Principal Security Architect - Sentinel Siem Xdr Detection Engineering
CurrentSIEM XDR Threat Detection Engineering Architect - leading one of Microsoft’s largest Sentinel SIEM XDR rollouts for a $15B top Healthcare Provider in the U.S.Working directly with Microsoft product group to develop and test security automation for the detection and remediation of advanced nation state threats using Microsoft Azure Sentinel SIEM / Defender for Endpoint ( MDE XDR ), Copilot for Security ( Security Copilot ), Copilot for Azure alongside Defender for Cloud, Azure Arc and the entire Azure security stack.SIEM Engineering Detection EngineeringXDR EngineeringGen AI for Security / SOARPurple TeamKQL / KustoSecurity Copilot LLM SOARAzure Machine Learning / AMLAzure ML StudioAzure Fusion MLMSTICPyAzure SynapseJupyter NotebooksGitAzure DevOps / DevSecOpsTerraformAzure CLI / Cloud Shell / bashInfrastructure as Code / IaCAzure PlaybooksLogic AppsFunction AppsADLSAzure Workspaces / Resource GroupsMicrosoft GraphAzure Resource GraphCustom Analytic Rules / Entity MappingsASIM NormalizationAdvanced Hunting QueriesARM / arm-ttk / Azure Resource ManagerCriblKafkaAzure Data Explorer ( ADX )Azure Event Hubsrsyslog / NXlogOMS / Log Analytics AgentLog Analytics WorkspaceAzure Monitoring Agent / AMAData Connectors / Regex ParsersSyslog / CEFTLS / SSL / HTTPSREST APIAzure ArcThreat Intelligence Watchlists / TI Incident and Logging Enrichment LLM SOARRiskIQ / VirusTotalMITRE ATT&CKUnit 42 EngagementRHEL 9 / SElinuxtcpdump / wireshark / fiddlerPython / PowerShell / YAML / JSONDefender for Endpoint EDR / XDR / MDEDefender for ServerDefender for Cloud ( MDC )Defender for Cloud Apps / CASB / Security Broker