Profileimage by Bastian Haberl Consultant und Engineer IT Security, Security Architect from Kuemmersbruck

Bastian Haberl

partly available

Last update: 06.09.2022

Consultant und Engineer IT Security, Security Architect

Graduation: Master of Engineering
Hourly-/Daily rates: show
Languages: German (Native or Bilingual) | English (Full Professional) | French (Elementary)

Skills

-----
Personal focus on projects with the following areas:

1) Splunk Phantom (Senior Positions/Solutions Architect  Professional Services) and Splunk Enterprise (Admin Certification in Progress)
2) SOAR in general (Palo Alto Networks Demisto, Siemplify)
3) Penetration testing (junior level) - teaming with senior penetration testers would be beneficial
4) Incident Response + Digital Forensics, SOC Analyst
5) Security Management/Risk Management
6) Security Architecture Development, ISO27k1 etc.
-----

Experience from various projects in international environments as project lead, team lead and project member with international colleagues  in:

 
  1. SIEM/Logmanagement + UseCase Development + UseCase Management (ArcSight, Splunk + Use Case Framework)
  2. Cyber Defense Services - 1st/2nd Level + Incident Handler/Manager
  3. Transforming CDC Operations Processes and Runbook development (Alarm/Incident Management)
  4. SOAR - Trusted Advisory Services (PoCs and Project Management) SOAR - Implementation of solutions - Siemplify, Splunk Phantom, Demisto, Resilient
  5. Metrics  and Reporting (KPIs)
  6. Deception Technology - Implementation and Advisory Services (PoCs and Project Management)
  7. Intruder Hunting with Deception Technology - Cymmetria MazeRunner
  8. Inhouse trainer for Splunk Phantom (Basic and Advanced/Power User Training)

Knowledge in
1) SOX
2) PCI DSS

Personal Interests:
1) Security Transformation, Security Architecture, CDC Management, Risk Management, Security Strategy, Incident Management
2) Penetration Testing, CDC Technology, IT Forensics

Languages:
German - mother tongue
English - fluent (spoken and written)

Degree:
B.Eng - Engineering & Management
M.Eng - Electrical Engineering and Information Technology

Certifications:
GCIH - GIAC Certified Incident Handler
Splunk Power User
ICO ISMS Security Officer according to ISO/IEC 27001:2013

Programming and Scripting Languages:
C/C++
C#, .NET
VBS/VBA
Python

Project history

11/2020 - Present
Senior Security Analyst
IT Service Provider (Insurance, 1000-5000 employees)

- Collaboration with SOC Architect to build a SOC form scratch
- Vulnerability Handling and Management
- Incident Management/Handling
- Process development/optimisation
- Analysis of Security Alerts

05/2019 - Present
SOAR Engineer for Siemplify and Senior Security Analyst
Telecommunication provider (Telecommunications, >10.000 employees)

  1. Implementing and maintaining SOAR platform Siemplify
  2. Playbook Developemt (Triage and Incident Management Playbooks)
  3. Development of SOC KPI's and Metrics

01/2020 - 09/2020
Technical Lead SOAR Team Splunk Phantom
Bank (Banks and financial services, >10.000 employees)

  1. Playbook Development
  2. Development of SOAR Architecture
  3. App Development
  4. Project Management
  5. Leading development team

12/2018 - 12/2019
SOAR Engineer Splunk Phantom
Bank (Banks and financial services, >10.000 employees)

  1. Playbook Development
  2. Development of SOAR Architecture
  3. App Development
  4. Project Management

09/2019 - 10/2019
Product Auditor - Trusted Advisory Services
Security Application Vendor (Internet and Information Technology, 50-250 employees)

  1. Analysis of application
  2. Creating audit report
    • recomendations for strategic positioning at the market
    • technical gap analysis - product capabilities vs market
    • Providing potential scenarios for further investment

10/2017 - 11/2018
Security Analyst - 1st and 2nd Level + Incident Handler/Manager
Telecommunication provider (Telecommunications, >10.000 employees)

  1. Security Operations
  2. Runbook development (Triage and Incident Management)
  3. Handling of incidents with lower criticality (no crisis management)
  4. Development of Splunk Correlation Searches
  5. Development of SOC KPI's and metrics for management reports

Local Availability

Open to travel worldwide
Project preferred in the greater area of Nuremberg and Regensburg as well as Munich
However mix of on-site and home office does work for me as well for national and international projects
Profileimage by Bastian Haberl Consultant und Engineer IT Security, Security Architect from Kuemmersbruck Consultant und Engineer IT Security, Security Architect
Register