I'm currently building SOC detection and response capabilities at Skillmine Technologies, monitoring SentinelOne across 400+ endpoints and investigating IOCs, process activity, malicious IPs, domains, and hashes.
I've deployed Wazuh SIEM across client and internal environments, written custom detection rules, built Kibana dashboards, and centralized logs from AWS, Kubernetes, firewalls, EDR platforms, and on-premise systems. I also designed CloudTrail and VPC Flow Log pipelines and Fluent Bit-based Kubernetes log collection into Wazuh.
I automate alert enrichment, investigation support, and ticketing workflows with Python, Bash, and PowerShell. My work also includes web application vulnerability testing with Burp Suite and OWASP ZAP, Sophos EDR integrations, Zscaler DLP monitoring, and secure log forwarding through Cloudflare Tunnel and Tailscale VPN.
Previously at Tech Geek, I monitored Splunk and QRadar alerts, tuned detection rules and IDS/IPS configurations, integrated OSINT threat intelligence, performed forensic log analysis, and documented incident response and risk-assessment findings.
