SOC & SIEM Engineering
Wazuh-centered monitoring architecture, ingestion, tuning, detection workflows, and evidence-oriented reporting.
I am open to technical roles, collaborations, and carefully scoped pilot work where the environment, authorization, deliverables, and success criteria are explicit.
Wazuh-centered monitoring architecture, ingestion, tuning, detection workflows, and evidence-oriented reporting.
Controlled triage, enrichment, case handling, and human-approved response with safe defaults.
Python, FastAPI, Docker, queues, data stores, and observability for repeatable security operations.
Authorized lab and application assessment with reproducible evidence, risk explanation, and mitigations.
Bounded designs for SMB environments, including assumptions, failure modes, privacy, and operational constraints.
Architecture maps, runbooks, maturity statements, evidence packages, and implementation-ready handoffs.