Omri Degani

Detection Engineering & Security Operations

Detection engineer building MITRE ATT&CK-aligned content across XSIAM, Sentinel and EDR.

01 About

Detection engineering and security operations specialist with seven years across enterprise and MSSP environments. Currently Senior Information Security Analyst at a 5,000-person global manufacturer, where I've authored 200+ purpose-built, MITRE ATT&CK-aligned detection rules across Cortex XSIAM, Cortex XDR, Microsoft Sentinel, Defender for Endpoint and CrowdStrike Falcon, spanning endpoint, network, cloud and identity telemetry. I led the enterprise migration onto Cortex XSIAM and its log-source strategy, and previously led a SOC team of 7-10 analysts across multiple client environments.

๐Ÿ“ Tel Aviv, Israel ยท โœ‰ [email protected]

02 Experience

Senior Information Security Analyst @ Firstquality

Feb 2022 โ€“ Present

Detection engineering for a 5,000-person global manufacturer (~5,000 endpoints, 2,000 servers, 7 US/Canada sites; corporate IT plus monitored OT). Authored 200+ detection rules from scratch across Cortex XSIAM, XDR, Microsoft Sentinel, Defender for Endpoint and CrowdStrike Falcon, each mapped to MITRE ATT&CK. Led the enterprise migration onto Cortex XSIAM and owned log-source strategy under SaaS ingestion constraints. Drove tuning that cut the false-positive rate from ~50% to ~15%, built the SOAR automation layer in Python and PowerShell, and act as final in-region escalation authority.

SOC Team Leader @ Triple Cyber

Mar 2021 โ€“ Feb 2022

Led SOC operations for an MSSP with a team of 7-10 analysts across multiple concurrent client environments โ€” owning shift structure, monitoring coverage and queue management. Established incident escalation protocols and triage standards, served as escalation authority on complex incidents, and prioritised vulnerability management across client estates.

SOC Analyst @ TrustNet

Aug 2019 โ€“ Mar 2021

Triaged and escalated confirmed incidents with supporting investigative analysis across multiple MSSP client estates. Analysed network traffic and endpoint logs to identify anomalous activity, investigated incidents to root cause, and tuned alert configurations to improve signal quality and reduce low-value volume.

System Administrator @ Impact Networks Group

Nov 2018 โ€“ Jul 2019

Delivered managed IT across multiple on-prem and hybrid client environments: Windows Server, Active Directory, DNS/DHCP, Hyper-V and VMware, Microsoft 365 and Exchange. Managed perimeter security (FortiGate and Check Point firewalls, SSL-VPN, endpoint protection, Group Policy) and backup/replication infrastructure, automating recurring tasks with PowerShell.

03 Projects

Security Detection & Response Homelab preview

Security Detection & Response Homelab

A dedicated detection-and-response lab on a self-built private cloud (Apache CloudStack on KVM). I replicate adversary techniques drawn from threat intelligence โ€” focused on Windows and Active Directory โ€” to validate detection coverage, confirm authored rules fire as intended, and evaluate EDR/detection products before deployment decisions.

Apache CloudStackKVMDetection EngineeringMITRE ATT&CKEDR Validation

04 Skills

Automation

SOAR / PlaybooksWorkflow Automation

Cloud & Identity

Microsoft Entra IDAzure TelemetryActive DirectoryNetskope

Controls & Platforms

NGFW / IPS / WAFDLP / NACGuardicoreOT / ICS Monitoring

EDR / XDR

Cortex XDRDefender for EndpointCrowdStrike Falcon

IT & Endpoint

Microsoft 365ExchangeGroup PolicyEndpoint ManagementWindows Administration

Networking

FortiGateCheck PointSSL-VPNDNS / DHCPRouting & SwitchingVLANs & SegmentationUniFi

Query & Scripting

KQLXQLPythonPowerShell

Security Operations

Incident ResponseThreat HuntingThreat IntelligenceIOC AnalysisVulnerability Management

Server Management

Windows ServerLinux / DebianBackup & ReplicationPatch ManagementNginx / HAProxy

SIEM & Detection

Cortex XSIAMMicrosoft SentinelDetection EngineeringCorrelation RulesMITRE ATT&CK MappingAlert TuningLog Source Strategy

Virtualization

VMwareHyper-VKVM / QEMUApache CloudStackProxmox VEDocker

05 Education

Cyber Security ยท HackerU

2018 โ€“ 2019

Network and System Administration ยท Technion โ€“ Israel Institute of Technology

2016 โ€“ 2017

06 Get in touch

Have a role, a project, or just want to say hello? I'd love to hear from you.

[email protected]