byte0x0f0x3f
yesterday at 11:24 PM
Location: Houston, TX, USA / Remote
Remote: Yes
Willing to relocate: Open to the right role, prefer remote
Technologies: SIEM/SOAR, Splunk, Azure Sentinel, ELK/OpenSearch, Logstash, Cribl, Fluentd, Datadog, XSOAR/Demisto, Splunk Phantom, Swimlane, Tines, SentinelOne, Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, CrowdStrike, OpenEDR, Wiz, Palo Alto, CyberArk, Okta, SAML/SSO/ADFS, Intune, Jamf, Kandji, osquery, KnowBe4, Rapid7, Cisco Umbrella, Abnormal Security, Avanan, Zeek, Suricata, Security Onion, SIGMA, YARA, STIX/TAXII, MISP, TheHive, Cortex, Python, Go, Bash, Docker, Kubernetes, Helm, AWS, Azure, GCP, Qubes/Xen, DRAKVUF, libVMI, LLM integration, RAG, MCP, prompt engineering, AI security, EU AI Act, Google SAIF, ISO 42001, SAST/SCA/IAST/DAST automation
Résumé/CV: available on request
Email: keatonarter@pm.me
Senior Security Engineer with 5+ years of experience across SIEM/SOAR automation, detection engineering, cloud security, endpoint security, threat intelligence, and incident response. I have built and maintained large-scale logging and detection pipelines, custom SOAR integrations, Splunk/Azure Sentinel/ELK detections, XSOAR/Phantom/Swimlane playbooks, and security automation workflows for federal and enterprise environments.
Recent work includes securing Azure-hosted Logstash collectors, integrating Microsoft Sentinel / Log Analytics ingestion from endpoints, appliances, APIs, and network devices, hardening deployment pipelines with Git tag verification, cryptographic signatures, SHAsum validation, and pinned Docker image digests, and reducing SOC alert fatigue through better detection logic and automation.
I am especially interested in roles around security automation, detection engineering, cloud security, AI security, product security, incident response, or security platform engineering. I enjoy making security quieter, faster, and easier for engineers and analysts to live with.