Principal Siem Engineer
Current• Led and expanded the Managed SIEM team, serving as the highest technical authority on Microsoft Sentinel, Splunk, and Sumo Logic platforms.• Developed and executed strategic initiatives to enhance the Managed Services offering, including advanced use case development, customer education, and proactive SIEM health checks.• Built and maintained relationships with clients as a trusted advisor, providing tailored solutions and recommendations to meet evolving security needs.• Architected and managed comprehensive SIEM infrastructures, including Splunk environments (Indexer, Deployment Server, Universal Forwarder, Heavy Forwarder, and Search Head), ensuring seamless integration and optimal performance.• Designed and deployed Microsoft Sentinel environments, setting up Syslog servers, configuring Rsyslog, configuring DCRs and transformation rules and creating custom Logic Apps for automated incident handling and response.• Collaborated closely with clients to deliver tailored solutions, providing guidance on network policies, data collection, and threat detection enhancements.