Security Operations Engineer
CurrentEnterprise Security Engineering • Automation - Creating Python scripts linked to APIs for AWS, First Base, Kandji, Tanium, Carbon Black, Tenable, Jira, and Slack.• AWS / Terraform – Modified and created IAM objects, permissions, and references via Terraform.• Incident Response – Responding to incidents, collecting threat data, identifying root causes, reviewing and closing misconfiguration gaps, writing formal reports, and communicating to stakeholders. • Panther (SIEM) – Reviewing and filtering alerts, utilizing SQL for data presentation. • Google Workspace – Responding to incidents and overhauling configuration refinement.• Elasticsearch and Grafana (SIEM) – Created fully custom dashboards, alerts, and queries. • Carbon Black (AV) – Configuring policies, responding to alerts, and excluding false positives from watch lists. • Prisma Access (SASE) – Reviewing, approving, and recommending firewall implementations, troubleshooting end user issues. • Tanium (MDM) – Led RFP engagement to purchase, acting as secondary for deployments and patches. Studying Tanium Essentials course. • Secureworks (MSSP) – Coordinating with SOC agents and account management, defining alerts, threat hunting, utilizing their SIEM tooling. • Flashpoint (OSINT) – Led RFP engagement to purchase, gathered and presented threat intel reports, established and investigated alerts, pitched further tooling to stakeholders. • Further hands on and input with Okta, Tenable, Kandji, Airwatch, Jira, Confluence, First Base, TeamViewer, and many other tools. Project Management and Leadership • Presented team progress and planning a C-level tech committee. • Oversaw, organized, and provided input to multi-team projects, ensuring timely and thorough completion. • Took on a leadership style role in the long absence of a manager, leading conversations and decisions on critical matters while empowering colleagues to provide their own input and become the best version of themselves.