Detection engineering
KQL, MITRE ATT&CK mapping, use-case design and migration, and detection-as-code pipelines that validate a rule before it reaches production.
Cloud security architect · Kolkata, India
Twelve years in cybersecurity, from SOC analyst to architect. I design Microsoft Sentinel, Defender XDR and SOAR solutions for enterprise clients, and I build governed agentic AI — systems where models draft and people decide, with every step on the record.
What I work on
KQL, MITRE ATT&CK mapping, use-case design and migration, and detection-as-code pipelines that validate a rule before it reaches production.
Logic Apps, Azure Functions and Graph APIs for alert enrichment, identity containment and the ticketing work analysts should not be doing by hand.
LangGraph workflows with specialist LLM agents, human approval gates and Langfuse tracing — so AI assists triage and design without acting unchecked.
Prompt-injection boundaries, tool permissions and agent governance, mapped to the OWASP LLM Top 10 and the NIST AI Risk Management Framework.
Selected work
Some of this runs in private repositories. Happy to walk through the design in a conversation.
A LangGraph agent that triages a Microsoft Sentinel incident and stops for human approval before anything is dispatched. Deterministic enrichment and ATT&CK mapping run before any token is spent; incident text is treated as untrusted input. Runs with no API key.
A governed multi-agent framework for security delivery: specialist agents for Sentinel design, KQL authoring, architecture review and documentation, run by a workflow engine with approval gates, an append-only audit journal and full LLM observability.
A Python engine that turns a schema-validated architecture model into editable enterprise diagrams, with AI generation behind deterministic confidence gates and an independent reviewer agent that cannot approve its own work.
A KQL learning path from first query to threat hunt, plus a Sentinel table library with sample logs and MITRE-mapped hunts, built so practitioners can learn the reasoning rather than copy queries.
Writing
Why approval gates, independent review and an audit trail matter more than the prompts.
What to trace in a security workflow, and what must never be logged.
Version-controlled detections, validation gates and the review model around them.
Catching a broken analytic rule before it reaches the production workspace.
Detection engineering, Sentinel and Defender delivery, or how to put guardrails around agents that touch production. LinkedIn is the quickest way to reach me.