- Designed and developed security use cases in Splunk, including correlation searches, dashboards, and operational reports to support SOC monitoring and threat detection.
- Collaborated closely with SOC Analysts, Security Engineers, and SOC Managers to translate security requirements into actionable Splunk detections and analytics.
- Partnered with SOAR engineers to integrate and customize Splunk alerts for automated response workflows.
- Supported continuous improvement of SOC visibility by refining detections, tuning alerts, and enhancing dashboards based on analyst feedback.
Work
- Jun 2021 - Jul 2023Globe TelecomSecurity Platform Development Expert
- Jan 2020 - Oct 2020AccentureSplunk Engineer
- Led the end-to-end implementation of Splunk Enterprise for Accenture’s MyWizard platform, from initial installation to production support.
- Architected and configured a distributed Splunk deployment, including indexer clusters, search head clusters, heavy forwarders, deployer, cluster master, license master, and deployment server.
- Worked closely with project managers and cross-functional engineering teams to deliver Splunk solutions aligned with project timelines and requirements.
- Provided post-deployment support and troubleshooting to ensure platform stability and performance.
- Aug 2019 - Jan 2020AccentureMicrofocus Tools Engineer
- Provided Tier 2 operational support for Micro Focus monitoring tools, including Operations Manager i, Network Node Manager i, and SiteScope.
- Collaborated with the Service Delivery team to onboard servers, network devices, and monitored services, improving observability coverage.
- Managed incident and service request tickets using ServiceNow, ensuring timely resolution and adherence to SLAs.
- Supported monitoring and alerting workflows in enterprise environments.
- Sep 2016 - Aug 2019Netpoleon SolutionsSplunk Engineer
- Administered Splunk Enterprise and Splunk IT Service Intelligence (ITSI) in a clustered environment with multiple indexers and search heads.
- Managed large-scale Splunk Forwarder onboarding, working closely with system administrators to integrate diverse log sources.
- Performed monthly configuration backups, platform health checks, and maintenance to ensure system stability and reliability.
- Collaborated with SOC teams on custom integrations and Splunk development, enhancing security monitoring and operational visibility.
- Handled day-to-day Splunk administration tasks, including user management, app deployment, and troubleshooting.