Technical Lead Security Engineer
CurrentIn my current role, I integrate and optimise security tools within SIEM solutions, specifically Alert Logic and Microsoft Sentinel. I lead vulnerability management and enterprise-wide remediation efforts, assist SOC analysts with threat hunting and incident response using KQL/SQL and Python, and oversee PKI management as well as identity and access controls across Azure and on-premises environments. I successfully migrated our organization from Sophos to Defender XDR, setting up and maintaining Defender for endpoint, identity, and cloud protection, achieving a secure score of 85% across devices, identity, cloud, and data. Additionally, I automated remediation processes with custom scripts, SCCM, and Intune, and aligned all Windows devices with CIS v1.10.1 and STIG compliance benchmarks. My work also includes implementing Azure security controls for compliance with CIS, ISO 27001, and PCI DSS standards, enhancing email security with DKIM, DMARC, and SPF via Mimecast and Defender for O365, and enforcing data loss prevention through Varonis and Microsoft Purview with data classification and labeling. I manage mobile device security with JAMF Trust and Intune, oversee Forcepoint Web Proxy and Defender for Cloud Apps, administer Cisco Meraki switches, and lead remediation of penetration testing findings.