Experienced cybersecurity professional specializing in ArcSight SIEM and XDR technologies with a strong focus on device integration and security operations. Skilled in integrating a wide variety of network devices, endpoints, and security solutions into ArcSight SIEM platforms to ensure effective threat detection, monitoring, and response. Proficient in developing custom connectors, parsers, and integration scripts to streamline data flow and enhance system performance. Expertise in leveraging XDR capabilities for advanced threat hunting, incident detection, and automated response, ensuring comprehensive visibility across the security landscape. Adept at troubleshooting, fine-tuning, and optimizing security platforms for maximum operational efficiency. Strong communication skills and a collaborative team player, delivering integrated, scalable, and resilient security solutions to safeguard organizational assets.
Coordinating and conducting event collection, log management, event management, compliance automation and identity monitoring activities using the SIEM different components. Develop, Implement, and execute standard procedures for the administration, content management, version/patch management, and lifecycle of the SIEM platforms. Creation of technically detailed report on the status of the SIEM to include metrics on items such as number of logging sources, log collection rate, and server performance. Cloud products (Azure, GCP, AWS) view for integration with API using different techniques, baseline document preparation based on the essential log ingestion. Recommended security strategies based on real time threats. Act as the point of escalation for the others (SIEM engineers, Senior Engineer) and provide guidance and mentoring.
XDR