Michael Hill, Cissp, Ccsp, Ecthpv2

Michael Hill, Cissp, Ccsp, Ecthpv2 Email and Phone Number

Director of Cyber Security Operations @ NetSPI
Washington, DC, US
Michael Hill, Cissp, Ccsp, Ecthpv2's Location
Washington DC-Baltimore Area, United States
About Michael Hill, Cissp, Ccsp, Ecthpv2

Michael is a Director of Cyber Security Operations at a Fortune 200 company with over 300,000 employees and substantial public facing infrastructure. He oversees the Applied Cyber Threat Research (ACTR) department which includes the Threat Hunting, Threat Intelligence, and Reverse Engineering teams. He has a strong technical background from hands on experience as both a leader and individual contributor in multiple cyber domains, including: SOC operations, incident response, SIEM operations, threat hunting, threat intelligence, endpoint protection engineering, vulnerability management, cloud security and phishing defense.With over 15 years in cyber security, he holds a Bachelors in cyber security and numerous cyber industry standard certifications including the CISSP and CCSP. He is an intelligent, resourceful, energetic, focused, tactful, and impactful leader with a history of achieving results.He is currently open to new opportunities at companies with progressive work cultures, strong financials, effective IT departments, and relatively low technical debt.

Michael Hill, Cissp, Ccsp, Ecthpv2's Current Company Details
NetSPI

Netspi

View
Director of Cyber Security Operations
Washington, DC, US
Website:
netspi.com
Employees:
635
Michael Hill, Cissp, Ccsp, Ecthpv2 Work Experience Details
  • Netspi
    Director Of Cyber Security Operations
    Netspi
    Washington, Dc, Us
  • Confidential
    Director Of Cyber Security Operations
    Confidential Oct 2022 - Present
    United States
  • Confidential
    Principal Cyber Security Specialist – Threat Hunting Program Lead
    Confidential Jan 2020 - Sep 2022
    - Established and operated an advanced, scalable, Threat hunting program consisting of 2 FTE Threat hunters, 8 Cross-functional hunters, 24/7 SOPs, custom tooling, and a purpose-built Threat Intelligence and Hunt ticketing system- Successfully identified active 0-day APT threats at multiple stages of the attack chain using a combination of emerging Threat Intelligence and awareness of common adversary techniques, tactics, and procedures- Became a top resource for supporting high-profile… Show more - Established and operated an advanced, scalable, Threat hunting program consisting of 2 FTE Threat hunters, 8 Cross-functional hunters, 24/7 SOPs, custom tooling, and a purpose-built Threat Intelligence and Hunt ticketing system- Successfully identified active 0-day APT threats at multiple stages of the attack chain using a combination of emerging Threat Intelligence and awareness of common adversary techniques, tactics, and procedures- Became a top resource for supporting high-profile and high-impact incidents- Created advanced SIEM Dashboards in Splunk to orchestrate hunting of atomic IOCs across all relevant data sources, drastically improving the speed and consistency of simple IOC hunts. These later became the basis for Automated hunting, for which I was also involved in development and driving the need- Communicated risk of recurring and emergent threats to both Leadership and the corresponding teams in proximity of those threats- Helped establish an “Operational Risk Registry” to track the status of risks discovered from Threat Hunting and Incident Response lessons learned- Measured program progress with both OKRs and KPIs in line with the higher Cyber Operations organizational objectives- Developed multiple reporting dashboards related to the intelligence and hunting programs’ activities- Analyzed Threat Intelligence from a curated list of open and closed source Intelligence sources- Held highest overall achievement score in ImmersiveLabs cyber training platform amongst 32 peers (107k points). Also held highest number of labs completed at difficulty levels 8, 9, and 10. In total: 750+ labs, 249 CEU’s, in approximately 4 years Show less
  • Confidential
    Senior Cyber Security Analyst - Incident Response
    Confidential Jan 2019 - Jan 2020
  • Confidential
    Senior Cyber Security Analyst – Soc & Incident Response Lead
    Confidential Dec 2016 - Jan 2019
    - Led a team of Cyber Security professionals tasked with performing SOC operations, incident response and various cyber security enhancing projects- Key provider of evidence to attain NIST 800-171 compliance- Primary incident responder for all Tier 3 incidents- Onboarded, trained, and mentored junior SOC and CIRT members, including the development of SOPs for all members to follow for various frequent use case scenarios- Identified numerous improvement opportunities for Splunk… Show more - Led a team of Cyber Security professionals tasked with performing SOC operations, incident response and various cyber security enhancing projects- Key provider of evidence to attain NIST 800-171 compliance- Primary incident responder for all Tier 3 incidents- Onboarded, trained, and mentored junior SOC and CIRT members, including the development of SOPs for all members to follow for various frequent use case scenarios- Identified numerous improvement opportunities for Splunk Correlation rules, Firewall Rules, and Endpoint Security configurations- Established and maintained a formal company-wide Phishing Awareness and Response Program. Including simulated campaigns, reporting metrics, and phishing response SOPs.- Reduced company-wide phishing susceptibility by 65%- Represented the company at industry conferences including those specific to Government Defense and Aerospace Contractors Show less
  • Confidential
    Senior Technical Account Manager - Endpoint Protection Specialist
    Confidential Aug 2012 - Jul 2016
    - Served as top tier, dedicated technical account support for Symantec’s flagship enterprise product: Symantec Endpoint Protection, which included functionality for Antivirus, Host Firewall, Host IPS, and Network access Control- Simultaneously serviced 3 Fortune 500, and 2 Fortune 100 accounts with Endpoint environments ranging from 15k to 220k Endpoints each- Achieved a 100% customer renewal rate during my tenure and received positive reviews from each of my 5 named accounts during… Show more - Served as top tier, dedicated technical account support for Symantec’s flagship enterprise product: Symantec Endpoint Protection, which included functionality for Antivirus, Host Firewall, Host IPS, and Network access Control- Simultaneously serviced 3 Fortune 500, and 2 Fortune 100 accounts with Endpoint environments ranging from 15k to 220k Endpoints each- Achieved a 100% customer renewal rate during my tenure and received positive reviews from each of my 5 named accounts during every review period- Provided direct expert level support to the named contacts within my 5 dedicated customer accounts on issues ranging from: active virus outbreaks, intrusion events, installations, upgrades, configuration, product defects, and enhancement requests- Worked high severity issues across a 24/7 Follow the Sun support model with TAMs in EMEA and APAC- Leveraged other advanced company resource departments as needed to resolve the needs of the customer, including Back Line Engineering, Security Response, and Malware Analysis Teams- Represented the company on Executive Level Briefs with the customer, engaging additional company resources where fitting for the call Show less
  • Confidential
    Technical Support Engineer
    Confidential Aug 2011 - Aug 2012
    - Supported SSL certificate suite of products at the enterprise level. Ranging from Enterprise Managed PKI services to small business customers.- Consistently maintained High Customer Satisfaction ratings and case volume- Created and updated Knowledge Management Articles regarding Technical Troubleshooting and Instructional Guides

Frequently Asked Questions about Michael Hill, Cissp, Ccsp, Ecthpv2

What company does Michael Hill, Cissp, Ccsp, Ecthpv2 work for?

Michael Hill, Cissp, Ccsp, Ecthpv2 works for Netspi

What is Michael Hill, Cissp, Ccsp, Ecthpv2's role at the current company?

Michael Hill, Cissp, Ccsp, Ecthpv2's current role is Director of Cyber Security Operations.

Who are Michael Hill, Cissp, Ccsp, Ecthpv2's colleagues?

Michael Hill, Cissp, Ccsp, Ecthpv2's colleagues are James Keane, Mac Knight, Kimberly Wiles, Rhys O'higgins, Ligia Zayas, Mason Remund, David Mahannah.

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.