← Back to Portfolio

Flagship Project • Security & Threat Detection

IT Security Infrastructure

Integrated security operations stack for monitoring, case handling, automation, and threat-intelligence sharing.

Production-Oriented Security Operations Integrated SOC Flow

Workflow Illustration

Illustration of disconnected security tools evolving into an integrated SOC workflow across Wazuh, Shuffle, Iris, and MISP

This stack connects security operations that would otherwise stay siloed across separate consoles. Alert ingestion, workflow automation, case handling, and threat-intelligence context become easier to follow when the response chain is structured from detection through resolution.

Business Problem

Security monitoring, automation, case handling, and threat-intelligence workflows lose effectiveness when each function lives in disconnected tooling.

My Contribution

Structured a more coherent internal stack around Wazuh, Shuffle, Iris, and MISP to improve visibility, response workflow structure, and security operations readiness.

Operational Flow

  • Security telemetry and alerts are ingested into a more unified monitoring context.
  • Automation workflows help enrich and route alert handling faster.
  • Case handling supports investigation and response tracking in a more structured process.
  • Threat-intelligence context strengthens incident review and prioritization.

Key Capabilities

  • SIEM-oriented visibility with Wazuh.
  • SOAR automation flow with Shuffle.
  • Case handling support with Iris.
  • Threat-intelligence sharing context with MISP.

Current Status

Status: Integrated internal security workflow focused on connecting monitoring, automation, case handling, and intelligence context into one clearer SOC operating model.

IT Security screen 1 IT Security screen 2 IT Security screen 3

Privacy note: environment details, access endpoints, and security-sensitive configuration are excluded.