Skip to content

Security Operations · Incident Response · Detection Engineering

FredZirbel

I investigate threats, improve detection quality, and build practical workflows that help analysts move from alert to defensible action.

  • Dallas, TX · Remote, hybrid, or onsite
  • Open to relocation within the U.S.
  • U.S. work authorized · No sponsorship required now or in the future
  • 2 years of professional cybersecurity experience
  • Eligible and willing to obtain a U.S. security clearance
  • Available to interview · Two weeks' notice to start

01Impact

Fast response. Durable signal.

16 min

average time to investigation

Fast, evidence-led alert ownership

300+

investigations each month

Across identity, email, endpoint, and cloud

500+

suppression filters engineered

KVP and regex logic reducing recurring noise

02Experience

Critical Start

Promoted from Security Analyst to Principal Security Analyst through three roles of increasing scope in investigations, customer response, detection tuning, remediation, and analyst mentorship.

Principal Security Analyst

Jul 2026 - Present

  • Lead complex, customer requested deep dive investigations into phishing, malware, and identity intrusions across an MDR operation protecting 2,500+ customer environments. Correlate evidence from 30+ security products to determine scope, root cause, and required containment.
  • Maintain a 16 minute average time to investigation while handling 300+ alerts monthly, enabling timely customer escalation and containment.
  • Execute live containment and remediation through a dual authorization workflow that removes attacker access and malicious artifacts, then translate scope, impact, and recovery status into decisions for customer stakeholders during high priority incidents.
  • Train and mentor L1 analysts to use the in-house AI platform effectively, improving investigation efficiency, correlation quality, and client ready writeups.

Senior Security Analyst

Jul 2025 - Jul 2026

  • Reconstructed attacker activity with custom KQL across email, identity, and endpoint evidence while correlating indicators across customer environments to identify shared campaigns, establish root cause, and enable coordinated response.
  • Briefed customer stakeholders during three to five weekly high priority incident calls, delivering findings, attribution, and remediation guidance that informed response decisions.
  • Engineered 500+ KVP and regex suppression filters while validating five or more daily orchestration changes, eliminating thousands of recurring false positives and preventing faulty logic from reaching production.

Security Analyst

Oct 2024 - Jul 2025

  • Triaged identity, phishing, malware, and endpoint alerts across four EDR and SIEM platforms while developing custom KQL to accelerate incident scoping in Microsoft Sentinel and Defender.
  • Produced client ready escalations with attribution, investigation context, and remediation guidance, giving senior responders an actionable basis for customer communication.

03Projects

04Credentials

Earned certifications

6 earned

In progress

ISACA CISM — In Progress

Education

M.S. Cybersecurity & Information Assurance
Western Governors University

B.S. Information Systems
The University of Texas at Arlington

Capability matrix

Engineering capabilities developed through active hands-on projects and continued technical development.

Detection

  • KQL
  • Sigma
  • Microsoft Sentinel
  • Splunk ES
  • MITRE ATT&CK

Investigation

  • Defender XDR
  • CrowdStrike Falcon
  • Cortex XDR
  • SentinelOne
  • Sumo Logic

Engineering

  • Python
  • FastAPI
  • Docker
  • GitHub Actions
  • ELK Stack