SKILLS
SOC, SIEM, security operations, security monitoring, incident handling, use-case development, ArcSight
CISSP, GCIA, GPEN
SIEM Use-Case development
- from identifying the log-sources,
- on-boarding the feeds,
- making sure that meaningful events show up in the SIEM,
- building-up resource-safe/optimal and operational-ready content,
- extensively testing the use-cases,
- proper documentation,
- and integration with operations.