v
vasilis_mantas

Vasilis M

@vasilis_mantas

Senior Threat Detection Engineer

Greece
Greek, English
About me
I am a Threat Detection & Response Expert specializing in securing digital landscapes against emerging cyber threats. My expertise spans SIEM engineering, threat detection, and security automation, blending deep cybersecurity knowledge with a strong DevOps foundation to create resilient security operations. I thrive in dynamic environments that demand incident response and automation-driven defense strategies.... Read more

Skills

v
vasilis_mantas
Vasilis M
Offline • 
Average response time: 1 hour

See my services

Cloud Network & Security
I will tune defender kql detections and write threat hunting queries
Professional Industry Articles
I will write cybersecurity related articles and blog posts

Work experience

Obrela

Senior Threat Detection Engineer

Obrela

Dec 2024 - Present1 yr 9 mos

-Author and tune threat detection analytics in Azure Sentinel and Microsoft Defender XDR using KQL, covering network, endpoint, and cloud data sources -Lead threat hunting initiatives targeting novel attack patterns and zero-day coverage, mapped to MITRE ATT&CK -Architected the CTEM (Continuous Threat Exposure Management) service detection pipeline on Microsoft Defender XDR, covering telemetry ingestion, detection logic, and MSS analyst workflows -Implemented 150+ alert tunings in Azure Sentinel, decreasing noise by up to 70% for high-priority detections while preserving coverage fidelity. -Review and QA detection analytics authored by team members; mentor junior analysts on KQL and threat-informed defense

Neurosoft

Security Operations Engineer

Neurosoft

Jul 2024 - Dec 20245 mos

-Architected and maintained QRadar SIEM infrastructure supporting 30+ managed security services customer environments -Standardized log onboarding for 30+ MSSP customers, reducing integration time and improving consistency across customer deployments -Optimized QRadar infrastructure through improved backup management and disk allocation strategies -Introduced Ansible for infrastructure provisioning and repetitive deployment tasks, enabling rapid SOC R&D environment setup. -Authored and maintained playbooks and operational documentation for incident response workflows