A skill, in practice
Microsoft Sentinel
Explore how I used Microsoft Sentinel through 5 case stories.
Experience at UK Water Utility
All cards in this section are viewed.
Keeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyFrom business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyCreate realistic security incidents on demand
Automation / Security Operations EngineeringBuilt a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.
Read the storyKeep incident meaning intact across platforms
Security Operations EngineeringValidated nine bidirectional Sentinel–ServiceNow closure scenarios and defined incident, entity and escalation requirements across the SIEM/SOAR workflow.
Read the storyRead the operation behind the OT alert
OT Security Monitoring & InvestigationInvestigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.
Read the story