Federal organizations needed consistent security visibility and continuous monitoring across cloud, hybrid, and on-prem environments without every agency rebuilding the same operating model.
A reusable security platform supporting 15+ federal agencies.
I designed, planned, and delivered a Splunk-based SIEM-as-a-Service platform supporting a broader federal SOC-as-a-Service offering. I lead the engineering work behind cloud, hybrid, and on-prem deployments, detection engineering, and continuous monitoring.
- 15+ agencies
- 60,000+ endpoints
- 12 Splunk deployments
- FISMA / OMB M-21-31

As SIEM Team Lead and Senior Security Engineer, I architected and scaled the platform and direct engineers and content developers across agile delivery, detection engineering, and continuous monitoring.
The service spans 12 Splunk Cloud and Enterprise deployments and 60,000+ endpoints, with integrations across CrowdStrike, Zscaler, and Qualys. A reusable content-as-a-service framework standardizes detections to FISMA and OMB M-21-31 requirements.
The platform supports 15+ external federal agencies and DOJ components while making onboarding, detections, and operational delivery more repeatable across participating environments.