At REWTERZ, I administer geographically distributed Elastic Stack clusters for a 24/7 SOC. I ingested more than 10 log source types through ECS-compliant Logstash pipelines and configured lifecycle and snapshot policies that helped cut storage costs by 22%.
I created KQL and Query DSL detection rules for lateral movement, exfiltration, and anomalous authentication. Kibana Lens and TSVB dashboards replaced manual analyst reporting and reduced MTTR by 38%, while Python and the Elasticsearch REST API helped automate administration.
At Systems Limited, I was part of a three-person team deploying and managing Elasticsearch clusters for an environment with more than 2,000 servers and 7,000 endpoints. I also created Kibana dashboards that helped reduce SOC incident response times by 45%; earlier, as a Security Engineer Intern at NASTP, I built an AI-powered SOAR platform that generated incident response playbooks from real-time detection alerts.

