Meta
Security Engineering Intern
May 2025 to August 2025
Built and tuned production detections and response automation using a TTP-based threat modeling approach in a production-scale environment supporting 4B+ users.
- Built and deployed production-grade SQL detections operating on billion-row datasets supporting 4B+ users, using TTP-based threat modeling to align coverage with real-world attacker behaviors.
- Reduced false positives by 60% and cut compute costs by 95% through detection tuning, query optimization, and structured validation in controlled test environments.
- Designed scalable response automation workflows adopted across 10+ detections, decreasing alert triage time by 40% and contributing to a 25% reduction in MTTR.
- Identified and closed a detection gap between data exfiltration and downstream misuse by engineering correlation logic that strengthened defense-in-depth controls.
- Collaborated with Security Operations and Incident Response teams to investigate high-fidelity alerts, shadow SEV escalations, and deliver a standardized threat response playbook to operationalize detection logic.