At 7-Eleven, I investigated security events across endpoints, servers, networks, and cloud environments using Splunk, Microsoft Sentinel, and Palo Alto Cortex XDR. I analyzed Active Directory attacks, credential abuse, and lateral movement, and coordinated endpoint containment and recovery.
At NCR Voyix, I optimized Splunk SIEM detection and alerting, reducing false-positive alerts by ~40%. I also investigated phishing, malware, suspicious PowerShell activity, and C2 traffic, and supported incident response through remediation and closure.
I’ve deployed EDR and SIEM platforms, developed custom EDR detection rules and SIEM use cases, and deployed DLP for 10,000 users. I hold the Microsoft SC-200 and EC-Council CEH certifications.

