← Security & Infrastructure
SecOps Incident Response
Front-line response to 200+ incidents across 300+ client organizations, averaging 1–3 minutes to mitigation.
- Category
- Security & Infrastructure
- Type
- Production work
Front-line response to 200+ incidents across 300+ client organizations — business email compromise, account takeovers, malware, phishing and vishing, browser hijacking — with a 1–3 minute average to full mitigation using SentinelOne, Wazuh, OpenCTI, and Microsoft Entra.
At that volume the work is as much triage discipline as tooling: deciding fast what is noise, what is a single compromised mailbox, and what is a tenant-wide problem, then containing it before the attacker finishes what they started.
Built with
- SentinelOne
- Wazuh
- OpenCTI
- Microsoft Entra
- EDR/XDR
- Mimecast
Client work — no public link, and no client names or specifics beyond what is already on the resume.