Your Expert in SIEM Tuning and Cybersecurity Solutions
SIEM tuning services hunting? Welcome to SIEMtune, where I transform Security Information and Event Management (SIEM) systems into powerful, efficient tools for detecting and responding to cyber threats. With over 25 years of experience in cybersecurity, advanced education in AI and machine learning, industry-leading certifications, award-winning performance, and specialized training, I specialize in optimizing platforms like Splunk, Devo, ArcSight, RSA Netwitness, and QRadar SIEM tuning services to deliver actionable insights, reduce noise, and strengthen your organization’s security posture.
My Mission
At SIEMtune, my mission is to empower businesses with finely tuned SIEM solutions that provide real-time visibility and robust protection against evolving cyber threats. I’m dedicated to simplifying SIEM management, enabling your team to focus on critical threats while ensuring compliance with standards like FISMA, NIST, GDPR, and HIPAA and not focusing on your SIEM tuning services.
Who I Am
I’m a seasoned cybersecurity professional with a robust academic and professional foundation:
- Education:
- Master of Engineering (M.Eng.) in AI and Machine Learning, The George Washington University, 2022–2026 (Expected): Pursuing advanced studies in AI to enhance cybersecurity solutions, with an A grade and active membership in the ISC2 Middle GA Chapter.
- Bachelor of Science (BS) in Applied Computing, Tulane University, 2011–2013: Graduated Cum Laude while working full-time in cybersecurity, specializing in computer science and penetration testing.
- Certificate in Management, Tulane University, 2011–2013: Strengthened leadership and management skills.
- Associate in Applied Science, Information Systems Technology, Community College of the Air Force, 2004–2009: Gained expertise in systems administration during USAF service.
- Associate of Applied Science, Aviation Maintenance Technology, Community College of the Air Force, 2001–2004: Developed technical systems maintenance skills.
- Studies in IT, Tallahassee State College, 1998–1999, and North Florida Community College: Laid the groundwork for my technical career.
- Specialized Training:
- Completed extensive coursework at Tulane University, NCI Information Systems, FedConcepts, and other institutions, covering SQL, Oracle, web development (ASP.NET, HTML, JavaScript, AJAX), intrusion detection systems (DoD IDS Analysis), virtualization (VMware vSphere, NetApp Data ONTAP, SnapManager), and information security management. These courses enhanced my technical proficiency in SIEM tuning, network security, and enterprise systems administration.
- Certifications:
- AWS Cloud Engineer Partner Learning Plan (Amazon Web Services, 2022)
- Splunk 7.x Fundamentals 1 & 2 (Splunk, 2021)
- Certified Ethical Hacker (CEH V8, EC-Council, 2015)
- VMware Certified Professional 5 Data Center Virtualization (VCP 5 DCV, VMware, 2014)
- CompTIA Network+ CE (2010), Security+ CE (2009), A+ CE (2008)
- VMware Certified Professional 3 (VCP 3, VMware, 2009)
- RSA Security Engineer Certified Professional in Security Analytics (2016, Expired)
- RSA Sales Engineer Certified Master in Security Analytics (2016, Expired)
- Security Engineer Associate and Sales Associate in Advanced Security Operations (ASOC, RSA Security, 2016, Expired)
- Delivery Services in ASOC (RSA Security, 2016, Expired)
- Professional Experience:
- Cyber Defense Manager, Program Lead at Nightwing, Mar 2024–Present, Thomas County, GA: Lead cyber defense programs, managing operational, intelligence, and triage challenges for diverse clients, with expertise in project management and strategic communications.
- Cyber Defense Engineer at RTX, Mar 2019–Apr 2024, Remote: Tackled complex cybersecurity challenges, optimizing SIEM platforms and implementing security content for enhanced threat detection.
- Principal Cyber Security Systems Engineer & vSOC Security Systems Engineer at RTX/Raytheon Foreground Security, Apr 2016–Mar 2024: Performed SIEM tuning, security content creation, and team leadership, alongside network and firewall engineering.
- Security Operations Center Systems Engineering at Phoenix Data Security Inc., Apr 2014–Apr 2016: Utilized Splunk, Tenable Security Center, and Swimlane to prioritize alerts, remediate threats, and enhance SOC performance.
- Senior Systems Engineer at NCI Information Systems, Inc., Apr 2012–Apr 2014, Keesler AFB: Supported DoD contracts with virtualization, enterprise domain services, and system hardening.
- Senior Systems Engineer at EADS Defense Security and Systems Solutions Inc., Aug 2010–Jan 2012, Biloxi, MS: Designed network security solutions and led Air Force cyber training.
- Systems Engineer at FedConcepts, Jan 2009–Aug 2010, Camp Lejeune: Managed Marine Corps virtual infrastructure with VMware ESX and NetApp, automating enterprise processes.
- US Air Force, Jan 2001–Jan 2009: Served as Communications-Computer Systems Operations (3C0X1) specialist, administering DoD networks, and as Aircraft Electrical and Environmental Systems (2A6X6) technician, maintaining critical aircraft systems.
- Key Projects:
- Azure to Devo via Cribl, Nightwing: Overcame certificate issues by using Cribl Stream for log parsing and cert exchange, leveraging rex, eval, and mask functions for custom processing.
- Splunk Distributed Deployment Lead Engineer, Raytheon Technologies: Built and maintained a Splunk enterprise across 30+ sites, enhancing performance with Linux administration, Ansible, and regex.
- Splunk to Devo Migration, Raytheon Technologies: Led cybersecurity engineering for a seamless SIEM migration, ensuring robust data integration and threat detection.
- Carbon Black/Splunk Cloud Migration & Eternal Blue Defense, Raytheon Technologies: Migrated 25 sites to Splunk Cloud and identified stolen NSA code (Eternal Blue) using log and packet inspection, isolating patient zero and securing systems with SMB ACLs.
- RSA Security Analytics Implementation, Raytheon Foreground Security, 2015–Present: Configured custom parsers, application rules, and feeds for advanced threat hunting tailored to client enterprises.
- RSA Charge Speaking Engagement, 2016: Delivered a talk on ransomware detection, investigation, remediation, and prevention, showcasing cyber threat intelligence expertise.
- Security+ Boot Camp Lab, NCI Information Systems, 2014–Present: Architected a training lab for CompTIA SY0-401 certification, enabling Air Force personnel to gain cybersecurity skills.
- Honors & Awards:
- Multiple RTX Awards, 2018–2024: Consistently recognized by RTX with numerous Achievement and Spot Awards for accountability, collaboration, innovation, commitment, and contributions to cybersecurity projects, including Splunk collaboration, threat hunting, firewall engagements, and contract renewals.
- Undergraduate Cyberspace Training Plank Owner, US Air Force Air Education and Training Command, 2010: Honored as a founding member of a new cyberspace training program, contributing to its establishment and success.
- IDEA Certificate, Department of the Air Force, 2004: Recognized for innovative contributions to Air Force operations.
- Senior Airman Below the Zone, 437 Aircraft Maintenance Squadron, 2003: Awarded early promotion for exceptional performance in aircraft maintenance.
- Organizations:
- NESCO, 2010–2011: Contributed to cybersecurity initiatives as a member of a professional organization focused on advancing network security and operations.
- Key Skills:
- SIEM Optimization (Splunk, Devo, Cribl, Regular Expressions, Parsing, Log Interpretation)
- SIEM tuning services, Professional Services Consulting
- Cybersecurity Operations (Cyber Defense, IT Security Operations, Enterprise Security)
- Network Security (Cisco Firewalls, Palo Alto Networks, Deep Packet Inspection)
- Vulnerability Management (Penetration Testing, Vulnerability Scanning, Nessus)
- Information Security Management (FISMA, NIST, Information Assurance)
- Systems Administration (Linux, VMware ESX/vSphere, NetApp, Active Directory)
- Scripting and Automation (Bash, Ansible, Git)
- Cloud Security Monitoring (Azure, Microsoft Exchange, ePolicy Orchestrator)
- AI Prompt Engineering (leveraging M.Eng. in AI and Machine Learning)
- SOC Operations (Splunk Distributed Deployment, SOC Engineering)
- Threat Hunting (Eternal Blue, RSA Security Analytics)
- Project and Program Management
- Leadership and Team Development
- Compliance and Risk Management (DoD, GDPR, HIPAA)
- Technical Writing and Communication
- Web Development Basics (HTML, JavaScript, ASP.NET)
- Database Management (SQL, Oracle)
- Business Development
My expertise in tools like Cribl Stream, Splunk, and Devo, along with monitoring Azure Intune audit logs (e.g., DeviceManagementScript operations), enables me to deliver AI-driven, cutting-edge cybersecurity solutions.
What SIEMtune Offers
SIEMtune specializes in making your SIEM work smarter. My services include:
- Custom SIEM Configuration: Tailoring platforms like Splunk, Devo, ArcSight, or QRadar to your threat landscape and business goals.
- Noise Reduction: Filtering false positives to prioritize real threats, improving response times and efficiency.
- Advanced Threat Detection: Crafting correlation rules and dashboards, including cloud-based monitoring for Azure Intune and other platforms.
- Continuous Monitoring and Support: Providing 24/7 SOC services for real-time threat detection and response.
- Compliance and Reporting: Streamlining compliance with FISMA, NIST, GDPR, HIPAA, and PCI-DSS through optimized SIEM configurations.
Why Choose SIEMtune for SIEM tuning services?
- Proven Expertise: Over 25 years of experience across DoD, commercial, and enterprise environments, with partnerships with vendors like Splunk, Swimlane, Devo, and Tenable.
- AI-Driven Solutions: Leveraging my M.Eng. studies in AI and machine learning to enhance SIEM capabilities and threat detection.
- Award-Winning Performance: Recognized for innovation, collaboration, and accountability in high-stakes cybersecurity projects.
- Client-Centric Service: Flexible, responsive, and committed to your success.
My Commitment to You
At SIEMtune, I believe cybersecurity is about protecting your business, data, and reputation. My goal is to make your SIEM a seamless, powerful asset, giving you confidence in a complex digital world.
Get in Touch for SIEM tuning services
Ready to optimize your SIEM and elevate your cybersecurity? Contact SIEMtune today to achieve unparalleled visibility and protection. Let’s secure your future together.
View My LinkedIn Profile | Contact SIEMtune | Explore Our Helpful Documentation