Susquehanna International Group
Blue Team Security Engineer Co-op
- Built a PowerShell module integrating ZeroFox APIs into internal tooling to surface brand/VIP impersonations directly into the triage workflow
- Upgraded Windows Event Collector servers to a modern OS, configured to allow for log ingestion (Sysmon/Windows) across thousands of endpoints
- Triaged and investigated SIEM/EDR alerts using Sysmon/WEC, Microsoft Defender for Endpoint, and network telemetry. Documented findings to close alerts and tune rules
- Investigated employee-reported malicious emails and wrote regex rules to block recurring malspam campaigns
- Developed and tuned detection rules, authored playbooks, tested and maintained existing rules, suppressed noisy alerts, and added IOCs to our database during incidents