← Selected work
01Federal security operations

A reusable security platform supporting 15+ federal agencies.

I designed, planned, and delivered a Splunk-based SIEM-as-a-Service platform supporting a broader federal SOC-as-a-Service offering. I lead the engineering work behind cloud, hybrid, and on-prem deployments, detection engineering, and continuous monitoring.

Sanitized federal security operations center service overview
Challenge

Federal organizations needed consistent security visibility and continuous monitoring across cloud, hybrid, and on-prem environments without every agency rebuilding the same operating model.

My role

As SIEM Team Lead and Senior Security Engineer, I architected and scaled the platform and direct engineers and content developers across agile delivery, detection engineering, and continuous monitoring.

Approach

The service spans 12 Splunk Cloud and Enterprise deployments and 60,000+ endpoints, with integrations across CrowdStrike, Zscaler, and Qualys. A reusable content-as-a-service framework standardizes detections to FISMA and OMB M-21-31 requirements.

Outcome

The platform supports 15+ external federal agencies and DOJ components while making onboarding, detections, and operational delivery more repeatable across participating environments.

View the public SOCaaS overview
Next case studyOn-device AI that helps people reach Inbox Zero faster.