Associate Director, Security Product Owner (Azure Sentinel Sme)
Current-Acting SME for any use cases related to Azure Sentinel.-Lead migration from Splunk to Sentinel-Plan, POC and implement SOAR (Playbooks, Workbooks, Notebooks)-Facilitate training and education on the benefits of MSFT Sentinel.-Demonstrate SME of KQL by utilizing functions, writing hunting queries and analytical queries.-Gather use cases on current processes that can be automated using MSFT Sentinel's SOAR capabilities.-Utilize Logic Apps for automating KQL reports, importing 3rd party data to Sentinel using the Sentinel API and completing other use cases.-Manage multiple Linux VMs for Syslog/CEF. Demonstrate advanced knowledge of Linux (Ubuntu) -Utilize CI/CD to manage multiple Sentinel instances, project management and change control.-Maintain up-to-date knowledge on changes coming to Sentinel and how those changes may impact the solution.-Secure all Sentinel instances utilizing tools such as RBAC.-Design Security Data Pipelines that eliminate false positives and create actionable data points.-Maintain reporting that utilizes Power BI for creating dashboards and enriching data. Make sure the data is clear, actionable and easily readable.-Make sure all customer requirements are met and customer satisfaction stays at 100%.-Assist with developing the company's AI strategy for quarter 4 implementation.