Senior Consultant
CurrentResponsible for leading the development of strategies, engineering conecepts, automated workflows, and the implementation of operational aspects to delivering modern application monitoring solutions for the organization.Manage Splunk environment architecture changes, design, as well as deployments such as ground up environment builds of all server roles. Assist clients in cloud migration efforts.Manage the end-to-end integration of log sources, ensuring proper parsing, event normalization, and enrichment for security monitoring.Design, configure and maintain log aggregation solutions, with a strong focus on data normalization.Implement and manage security event correlation and alerting rules to detect and respond to suspicious activities.Fine-tune and optimize log forwarding streams to avoid unnecessary noise, reduce false positives, and prioritize security-relevant dataDevelop and customize SIEM dashboards, alerts and reports to meet security monitoring needs.Develop and implement new SIEM detection correlation rules, and alerts for emerging threats and attack vectors.Identify opportunities for automating log ingestion, enrichment, and correlation within the SIEM to reduce manual effort and enhance detection.Experience with automating MITRE listed TTPs and ways to detect relevant IOCs and IOAsIntegrate various log sources in to Splunk for real-time monitoring and analysis.Created monitoring and diagnostic performance profiles of mission-critical applications.Responsible for data onboarding which may include application/add-on installation, custom parsing rules, and CIM compliance.Experience in optimizing data pipelines for performance and efficiency, handling large data volumes, and implementing best practices for data integrity and consistencyStrong analytical and problem-solving skills, with the ability to effectively prioritize and execute tasks