On-Prem SIEM Architecture
Built a production SIEM with ELK, Wazuh, Elastic Defend, and n8n to centralize telemetry across 500+ endpoints and network devices.
ELK StackWazuhElastic Defendn8n
Read case study
Each project is written like a recruiter-friendly proof point and a manager-friendly case study: context, approach, tools, and measurable outcome.
Built a production SIEM with ELK, Wazuh, Elastic Defend, and n8n to centralize telemetry across 500+ endpoints and network devices.
Created a reusable detection library and playbook set for SOC operations, improving consistency across triage and escalation.
Ran recurring vulnerability scans and hardening cycles to reduce attack surface across Linux and Windows systems.
Designed multi-site routing, VLAN segmentation, and firewall policy changes to support secure inter-site connectivity.
Automated alert routing and enrichment with n8n to shrink response delays and standardize security notifications.