Senior Information Security Analyst @ Firstquality
Feb 2022 โ PresentDetection engineering for a 5,000-person global manufacturer (~5,000 endpoints, 2,000 servers, 7 US/Canada sites; corporate IT plus monitored OT). Authored 200+ detection rules from scratch across Cortex XSIAM, XDR, Microsoft Sentinel, Defender for Endpoint and CrowdStrike Falcon, each mapped to MITRE ATT&CK. Led the enterprise migration onto Cortex XSIAM and owned log-source strategy under SaaS ingestion constraints. Drove tuning that cut the false-positive rate from ~50% to ~15%, built the SOAR automation layer in Python and PowerShell, and act as final in-region escalation authority.