Incident response
Triage and containment across endpoint and identity alerts using Defender XDR, SentinelOne, CrowdStrike Falcon, RocketCyber, and Huntress.
Incident response · phishing investigation · endpoint security
Cybersecurity Professional | Security+ & CySA+
Hands-on security operator with experience investigating and remediating 1,000+ security incidents and 300+ phishing cases. I work daily in Microsoft Defender XDR, SentinelOne, CrowdStrike, Huntress, Entra ID, Intune, Microsoft 365, and Google Workspace.
Focus areas
Triage and containment across endpoint and identity alerts using Defender XDR, SentinelOne, CrowdStrike Falcon, RocketCyber, and Huntress.
Investigate compromised accounts and suspicious authentication using Entra ID and Google Workspace audit logs, then close the loop with the user.
Administer Entra ID, Intune, Microsoft 365, and Google Workspace while supporting Windows, macOS, Linux, and mobile endpoints.
Log pipeline
How telemetry from endpoints, identity, email, and the firewall is ingested, load balanced, and sent to the right place.