Analytic Siem Consultant
Current- LogRhythm SIEM Administration and Analytics– Provided regular consultation to customers from a widevariety of industries to support LogRhythm SIEM operational management. Areas of consultation included UseCase/Module.
- Documentation and Knowledge Transfer – Created and maintained individual documentation of SIEMactions, changes, AIE rule management, and helped define security requirements to satisfy log source needs asapplied to AIE..
- Environmental Work – Provided health checks, Global Log Processing Rules, Risk Based Priority enablement,and tuning of AI Engine performance.
- Product Coaching – Developed a Case Management with Smart Response and Playbooks lesson for coachingcustomers with best practices.
- Event Tuning – Managed event flow and creation, reviewed log sources for required use cases, includingWindows Event logs, Windows Auditing, Powershell/Command line audits, and MS Sysmon implementation.