I've built and operated SIEM monitoring and detection capabilities across ArcSight, Splunk, QRadar, and ELK, with hands-on experience investigating endpoint and email threats.
At CIBCGlobal-AnewzTV, I conduct threat hunting and investigate CrowdStrike Falcon alerts, endpoint telemetry, phishing attempts, malicious files, URLs, hashes, and email attachments. I document findings and support triage, escalation, containment, remediation, and recovery activities.
At Vodafone Prague, I deployed and maintained ArcSight ESM and Splunk, onboarded and normalized security logs, and developed correlation rules, dashboards, searches, and detection use cases mapped to MITRE ATT&CK.
My background also includes CrowdStrike EDR/XDR monitoring at Marelli Magneti Automotive Lighting, FortiMail and FortiSandbox administration at Fortinet, and ArcSight SIEM engineering at ING-NN Bank Group.

