I've monitored and triaged 30–40 security alerts per shift at Advanced Technologies, using Microsoft Sentinel and Splunk Enterprise Security to identify true positives and escalate critical incidents within SLA timelines. I lead response for phishing, malware, and unauthorized-access events, coordinating containment, remediation, and root cause analysis across teams.
Previously at Onwards Technologies, I performed Level 1 alert triage, analyzed Windows, Active Directory, Microsoft 365, and network logs, and supported phishing investigation, vulnerability management, endpoint monitoring, and detection-rule improvements. I work across Microsoft Defender, CrowdStrike, Microsoft Entra ID, Palo Alto Networks, Cortex XSOAR, ServiceNow, KQL, and MITRE ATT&CK-driven threat hunting.
