Cybersecurity Engineer Northern Trust / RUBISTONE TECHNOLOGIES LLC
Designed, developed, and tuned threat detection logic, correlation rules, and alerting thresholds across cloud and on-premises environments. Built log-ingestion processes by onboarding endpoint, identity, cloud, application, and infrastructure telemetry into Microsoft Sentinel and Splunk.
Developed KQL, SPL, and SQL queries for event analysis, threat hunting, and investigations. Integrated telemetry from CrowdStrike Falcon, Microsoft Defender, AWS CloudTrail, GuardDuty, Windows Event Logs, Linux Syslogs, and Active Directory; automated validation and reporting with Python and PowerShell; mapped coverage to MITRE ATT&CK; and produced detection playbooks and SOC procedures.