About
Detection is engineering. Investigation is method.
My work splits three ways. I operate — alert triage, incident investigation, root-cause analysis, and coordination against an SLA when something escalates. I engineer detection — KQL analytics rules and hypothesis-driven hunt packages, each mapped to MITRE ATT&CK so coverage and gaps stay explicit, tuned as hard for signal as they're written. And I engineer the platform — Microsoft Sentinel deployed as infrastructure-as-code, log sources and data connectors brought online, threat intelligence integrated through APIs, and SOAR playbooks built to act on the high-fidelity alerts.
That reaches across the rest of the Microsoft security stack. I investigate identity activity in Microsoft Entra ID, review posture with Microsoft Defender for Cloud, keep automation identities scoped to least-privilege RBAC, and bring network and workload context into how detections are written — grounded in AZ-500, SC-200, and SC-300. Google SecOps and LogRhythm, plus a Google Cloud security operations certification, keep the work from being single-vendor.
- Role
- Senior Cybersecurity Analyst & Security Engineer
- Currently
- Mannai Technologies — Microsoft Hub
- Experience
- 4+ years, security operations & engineering
- Focus
- Security OperationsThreat DetectionIncident ResponseDetection EngineeringAzure SecuritySecurity Automation
- Certifications
- SC-200 · SC-300 · AZ-500+ 6 more
Where I've done it.
Four years in security operations — from first-line triage on a 24/7 rotation to security engineering across Microsoft Azure and Sentinel.
SOC Engineer
Security engineering and threat hunting for a Microsoft-partner team running a 24/7 managed SOC on Azure and Sentinel.
- Deploy and configure Microsoft Sentinel workspaces; onboard log sources and data connectors as new coverage comes online
- Author and tune KQL analytics rules mapped to MITRE ATT&CK; integrate external threat-intelligence feeds through Sentinel's ingestion APIs
- Run proactive, hypothesis-driven threat hunting in KQL — hunt packages mapped across the MITRE ATT&CK matrix
- Build SOAR: Logic App playbooks, Sentinel automation rules, and Azure Automation runbooks for enrichment, notification, and response — authenticated with Key Vault-backed managed identity
- Operate multi-SIEM across Microsoft Sentinel, Google SecOps (Chronicle), and LogRhythm
- Investigate across Azure workloads and identity with Microsoft Defender for Cloud, Entra ID, Azure Monitor, and Log Analytics
- Incident response and escalation: alert triage, root-cause analysis, SLA tracking, coordination on high-severity incidents, and Sentinel workbooks for operational reporting
SOC Analyst
L1 analyst on a 24/7 monitoring rotation — first-line triage and investigation before escalation.
- Monitored SIEM alert queues, carried out initial triage, and separated true positives from false positives
- Escalated confirmed incidents to L2 with investigation notes and supporting evidence
- Ingested IOCs from threat-intel feeds and vendor advisories and matched them against environment telemetry
- Produced shift-handover, weekly alert-trend, and monthly operational reports feeding tuning recommendations back to senior analysts
- Maintained investigation records and runbook documentation; followed escalation paths and tracked ticket SLAs
Credentials, and what they mean in practice.
The Microsoft role-based certifications, shown as what they cover and how that shows up in the work — not just badges.
Security Operations Analyst Associate
Core knowledge
Practical skills
- Investigate and remediate incidents across Sentinel and Defender
- Author and tune scheduled analytics rules mapped to MITRE ATT&CK
- Run hypothesis-driven hunts and turn findings into detections
- Configure data connectors, watchlists, and automation rules
Identity and Access Administrator Associate
Core knowledge
Practical skills
- Design identity lifecycle, authentication, and access policy for a tenant
- Investigate risky sign-ins and identity-based attacks
- Scope RBAC and least-privilege access for automation identities
- Run access reviews and entitlement management
Azure Security Engineer Associate
Core knowledge
Practical skills
- Secure Azure networks with NSGs, Firewall, and Private Link
- Manage secrets and keys with Azure Key Vault and managed identity
- Review posture with Microsoft Defender for Cloud
- Wire workload and platform telemetry into Sentinel
Also held
Tools & technologies.
What I work in day to day, grouped by where it sits in the pipeline.
Education