Threat hunting and detection engineering
Investigate suspicious activity across DNS, endpoint, threat-intelligence, and cloud telemetry, then convert findings into detection logic and repeatable response steps.
- Hunt through Cisco Umbrella DNS telemetry and correlate indicators.
- Develop and tune Recorded Future alerts for relevance and impact.
- Test and maintain Microsoft Sentinel analytic rules.
- Use Defender telemetry to support triage and incident response.
Value: stronger signal quality and clearer analyst action.