Detection Engineer | SOC Automation | Threat Hunting
Security Analyst focused on designing autonomous SOC architectures, SIEM-based detection engineering workflows, and cyber threat intelligence pipelines. Experienced in bridging the gap between manual alert triage and programmatic defense by building deterministic SOAR pipelines and authoring high-fidelity, MITRE ATT&CK-mapped detection logic.
Currently open to remote opportunities in Detection Engineering, Threat Intelligence, and Security Automation.
Let's save each other some time. If your screening process requires a rigid keyword match or a standard Computer Science degree, we are not a match. You can safely move on.
I hold a B.A. in Political Science. It is a non traditional background, but it gives me a massive edge. Security is about understanding human intent, contextualizing business risk, and delivering actionable intelligence.
I am open to junior and mid level roles, but my technical output is not junior. You will be hard pressed to find another candidate at this level who architects deterministic SOAR pipelines, writes custom MITRE mapped Sigma rules, and integrates threat intelligence environments completely from scratch.
If you want someone who actually builds, executes, and thinks critically, my work speaks for itself.
- Detection Engineering & SIEM: Wazuh, Microsoft Sentinel, Splunk (SPL), ELK Stack, Sigma Rules, Sysmon, Windows Event Logs.
- SOAR & Automation: N8N agentic pipelines, REST API integration, Python, PowerShell, Bash, JSON processing, webhook architecture.
- Threat Intelligence & Emulation: MISP, CISA KEV catalog integration, MITRE Caldera, OSINT, hypothesis-driven threat hunting.
- Incident Response & Validation: Velociraptor, ProcessGuid pivoting, host/process tree forensics, Diamond Model.
- Cisa-KEV-Threat-Intel-Orchestrator: Zero-touch pipeline built with N8N and Google Gemini that automatically converts newly weaponized CVEs from the CISA KEV catalog into production-ready Sigma detection rules.
- SOC Automation Lab: End-to-end automated SOC detection and response lab documenting attack simulation (MITRE Caldera), detection (Wazuh), enrichment/notification (N8N), and forensic validation (Velociraptor).
- Phishing Email Triage Pipeline: Autonomous triage pipeline utilizing N8N, VirusTotal API, and Google Gemini to extract IOCs and aggregate reputation scores, reducing time-to-verdict from 20 minutes to under 45 seconds per alert.
- Detection-Rules & Analysis: Validated custom Sigma detection rules for critical techniques observed during APT29 simulation (credential access, lateral movement, persistence) across a dataset of 196,071 log events.
Authoring technical forensics series and practical engineering guides on Medium and Substack (Detection Desk). Key topics include:
- Advanced process tree forensics, network correlation, and detection logic.
- Integrating Wazuh and N8N for automated incident response workflows.
- Practical ELK stack configuration and debugging for SOC environments.
- LinkedIn: linkedin.com/in/manishrawat21
- Email: rawatmanish21@outlook.com
- Medium: medium.com/@manishrawat21
- Substack: substack.com/@manishrawat21
- GitHub: github.com/manishrawat21
