SIEM Detection Engineering & Threat Visibility
February 2025 - February 2026
ProfessionalLed detection engineering initiatives that delivered unified visibility and threat detection across a customer environment spanning cloud services, SASE, on-prem network security platforms (Palo Alto, Sophos, Thor APT), Linux and Windows servers, virtualisation environments (Proxmox, VMware), OT infrastructure, and end-user workstations. Enhanced detection of insider data exfiltration and identity compromise risks, addressing the key business threats in a highly sensitive operating environment where comprehensive, cross-platform visibility had not previously existed.