Security Engineer - Detection & Incident Response
- Engineered KQL detections across Microsoft Sentinel, Defender XDR, Palo Alto, and Defender for IoT telemetry.
- Developed detections for suspicious parent-child processes, cross-zone lateral movement, and anomalous ICS/OT activity.
- Validated detection fidelity using synthetic attack chains and positive, negative, and near-miss test cases.
- Performed threat hunting across endpoint activity, Windows events, firewall traffic, and ICS/OT network telemetry.
- Investigated high-severity, multi-site incidents using endpoint telemetry, firewall logs, routing data, packet captures, and Windows event logs.
- Correlated security and network evidence to establish scope, evaluate root-cause hypotheses, and direct technical escalations.
- Coordinated investigations across SOC, network, cloud, infrastructure, and site teams during complex operational incidents.
- Converted incident findings into detection improvements, post-incident analysis, troubleshooting procedures, and response playbooks.
