Information Security Student Analyst
- Monitor, triage, and investigate endpoint and identity alerts across Windows and macOS environments.
- Work with CrowdStrike Falcon, Microsoft Defender for Endpoint, and Elastic SIEM.
- Co-built an Elastic-based monitoring stack using containerized infrastructure.
- Investigate authentication events, Active Directory changes, PowerShell activity, and endpoint process behavior.
- Created and tuned approximately 50 production SIEM rules for firewall, VPN, and network visibility.
- Analyzed data-loss-prevention alerts involving potential PCI and SSN exposure and helped refine detection rules.