Profilbild von Bastian Haberl Consultant und Engineer IT Security, Security Architect aus Kuemmersbruck

Bastian Haberl

teilweise verfügbar

Letztes Update: 06.09.2022

Consultant und Engineer IT Security, Security Architect

Abschluss: Master of Engineering
Stunden-/Tagessatz: anzeigen
Sprachkenntnisse: deutsch (Muttersprache) | englisch (verhandlungssicher) | französisch (Grundkenntnisse)

Skills

-----
Personal focus on projects with the following areas:

1) Splunk Phantom (Senior Positions/Solutions Architect  Professional Services) and Splunk Enterprise (Admin Certification in Progress)
2) SOAR in general (Palo Alto Networks Demisto, Siemplify)
3) Penetration testing (junior level) - teaming with senior penetration testers would be beneficial
4) Incident Response + Digital Forensics, SOC Analyst
5) Security Management/Risk Management
6) Security Architecture Development, ISO27k1 etc.
-----

Experience from various projects in international environments as project lead, team lead and project member with international colleagues  in:

 
  1. SIEM/Logmanagement + UseCase Development + UseCase Management (ArcSight, Splunk + Use Case Framework)
  2. Cyber Defense Services - 1st/2nd Level + Incident Handler/Manager
  3. Transforming CDC Operations Processes and Runbook development (Alarm/Incident Management)
  4. SOAR - Trusted Advisory Services (PoCs and Project Management) SOAR - Implementation of solutions - Siemplify, Splunk Phantom, Demisto, Resilient
  5. Metrics  and Reporting (KPIs)
  6. Deception Technology - Implementation and Advisory Services (PoCs and Project Management)
  7. Intruder Hunting with Deception Technology - Cymmetria MazeRunner
  8. Inhouse trainer for Splunk Phantom (Basic and Advanced/Power User Training)

Knowledge in
1) SOX
2) PCI DSS

Personal Interests:
1) Security Transformation, Security Architecture, CDC Management, Risk Management, Security Strategy, Incident Management
2) Penetration Testing, CDC Technology, IT Forensics

Languages:
German - mother tongue
English - fluent (spoken and written)

Degree:
B.Eng - Engineering & Management
M.Eng - Electrical Engineering and Information Technology

Certifications:
GCIH - GIAC Certified Incident Handler
Splunk Power User
ICO ISMS Security Officer according to ISO/IEC 27001:2013

Programming and Scripting Languages:
C/C++
C#, .NET
VBS/VBA
Python

Projekthistorie

05/2019 - bis jetzt
SOAR Engineer for Siemplify/ChronicleSOAR and Senior Security Analyst
Telecommunication provider (Telekommunikation, >10.000 Mitarbeiter)

  1. Implementing and maintaining SOAR platform Siemplify/Chronicle SOAR
  2. Playbook Developemt (Triage and Incident Management Playbooks)
  3. Development of SOC KPI's and Metrics
  4. Development of SOC Processes

03/2023 - 07/2023
XSOAR PS

  • Installation and Setup of a multi-tenant XSOAR environment
  • Playbook Review and Development
  • Setup of Integrations
  • XSOAR Training

11/2020 - 08/2022
Senior Security Analyst
IT Dienstleister (Versicherungen, 1000-5000 Mitarbeiter)

- Zusammenarbeit mit Security Architekten für SOC Aufbau
- Schwachstellenmanagement
- Incident Management/Handling
- Prozessoptimierungen
- (technische) Vorfallsanalyse

07/2021 - 09/2021
Short XSOAR PS Project - Initial Setup of SOAR platform

  • Initial Setup of Palo Alto Networks XSOAR Platform (Installation, Verification, etc.)
  • Analysis and architecturing of first customerm Playbooks

01/2020 - 09/2020
Technical Lead SOAR Team Splunk Phantom
Bank (Banken und Finanzdienstleistungen, >10.000 Mitarbeiter)

  1. Playbook Development
  2. Development of SOAR Architecture
  3. App Development
  4. Project Management
  5. Leading development team

12/2018 - 12/2019
SOAR Engineer Splunk Phantom
Bank (Banken und Finanzdienstleistungen, >10.000 Mitarbeiter)

  1. Playbook Development
  2. Development of SOAR Architecture
  3. App Development
  4. Project Management

09/2019 - 10/2019
Product Auditor - Trusted Advisory Services
Security Application Vendor (Internet und Informationstechnologie, 50-250 Mitarbeiter)

  1. Analysis of application
  2. Creating audit report
    • recomendations for strategic positioning at the market
    • technical gap analysis - product capabilities vs market
    • Providing potential scenarios for further investment

10/2017 - 11/2018
Security Analyst - 1st and 2nd Level + Incident Handler/Manager
Telecommunication provider (Telekommunikation, >10.000 Mitarbeiter)

  1. Security Operations
  2. Runbook development (Triage and Incident Management)
  3. Handling of incidents with lower criticality (no crisis management)
  4. Development of Splunk Correlation Searches
  5. Development of SOC KPI's and metrics for management reports

Reisebereitschaft

Weltweit verfügbar
Wohnort: München
Arbeitsorte: flexibel

Ab 01.01.2021:
Projekte in Nürnberg und Regensburg gesucht bzw. bevorzugt
Generell aber flexibel
Profilbild von Bastian Haberl Consultant und Engineer IT Security, Security Architect aus Kuemmersbruck Consultant und Engineer IT Security, Security Architect
Registrieren