Nathan Fanelli

Detection and response. SIEM operations, Microsoft 365 security, and incident handling.

I have run security end to end in production — daily alert triage, investigation, detection tuning, and incident response as the sole security owner for a 50-person organization on Microsoft Defender XDR and Sentinel.

Now inside a channel-exclusive MDR provider — deploying CrowdStrike Falcon Next-Gen SIEM on LogScale, authoring detection content and custom IOAs, and running threat hunting across partner environments.

Available for remote contract work — US business hours

Experience

SIEM Solutions Engineer

Jun 2026 — present

Vijilan Security · Channel-exclusive MDR provider · Remote

  • Deploy and onboard CrowdStrike Falcon Next-Gen SIEM on LogScale for MSP partners and enterprise clients — log source scoping, ingest architecture, parser development, and retention modeling.
  • Author detection content on Next-Gen SIEM data: CQL correlation rules, custom IOAs, and Vijilan-managed rules across third-party telemetry including Entra ID, Defender, Fortinet, Mimecast, and Sysmon.
  • Tune and maintain deployed detections — false positive reduction, threshold calibration, and governed exclusions with approver and expiry.
  • Run threat hunting across non-Falcon data sources, correlating identity, email, network, and endpoint telemetry into single cases.
  • Technical lead on MSP and enterprise opportunities: discovery, architecture sessions, proof-of-value evaluations, and engagement scoping into SOWs.
  • Own detection and response as the technical authority for a book of 20 MSP and MSSP partners and their end clients.

Security-Focused IT Systems Administrator

Jul 2025 — Mar 2026

Friede and Associates, Inc. · Sole IT and security owner, 50-person organization

  • Ran Microsoft Defender XDR and Sentinel in production as the only security operator: daily endpoint alert triage, investigation, KQL hunting, and end-to-end incident response.
  • Wrote and tuned Sentinel analytics rules to cut false positives; built the escalation and containment process from nothing.
  • Engineered identity controls in Entra ID — Conditional Access policy design, MFA enforcement, privileged access review — and hardened mail flow against phishing.
  • Operated vulnerability management with Qualys on a fixed patch and remediation cadence across endpoints and servers.
  • Managed Intune device configuration, compliance policy, and endpoint hardening baselines across the fleet.
  • Authored a NIST SP 800-34 disaster recovery plan and maintained SP 800-171 control documentation through audit.
  • Migrated all IT and security operations in-house from an outside MSP in six weeks — $53,200/yr saved, plus $5,120/yr cut from Azure spend.

Product Support Specialist II

Sep 2022 — Nov 2024

J. J. Keller and Associates, Inc. · Remote

  • Root-caused a critical vulnerability in a fleet ELD application driving more than half of high-volume support tickets, and drove remediation with engineering.
  • Owned escalated technical troubleshooting for enterprise clients across device, network, and application layers.
  • Authored the runbooks and knowledge base the support team worked from.

Hands-on practice

Top 1%global rank
469rooms completed
57badges

Public profile: tryhackme.com/p/th4d1g1m0rtal

  • SOC Level 1 and Level 2 paths worked end to end — SIEM query and correlation, alert triage workflow, escalation practice.
  • Phishing analysis: header and payload inspection, URL and attachment detonation, user-reported email investigation.
  • Endpoint and network forensics: Windows event log analysis, process and persistence hunting, packet inspection with Wireshark.
  • Threat hunting and detection: MITRE ATT&CK technique mapping, IOC pivoting, and writing queries against attacker behavior rather than signatures.

Certifications

Working knowledge

SIEM
Microsoft Sentinel (KQL), CrowdStrike Next-Gen SIEM on LogScale (CQL), Splunk (SPL), log source onboarding, detection tuning
Endpoint and XDR
Microsoft Defender XDR, Defender for Endpoint, CrowdStrike Falcon
Triage and incident response
Alert triage, false positive reduction, phishing analysis, containment and eradication, NIST incident response lifecycle
Identity and cloud
Entra ID, Conditional Access, MFA, Microsoft 365, Azure, Active Directory, Group Policy
Tooling
Qualys, Nmap, Wireshark, Burp Suite, PowerShell, Bash
Frameworks
NIST CSF, SP 800-53, SP 800-171, SP 800-34

Contact

nathan@nathanfanelli.com

Fully remote, US business hours. Open to contract and full-time detection, SOC, and Microsoft 365 security work.

github.com/th4d1g1m0rtal