SOC engineering
Keep response working
Connect Microsoft Sentinel, ServiceNow Security Incident Response and XSOAR through incident lifecycle requirements, controlled integration testing and operational handovers for an MDR service.
All cards in this section are viewed.
Keeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyKeep incident meaning intact across platforms
Security Operations EngineeringValidated nine bidirectional Sentinel–ServiceNow closure scenarios and defined incident, entity and escalation requirements across the SIEM/SOAR workflow.
Read the storyCreate realistic security incidents on demand
Automation / Security Operations EngineeringBuilt a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.
Read the storyTurn incident records into executive briefings
Reporting Automation / Security Operations EngineeringAutomated executive incident-of-note slides linking the security event, the weakness exploited and the follow-up actions required.
Read the storyFollow a skill into the work