Cyber Security Analyst
Current Engineered and optimised detection use cases for various tools, including SIEM (Splunk ES), EDR (CB & MDR), and others. Collaborated with the CD-SOC team to enhance security posture by supporting investigations and identifying new IOCs and TTPs to improve threat detection and prevention. Coordinated with CD-CTI and IT teams to upgrade detection capabilities, policies, and log visibility. Applied expertise in the cyber kill-chain and MITRE ATT&CK framework to refine detection methods. Led the development of a SOAR playbook as the primary point of contact (SPOC). Utilised comprehensive knowledge of operating systems (Windows, Linux) and networking concepts to bolster security infrastructure. Proactively refined detection rules, policies, and signatures, generating significant time and cost efficiencies. Managed and advanced information security documentation and processes across the Cyber Defense organisation. Leveraged KQL, Python, and PowerShell skills to automate security tasks and streamline operations. Excelled as an individual contributor and in collaborative team settings to drive security initiatives forward.