Senior Security Analyst
Current• Engineering/Architecture - Architected and Implemented an elastically scaled 6-figure EPS Syslog Ingestion System (SIS) for Microsoft Sentinel - Elastically-scaled SIS implemented the following products: - Logstash (plugins: tcp, udp, syslog, kafka, dns, grok, MS Sentinel) - Kafka-based Products (Apache Kafka, Confluent, Azure Event Hub) - Azure Private Link Scopes + Subservices - Network Load Balancers (Azure LB, Kemp LM, F5 LTM) - Virtual Machine Scale Sets - Custom Data Collection Endpoints - Custom Data Collection Rules (Parsing, Transformation, Tables) - Rsyslog (plugins: imudp/imtcp, omkafka) - Scale-in/Scale-out policies - Rewrote specific Logstash-based Microsoft plugin functions to increase compression - Designed, tested, and implemented several new DCRs to support new or under-supported data sources. - Most complex SIS was projected to scale to 6-figure EPS. - SIS implemented full security protocols including encryption, authentication, and AV/EDR capabilities