Skip to content
← Security & Infrastructure

SecOps Incident Response

Front-line response to 200+ incidents across 300+ client organizations, averaging 1–3 minutes to mitigation.

Category
Security & Infrastructure
Type
Production work

Front-line response to 200+ incidents across 300+ client organizations — business email compromise, account takeovers, malware, phishing and vishing, browser hijacking — with a 1–3 minute average to full mitigation using SentinelOne, Wazuh, OpenCTI, and Microsoft Entra.

At that volume the work is as much triage discipline as tooling: deciding fast what is noise, what is a single compromised mailbox, and what is a tenant-wide problem, then containing it before the attacker finishes what they started.

Built with

  • SentinelOne
  • Wazuh
  • OpenCTI
  • Microsoft Entra
  • EDR/XDR
  • Mimecast

Client work — no public link, and no client names or specifics beyond what is already on the resume.