Summary
Overview
Work History
Education
Skills
Certification
Timeline

Sameer Goyal

Rivian Automotive LLC
Chicago
1
Certification
10
years of professional experience

Incident response professional with 10+ years of experience investigating complex security incidents in large enterprise environments. Experienced in threat hunting, digital forensics, malware analysis, containment, root cause analysis, and recovery, as well as building detections, response automation, playbooks, on-call workflows, and program metrics.

Work History

Incident Response Lead

1 Year 7 Months
Rivian Automotive LLC | 02.2025 - Current
  • Lead complex security investigations and coordinate containment, recovery, and root cause analysis; direct technical response and communicate findings to Engineering, IT, Legal, Privacy, and business stakeholders.
  • Own the enterprise incident response program, including playbooks, severity and escalation procedures, responder readiness, and post-incident reviews.
  • Built automated end to end incident-management and on-call system to automate incident declaration, responder engagement, escalation, stakeholder communications, and post-incident follow-up.
  • Develop, test, tune, and maintain detections through GitLab-based Detection-as-Code workflows, turning attacker behaviors and investigation findings into version-controlled detection logic.
  • Build investigation and response workflows using Torq, Python, PowerShell, and APIs to automate alert enrichment and repetitive investigative and containment tasks.
  • Developed incident-response reporting for MTTD, MTTC, MTTR, severity drift, and false-positive rates to evaluate response performance and prioritize program improvements.
  • Translate threat intelligence, post-incident findings, and tabletop exercises into threat hunts, detection updates, logging requirements, and playbook improvements.

Senior Incident Response Engineer

2 Years 9 Months
Rivian Automotive LLC | 05.2022 - 02.2025
  • Led enterprise investigations using EDR, SIEM, cloud, and identity telemetry to reconstruct attacker activity, establish scope, and guide containment and remediation.
  • Handled and led investigation for cybersecurity end to end from identification to post incident actions.
  • Developed behavioral detections and hunting queries from attacker TTPs and investigation findings; identified gaps in logging and monitoring and worked with engineering teams to close them.
  • Built workflows to enrich alerts and correlate investigative data across security tools.
  • Partnered with Security Engineering, Infrastructure, IT, Legal, and Privacy to address control weaknesses and translate investigation findings into technical remediation and response procedures.

Senior Incident Response Analyst

2 Years 10 Months
Moody's Investor Services | 07.2019 - 05.2022
  • Used CrowdStrike Falcon as the primary enterprise EDR for endpoint investigations, threat hunting, and incident response across a global organization.
  • Built an automated forensic collection system using CrowdStrike Falcon to deploy KAPE on demand and retrieve endpoint artifacts for case-specific investigations.
  • Performed host, memory, malware, and network analysis using Falcon telemetry, SIEM data, Volatility, Wireshark, and forensic artifacts to establish root cause and incident scope.
  • Refined detection logic, investigative queries, runbooks, and SOAR workflows using adversary TTPs and recurring investigation findings.
  • Coordinated sensitive investigations with Legal, HR, Compliance, IT, and Infrastructure, communicating findings and supporting response decisions.

Information Security Analyst

2 Years 10 Months
Morgan Stanley | 08.2016 - 06.2019
  • Investigated endpoint, network, email, and perimeter-security alerts, correlating SIEM and security-tool telemetry to validate malicious activity and determine scope.
  • Performed malware analysis and host investigations to identify execution behavior, persistence, and indicators of compromise; incorporated findings into detection indicators and SOC procedures.
  • Trained and mentored Level 1 analysts on alert triage, malware investigation, and escalation procedures.

Education

M.S. - Cyber Risk & Strategy

New York University | 05-2021
GPA: 3.73/4.00

M.S. - Computer Science (Information Assurance)

Arizona State University | 05-2016
GPA: 3.81/4.00

Skills

Incident Response & Investigation: Incident Response
Threat Hunting
Digital Forensics
Malware Analysis
Containment
Root Cause Analysis
Detection Engineering: Detection Development & Tuning
Detection-as-Code
SIEM/XDR Operations
MITRE ATT&CK
Threat Intelligence
Security & Forensic Tools: CrowdStrike Falcon
Microsoft Defender
Splunk
Databricks
KAPE
Volatility
Wireshark
Automation & Orchestration: Python
PowerShell
APIs
GitLab
Torq
Rootly
OpenCTI
Cloud & Systems: AWS
Azure
GCP
Windows
Linux
macOS
Response Operations: Incident Playbooks
On-Call & Escalation Workflows
Stakeholder Communications
Tabletop Exercises
Post-Incident Reviews
Operational Metrics

Certification

  • SANS GCFE
  • SANS GCFA

Timeline

Incident Response Lead

Rivian Automotive LLC
02.2025 - CurrentRead More

Senior Incident Response Engineer

Rivian Automotive LLC
05.2022 - 02.2025Read More

Senior Incident Response Analyst

Moody's Investor Services
07.2019 - 05.2022Read More

Information Security Analyst

Morgan Stanley
08.2016 - 06.2019Read More

Arizona State University

M.S. from Computer Science (Information Assurance)
Read More

New York University

M.S. from Cyber Risk & Strategy
Read More
Sameer Goyal