The Boeing Company · 10,000+ endpoints
From alert to defensible incident decision
Lead investigator for assigned incident cases
Was the activity malicious, how far did it reach, and what action was justified by the available evidence?
Correlated endpoint, identity, network, and vulnerability signals; investigated malware, compromised accounts, phishing, suspicious PowerShell, and network anomalies; documented findings; and briefed technical stakeholders on containment and resolution.
Independently led 50+ documented incident cases and used investigation findings to improve Splunk correlation searches and behavioral detections.