At His Majesty’s Revenue and Customs, I moved 300+ detections to entity-based Risk-Based Alerting on Splunk ES and SOAR, cutting alerts from around 4,000 to around 400 a month and false positives by 97%+, while raising true positives by 80%+. I oversee 350+ detections across Splunk, MDE and CrowdStrike, and am developing a CI/CD pipeline to test and benchmark detections before production.
Alongside my government security operations work, I build Rust security tools and systems. Hisn.io is an edge security platform with a custom rules engine; BabySOARus runs sandboxed WebAssembly components inside Splunk; and Rasm compiles Sigma rules into detection formats for multiple SIEMs.

