I will build and tune siem detection rules for your soc
AI app hardening, productionization, and security focused development
Level 2
Has met high performance criteria and has a proven track record for meeting client expectations.
About this Gig
Struggling with alert fatigue and blind spots in your SOC?
I build and tune high-fidelity detection content so your team catches real threats not noise.
I'm a SOC engineer and vCISO AI-Cybersecurity specialist who handles detection engineering end to end: from log onboarding to production-ready rules mapped to MITRE ATT&CK.
WHAT YOU GET
- Custom detection rules Wazuh, Elastic/KQL, Sigma, Splunk SPL
- MITRE ATT&CK mapping + clear documentation
- Custom parsers/decoders & log normalization
- False-positive tuning that keeps coverage high
- SOAR playbooks (Shuffle, TheHive/Cortex) for auto-response
- Detection coverage gap analysis
WHY ME
Real SOC + SIEM engineering (Wazuh, Elastic Stack)
Every rule tested and documented nothing untested shipped
GRC-aware: aligned to ISO 27001, NIS2,...
Message me before ordering with your SIEM and use case, and I'll confirm scope + timing.
Let's turn your SIEM into a system that fires on the right things.
