Associate Director, Cyber Security Operations
● Scaled out QRadar SIEM to enhance visibility, reduce false positives, and improve detection of security and compliance issues. ● Collaborated with vendors to resolve QRadar on Cloud deployment and performance issues.● Implemented custom log sources for applications and devices not natively supported by QRadar. ● Tuned on-prem IDS/IPS systems for increased visibility of activity related to known vulnerabilities on network and improved Firepower Threat Defense performance.● Optimized Tenable.sc network scanning configuration to cover more LAN segments, resolved issues where scans impacted devices, and implemented credentialed scanning for higher quality data.● Deployed CrowdStrike EDR, Data Protection, File Vantage, Identity Management, Recon+, and Spotlight to replace Cylance AV and Recorded Future threat intel feed into QRadar.● Used CrowdStrike Identity to implement two factor authentication for administrative logins and web applications, reduce AD configuration issues, monitoring for unusual account activity, and email alerting to users for compromised passwords. ● Monitored data loss using CrowdStrike Data Protection, later blocked USB storage where possible on end-user devices using CrowdStrike device control policies. Built an exceptions process for USB storage where required to support business operations. ● Evaluated CrowdStrike Next-Gen SIEM and Spotlight as potential QRadar and Tenable.sc replacements.● Developed business case for Cisco Umbrella to filter endpoint Internet traffic, implemented proof of concept with network team, and performed final deployment. ● Assisted Legal, HR, IT, and other departments accessing logs and other information stored in QRadar, CrowdStrike Next-Gen SIEM, and other security tools to support investigations and troubleshooting.● Performed periodic pen-testing and social engineering to validate internal security controls.