
Designed and implemented a SOC monitoring workflow using Splunk SIEM to detect, investigate, and respond to security incidents across endpoint, email, and network environments. Performed log analysis, IOC investigation, MITRE ATT&CK mapping, and root cause analysis while integrating ServiceNow for incident tracking. Focused on reducing false positives and improving overall threat detection efficiency.
If I were to do this project again, I would place greater emphasis on automation and scalability. I would integrate additional security tools and threat intelligence feeds, implement automated response workflows to reduce manual effort, and expand the monitoring scope to include cloud workloads. I would also improve dashboard visualization and optimize detection rules to further reduce false positives and improve overall incident response efficiency.