Senior Security Engineer
Current▪ Implement Microsoft Sentinel, tune analytics rules, and develop custom hunting queries.▪ Implement Microsoft Purview with mandatory labeling policy.▪ Coordinate Sentinel cost cutting efforts: leading to $60k/annum in savings while minimizing impact on analytics rules.▪ Correct errors, tune alerts, and automate incident handling in Microsoft Defender XDR, lowering actionable incidents by 90%.▪ Develop custom Microsoft Graph PowerShell reports utilizing a Managed Identity running Azure Automation runbooks supporting user access reviews, device audits, onboarding/departure workflows, and consolidated views on the environment.▪ Develop custom KQL enriched powershell script automating updates, pruning, backup, and data enrichment within Microsoft Cloud App Security public IP ranges.▪ Compose internal SOP for global Phased IT Deployments. Develop custom Automation Runbook using parallelization, KQL, and Microsoft Graph through Powershell, enabling region-based & department-based device groups updating daily in under 14 minutes. ▪ Develop custom report for Microsoft for Cloud Apps, enabling expedited app evaluation & communication with primary users.▪ Develop training on JIRA sprint best practices and high-level design, present training, and assist with administration.▪ Assess gaps in Vulnerability Management & Patch Management workflows, document & diagram details of current state, and provide suggested mitigations.▪ Use KQL, mgGraph, and Powershell to deliver reports that drive business conversations and decisions (e.g. ending BYOD, objective email security POC results, co-managed Intune devices, etc.). ▪ Lead investigation & mitigation of major incidents. Document incident reports with root cause and provide suggestive controls to management.▪ Evaluate and strengthen Azure Conditional Access policies.▪ Implement Defender for Cloud Apps session policies, enabling DLP & session controls on BYOD.