I build and run enterprise SIEM and detection platforms. 25,000+ log sources onboarded, and incident response made 35% faster through automation. Say hello.
Selected work 5 projects
Brought detection engineering, SIEM engineering, and 3+ teams onto one approval and reporting workflow, with automated reporting for faster response and clearer cross-team visibility.
Built and manage the Splunk platform behind a bank's security operations: 15,000+ data sources, machine learning for better detection accuracy, and custom Splunk apps.
An ML-based solution that surfaced unmanaged assets across 100,000+ devices for a 10,000+ employee organization. Presented at an international conference.
Ran purple team engagements and turned the findings directly into new Splunk correlation searches, then tuned use cases to cut false positives.
Onboarded 10,000+ log sources, built 50+ ArcSight Flex Connectors, and kept an integration tracker covering 5,000+ assets to catch integration issues early.
About
I'm a Splunk Core Certified Consultant working across the full SIEM lifecycle: architecture and implementation, detection content engineering, security automation, and incident response.
I started in 2013 as a service engineer, moved through every SOC tier from L1 analyst to L3, and now lead SIEM and detection engineering at AL Rajhi Bank. Along the way I've worked with Splunk, ArcSight, Microsoft Sentinel, Google SecOps, and Cortex XSIAM.
- CurrentlySenior SIEM & Detection Engineer, AL Rajhi Bank
- SIEM platformsSplunk (Core, ES, App Dev), Google SecOps, ArcSight, Microsoft Sentinel, Cortex XSIAM
- Detection & responseDetection engineering, purple team, threat hunting, SOAR, digital forensics, malware analysis
- EngineeringPython, Java, C#, SQL, Splunk app and add-on development
- EducationB.Tech, Information Technology, Anna University
Experience Since 2013
- Build and manage the Splunk Core and Enterprise Security platform
- Integrated 15,000+ data sources and applied machine learning to detection
- Cut incident response time by 35% by automating log management workflows
- Lead the Detection Management Lifecycle initiative across 3+ teams
- Built correlation searches, dashboards, and reports in Splunk
- Ran purple team engagements and turned findings into detections
- Led investigation and incident response
- Upskilled SOC analysts on advanced detection techniques
- Managed Splunk and ArcSight across client environments
- Onboarded 10,000+ log sources
- Developed 50+ Flex Connectors, SOPs, and playbooks
- Threat intelligence analysis and proactive hunting
- SOC incident response across all severity levels
- Managed SIEM, Symantec Endpoint Protection, and 3 other tools
- Implemented a SIEM for a banking client with 500+ log sources
- SIEM administration and content management
- Advanced threat investigations with ArcSight and RSA Security Analytics
- Built JSP automation that centralized 40+ SIEM reports
- SOC L1 monitoring and triage with RSA enVision
- Analyzed 50+ suspicious emails daily
- Endpoint antivirus support
- VPN and Citrix support for 500+ remote users
Certifications 6
- Splunk Core Certified ConsultantSplunk
- Professional Security Operations EngineerGoogle Cloud
- Security Operations Analyst Associate (SC-200)Microsoft
- Certified Digital Forensics Professional (eCDFP)INE Security
- Certified Ethical Hacker (CEH)EC-Council
- CCNACisco
Writing All posts
Contact
Have a project or role in mind? Let's talk.
vinish.j.dev@gmail.com© 2026 Vinish Justin