Portrait

mrciano

Cybersecurity Analyst & SOC Engineer

Detection EngineeringIncident ResponseAutomation
Contact
Contact
contact@mrciano.com
Coming soon
Remote · Global
Skills
SIEMEDRDetection EngineeringIRSOARCloud SecLinuxKQLSigma
Certificates
  • SEC504 (Incident Handling)
  • AZ-500 (Azure Security Engineer)
  • GCIA / GCED equivalent experience
Tools
SplunkDefenderCrowdStrikeElasticAzure SentinelOktaMDESuricata
Experience
SOC Engineer
2023 — Present
Built detections, triage runbooks, and automated containment; drove continuous improvement of MTTR and coverage.
  • Auth anomaly detections (impossible travel, MFA fatigue).
  • IR playbooks integrated with SOAR for containment.
  • Threat hunting routines feeding detection backlog.
Detection Engineer
2021 — 2023
Authored Sigma/KQL rules, tuned alert quality, improved signal‑to‑noise ratio.
  • Coverage mapping to ATT&CK.
  • Metrics for drift, efficacy, and FP rate.
  • PR reviews and deployment pipeline for content.
Projects
Cloud Detections Pack
IAM anomalies, persistence, key exposure
IR Playbooks
Ransomware, BEC, insider risk
SOAR Automation
Ticketing, enrichment, containment
Threat Hunting
Hypothesis-driven hunts
Education
B.S. in Computer Science (Security Focus)
Built with v0