Security Operations
Leading SOC shift operations, incident response, and 24/7 monitoring across enterprise environments.
Detection & Response Engineer
Cybersecurity engineer with 10+ years of experience across Endpoint Detection & Response, Extended Detection & Response, threat detection, security investigations, and security operations — engineering detection capabilities and response workflows that hold up in enterprise environments.
I bring a combination of hands-on detection and response engineering, customer security assessments, endpoint investigations, and SOC leadership to improve security visibility, detection coverage, and response effectiveness.
My work spans endpoint security platforms, XDR onboarding, custom detection development, prevention configuration, response automation, threat hunting, and operational improvement across enterprise environments.
Leading SOC shift operations, incident response, and 24/7 monitoring across enterprise environments.
Building custom detections and response workflows across leading EDR and XDR platforms.
Onboarding and supporting 500+ EDR and 20+ XDR customers through assessments and configuration.
Driving SOP improvements, workflow automation, and knowledge transfer to raise operational maturity.
Proficio
Endpoint Detection & Response
Uber
Security Response & Investigations
Diyar United Company
Threat Intelligence & Investigations
Vodafone
Vodafone
Custom detections, detection rules, threat identification, detection coverage, and analytics improvement.
Platform onboarding, policy design, prevention controls, endpoint health, configuration, and operational readiness.
CrowdStrike Fusion workflows, SentinelOne STAR rules, response workflows, and operational automation.
Endpoint telemetry analysis, host-based investigations, threat intelligence, triage, escalation, and containment recommendations.
Shift leadership, incident coordination, SOP improvement, analyst mentoring, stakeholder collaboration, and knowledge transfer.
Customer environment reviews covering policies, prevention, exclusions, detections, configurations, and operational readiness.
Supported customer security environments from initial assessment and deployment through policy configuration, endpoint health, detection readiness, and ongoing response operations.
Designed and built CrowdStrike Fusion workflows, SentinelOne STAR rules, and custom detections to support repeatable threat identification and response use cases.
Improved operational effectiveness through investigation guidance, threat hunting, EDR optimization, SOP improvements, incident documentation, and knowledge transfer.
Open to conversations around detection engineering, EDR/XDR, security operations, incident response, and technical leadership opportunities.