I build and run enterprise SIEM and detection platforms. 25,000+ log sources onboarded, and incident response made 35% faster through automation. Say hello.

Selected work 5 projects

Brought detection engineering, SIEM engineering, and 3+ teams onto one approval and reporting workflow, with automated reporting for faster response and clearer cross-team visibility.

Built and manage the Splunk platform behind a bank's security operations: 15,000+ data sources, machine learning for better detection accuracy, and custom Splunk apps.

An ML-based solution that surfaced unmanaged assets across 100,000+ devices for a 10,000+ employee organization. Presented at an international conference.

Ran purple team engagements and turned the findings directly into new Splunk correlation searches, then tuned use cases to cut false positives.

Onboarded 10,000+ log sources, built 50+ ArcSight Flex Connectors, and kept an integration tracker covering 5,000+ assets to catch integration issues early.

About

I'm a Splunk Core Certified Consultant working across the full SIEM lifecycle: architecture and implementation, detection content engineering, security automation, and incident response.

I started in 2013 as a service engineer, moved through every SOC tier from L1 analyst to L3, and now lead SIEM and detection engineering at AL Rajhi Bank. Along the way I've worked with Splunk, ArcSight, Microsoft Sentinel, Google SecOps, and Cortex XSIAM.

  • CurrentlySenior SIEM & Detection Engineer, AL Rajhi Bank
  • SIEM platformsSplunk (Core, ES, App Dev), Google SecOps, ArcSight, Microsoft Sentinel, Cortex XSIAM
  • Detection & responseDetection engineering, purple team, threat hunting, SOAR, digital forensics, malware analysis
  • EngineeringPython, Java, C#, SQL, Splunk app and add-on development
  • EducationB.Tech, Information Technology, Anna University

Experience Since 2013

AL Rajhi Bank, Riyadh, Saudi Arabia. Nov 2023 – Present

  • Build and manage the Splunk Core and Enterprise Security platform
  • Integrated 15,000+ data sources and applied machine learning to detection
  • Cut incident response time by 35% by automating log management workflows
  • Lead the Detection Management Lifecycle initiative across 3+ teams

SBM, Saudi Arabia. Oct 2021 – Nov 2023

  • Built correlation searches, dashboards, and reports in Splunk
  • Ran purple team engagements and turned findings into detections
  • Led investigation and incident response
  • Upskilled SOC analysts on advanced detection techniques

ATOS Paladion, Saudi Arabia. Dec 2017 – Sep 2021

  • Managed Splunk and ArcSight across client environments
  • Onboarded 10,000+ log sources
  • Developed 50+ Flex Connectors, SOPs, and playbooks
  • Threat intelligence analysis and proactive hunting

Altisource, India. May 2017 – Dec 2017

  • SOC incident response across all severity levels
  • Managed SIEM, Symantec Endpoint Protection, and 3 other tools

Wipro Technologies, India. Aug 2016 – May 2017

  • Implemented a SIEM for a banking client with 500+ log sources
  • SIEM administration and content management

United Health Group, India. Feb 2015 – Aug 2016

  • Advanced threat investigations with ArcSight and RSA Security Analytics
  • Built JSP automation that centralized 40+ SIEM reports

Infosys, India. May 2014 – Jan 2015

  • SOC L1 monitoring and triage with RSA enVision
  • Analyzed 50+ suspicious emails daily

HCL Technologies, India. May 2013 – May 2014

  • Endpoint antivirus support
  • VPN and Citrix support for 500+ remote users

Certifications 6

  • Splunk Core Certified ConsultantSplunk
  • Professional Security Operations EngineerGoogle Cloud
  • Security Operations Analyst Associate (SC-200)Microsoft
  • Certified Digital Forensics Professional (eCDFP)INE Security
  • Certified Ethical Hacker (CEH)EC-Council
  • CCNACisco

Writing All posts

Contact

Have a project or role in mind? Let's talk.

vinish.j.dev@gmail.com

© 2026 Vinish Justin