Developing an internal SOAR platform for the MDR team and customers. Built RESTful APIs and integrations with third-party security platforms — including CrowdStrike, Splunk, LogRhythm, and Darktrace, among others — within a microservices architecture. Led and coordinated team efforts to optimise performance and delivery quality. Built an AI-driven solution that enriches security alerts and automation playbooks, reducing SOC analyst processing time by 30%. Designed data aggregation and sync functionality handling hundreds of security alerts per minute. Created comprehensive training materials and product documentation.
Worked on NDR (Network Detection and Response) product within a microservices architecture on GCP, developing custom security rules for network traffic analysis. Built RESTful APIs in Go and Python scripts to automate DevOps processes. Mentored two junior Python developers. Increased test coverage to 95% and resolved 100% of linter issues. Identified and resolved performance bottlenecks, improving service request processing speed by 10×.
Developed Splunk applications in Python for collecting and storing network traffic data, building dashboards, and implementing automated security alert rules. Developed a high-performance Python handler processing up to 1 million network events, and Python-based security alerts handling up to 100,000 events per minute. Also began NDR development as a Go developer, and conducted R&D on information security products and network protocols as an R&D Specialist.