Contact
contact@mrciano.com
Coming soon
Remote · Global
Skills
SIEMEDRDetection EngineeringIRSOARCloud SecLinuxKQLSigma
Certificates
- SEC504 (Incident Handling)
- AZ-500 (Azure Security Engineer)
- GCIA / GCED equivalent experience
Tools
SplunkDefenderCrowdStrikeElasticAzure SentinelOktaMDESuricata
Experience
SOC Engineer
2023 — Present
Built detections, triage runbooks, and automated containment; drove continuous improvement of MTTR and coverage.
- Auth anomaly detections (impossible travel, MFA fatigue).
- IR playbooks integrated with SOAR for containment.
- Threat hunting routines feeding detection backlog.
Detection Engineer
2021 — 2023
Authored Sigma/KQL rules, tuned alert quality, improved signal‑to‑noise ratio.
- Coverage mapping to ATT&CK.
- Metrics for drift, efficacy, and FP rate.
- PR reviews and deployment pipeline for content.
Projects
Cloud Detections Pack
IAM anomalies, persistence, key exposure
IR Playbooks
Ransomware, BEC, insider risk
SOAR Automation
Ticketing, enrichment, containment
Threat Hunting
Hypothesis-driven hunts
Education
B.S. in Computer Science (Security Focus)