At Swisslog Logistics, I design KQL detections in Microsoft Sentinel and Defender for threats including certutil abuse, unsigned executables, unauthorized PnP devices, and living-off-the-land activity. I also perform sandbox-based static and dynamic analysis, document indicators of compromise, and support incident remediation across a global follow-the-sun model.
Previously, I maintained hypervisors, guest VMs, network devices, and critical automation applications as a Systems Engineer. I led ISO 27001 preparation for customer-facing managed services, coordinated security patching, defined security baselines, and built repeatable SOP documentation.
My background also includes white-glove IT support, endpoint troubleshooting, network and VPN support, customer-site hardware refreshes, and PowerShell sandbox development. I hold CompTIA PenTest+, Security+, Network+, and A+ certifications.
