DetectionMITRE ATT&CKCloud
Detection & Response Modernization
Re-architected the detection stack across identity, endpoint, and cloud, mapping coverage to MITRE ATT&CK and cutting mean time to detect for high-severity alerts.
Challenge
The existing monitoring approach missed AI-enabled identity misuse and lacked cloud-native threat context.
Approach
I aligned detections with ATT&CK tactics, standardized telemetry across workloads, and built a response framework for high-risk AI and cloud incidents.
Outcome
The modernization effort delivered faster incident validation, clearer investigator workflows, and stronger coverage for identity and model access anomalies.
Back to projects
Explore the page for practical AI security outcomes and architectural details.