident response, threat hunting and security operations.

I help teams connect technical evidence with clear decisions. My work spans investigating security incidents, understanding attacker behaviour and strengthening the processes that help organisations detect and respond to threats.

Across roles at Morgan Stanley, Microsoft, PwC and Paysafe, I have combined hands-on analysis with response coordination, detection development and analyst mentoring.

Portrait of Amit Vijayan, cybersecurity professional and author of Hack Invasion
8+ yearsExperience across cybersecurity operations, detection and response
Master’s degreeInformation Systems Security Engineering · Concordia University
Montréal, QuébecProfessional experience across financial services, technology and consulting

How I approach security

My background brings together incident response, digital forensics, threat intelligence, insider-risk investigations and SOC operations. I am interested in how these disciplines support one another: intelligence gives an investigation context, endpoint and network evidence help test a hypothesis, and a clear response process turns findings into action.

Investigate with context

I look beyond an isolated alert to understand the sequence of events, the affected environment and the business impact. My experience includes endpoint investigations, SIEM analysis, threat hunting and intelligence reporting.

Make response repeatable

I develop playbooks, runbooks and investigation guidance that help teams work consistently. Response coordination and clear communication matter alongside the technical work.

Build analyst capability

Mentoring, quality reviews and practical training have been recurring parts of my roles. I value guidance that helps analysts explain their reasoning and make defensible escalation decisions.

Improve the workflow

My work has included security automation and AI copilot agents for incident-response workstreams. I focus on opportunities to reduce repetitive effort and improve the consistency of operational processes.

Professional journey

From day-to-day security monitoring to incident-response and detection leadership. Open a role to explore its focus.

Incident Response and Operations Lead · Morgan StanleySeptember 2023 – March 2026 · Montréal

Focused on incident response and recovery, insider risk, threat hunting and the operational readiness of security teams.

  • Led incident-response and recovery activities, with playbooks supporting collaboration across security, HR and legal teams.
  • Developed detection and response guidance and shared reusable hunting approaches with engineers, SIEM specialists and SOC analysts.
  • Produced threat advisories, supported vendor-breach response programmes and mentored analysts through investigation quality reviews.
  • Developed AI copilot agents to support incident-response workstreams and SOC workflows.
Incident responseInsider riskThreat huntingAnalyst mentoring
Incident Response and Detection Lead · MicrosoftApril 2022 – September 2023 · Toronto

Worked across detection development, threat intelligence and incident-response delivery.

  • Developed monitoring scenarios, detection-engineering playbooks and operational runbooks.
  • Prepared and presented threat-intelligence advisories to support client risk awareness and mitigation.
  • Supported Nation State Notification delivery during DART engagements and investigated insider-threat activity.
  • Collaborated with technical and business stakeholders and trained a vendor team in investigation workflows.
Detection engineeringThreat intelligenceIncident prevention
Cyber Security and Privacy Senior Associate · PwCJanuary 2020 – April 2022 · Toronto

Supported client security operations through incident response, threat hunting and improvements to monitoring and investigation processes.

  • Developed use-case designs, investigation playbooks and standard operating procedures.
  • Investigated alerts and tuned monitoring use cases to improve the relevance of detections.
  • Conducted hunts for indicators of compromise and attacker tactics, techniques and procedures.
  • Supported client engagements, escalation handling and training for first-line analysts.
ConsultingSIEM & XDRHuntingOperational delivery
Security Operations Analyst · PaysafeJune 2018 – October 2019 · Montréal

Built practical experience in security monitoring, access management and incident triage in a payments environment.

  • Monitored DLP and antivirus alerts and triaged malware incidents.
  • Supported identity and access management and audit-related security activities.
  • Collaborated on internal phishing-awareness campaigns and improved incident-ticket workflows.
Security monitoringIAMDLPAwareness

Technical expertise

My experience spans the tools and investigative methods used to understand threats and coordinate a response. Expand a discipline for examples.

Digital forensics & incident response

Endpoint investigation, memory analysis, timeline reconstruction and network analysis. Tools in my experience include Volatility, Autopsy, The Sleuth Kit and Wireshark.

Detection, SIEM & endpoint security

Security analytics and investigation across platforms including Splunk Enterprise Security, ArcSight, LogRhythm and Microsoft Sentinel, with endpoint experience spanning CrowdStrike Falcon, Cortex XDR, Carbon Black and SentinelOne.

Threat intelligence & hunting

IOC investigation, mapping observed behaviour to MITRE ATT&CK, developing hunting approaches and preparing tactical and strategic intelligence reports. My background includes MISP, ThreatConnect and OSINT research.

Insider risk, response coordination & automation

Insider-threat investigations, privacy-breach coordination, response playbooks and operational automation. I have worked with security and business stakeholders to support consistent incident handling and communication.

Education & continued learning

Concordia University

Master’s degree in Information Systems Security Engineering
2016–2018 · Montréal

Rayat and Bahra University

Bachelor’s degree in Computer Science Engineering
2011–2015

Certification background

My certification background includes eJPT, CEH v11 and Microsoft security and cloud exams SC-100, SC-200, SC-900, AZ-500 and AZ-900.

Listed from my professional résumé; current credential status and verification can be discussed directly.

Research and practical projects
  • Network security assessment: academic research into network controls and resilience through authorised testing.
  • Malware analysis: isolated-lab research into malicious behaviour, obfuscated scripts and detection opportunities using tools such as FLARE VM, REMnux and CyberChef.
  • Security awareness: experience designing and delivering phishing simulations and targeted learning activities.
  • Usability research: a cognitive walkthrough exploring software installation on Ubuntu.
Read the Ubuntu usability project →

Beyond the work

Community service is part of my professional and personal interests. My volunteer background includes blood-donation initiatives with Rotary Blood Bank, outreach through the World Sikh Organization, and OSINT volunteering supporting Trace Labs and the Innocent Lives Foundation.

Why I write Hack Invasion

I created Hack Invasion as a place to share technical learning. Today, its focus is practical, responsible and defensive cybersecurity: incident response, threat hunting, threat intelligence, product security and SOC operations.

The archive also preserves earlier projects and learning notes. Older material needs to be read in its historical context; my aim is to build a useful resource that makes complex security concepts easier to understand and apply responsibly.

All security testing discussed here should be performed only on systems you own or are explicitly authorised to assess. Views expressed are my own.


EmoticonEmoticon