Cybersecurity Analyst — Aptech Learning (2023–Present)
You developed and deployed 50+ custom SIEM correlation rules in Splunk/Elastic to improve detection performance, which involved defining and validating event patterns from security log text. You also contributed to reducing time-to-detection (MTTD) by tuning how the system classifies and correlates threat signals from incoming telemetry. The work functioned as a form of structured labeling/annotation of security events for downstream analytics and alerting. • Built SIEM correlation logic across Splunk/Elastic. • Tuned threat detection to reduce MTTD by 15%. • Supported VAPT remediation loops using findings to refine detection rules. • Improved alert relevance by refining event pattern matching and correlation.