Tim Harden
Senior SIEM Administrator at VF Corporation
- Role
- Senior Siem Administrator at VF Corporation
- Location
- Austin, TX, US
- LinkedIn followers
- 500 followers
About Tim Harden
As a Senior Administrator in Security Operations Center (SOC) Services, I architect and optimize enterprise‑grade security monitoring, analytics, and threat‑intelligence ecosystems. I integrate AI‑driven workflows into security operations to accelerate detection engineering, strengthen analytics, improve triage, and streamline SIEM content development. By blending AI augmentation with traditional engineering, I increase speed, accuracy, and overall SOC effectiveness.My experience spans Microsoft Sentinel, IBM QRadar, Azure Data Explorer (ADX), Cribl, the ELK Stack, SentinelOne, CrowdStrike, GreyMatter, and multiple cloud and endpoint platforms — giving me end‑to‑end visibility across modern SOC architecture and high‑scale data‑engineering pipelines.I design and implement ingestion architectures across cloud and on‑prem environments, including complete ELK Stack deployments and Filebeat‑driven telemetry flows with advanced parsing, normalization, and enrichment. My work with syslog‑NG, regex‑based parsing, and ETL‑style transformation ensures consistent, high‑fidelity visibility across thousands of data sources.I engineered the organization’s Anomali‑based threat‑intel ingestion ecosystem, automating indicator distribution into Sentinel, QRadar, CrowdStrike, Zscaler, and Check Point to expand threat‑intel coverage and improve threat‑hunting depth.I played a key leadership role in the company’s SIEM migration from QRadar to Microsoft Sentinel — designing ingestion strategies, converting correlation logic into KQL, validating log onboarding, optimizing ADX data models, and guiding the operational cutover. My ADX expertise supports scalable log design, advanced analytics, cost governance, and long‑term data‑model optimization.I’ve integrated SentinelOne telemetry into SIEM/SOAR workflows and strengthened cross‑platform correlation through GreyMatter. My cloud‑ingestion experience includes AWS S3, Azure Event Hub, and extensive 3rd‑party SaaS API pipelines for platforms such as Zscaler, CrowdStrike, SentinelOne, and Check Point.Automation is central to my engineering approach. I use advanced scripting and orchestration frameworks to streamline onboarding, automate API ingestion, manage Sentinel and Azure configurations, validate telemetry, and support recurring operational tasks — leveraging both PowerShell and Python to create scalable, reusable automation patterns.Across all initiatives, I focus on delivering resilient, scalable, analyst‑friendly ecosystems that increase visibility, reduce noise, and mature SOC operations.
Experience
Senior Siem Administrator
Dec 2020 — Present
Oversaw SIEM migration from Qradar to Sentinel. Assisted with implement and migration to Cribl. Rule creation and tuning and working with the SOC. Regularly work with system and platform administrators to architect methods of log ingestion and parsing. Implemented Anomali Threatstream integration server for QRadar, Sentinel, Crowdstrike, ZScaler, CheckPoint. Extensive use of Python, bash, VB and other scripting tools for creating custom syslog delivery solutions and integrations, including Azure, AWS logs using REST API. Implementation of WEF and WinCollect.
Education
New Horizons
Database Administration
2001 — 2001
Austin Community College
Associate of Science - AS, Computer and Information Systems Security/Information Assurance
2009 — 2013
Austin Community College
Associate's degree, Computer and Information Systems Security/Information Assurance
2008 — 2013
San Antonio College
General
1987 — 1988
St. Philip's College
Associates of Applied Science, Computer Maintenance
1991 — 1994
Skills
- Firewalls
- Windows
- Tcp/Ip
- Web Servers
- Lan-Wan
- Technical Support
- Mpls
- Telecommunications
- Vpn
- Comptia Network+
- Security
- Troubleshooting
- Voip
- Networking
- Cisco Technologies
- Ethernet
- T1
- Testing
- Windows Server
- Hardware
- Voice Over Ip (Voip)
- Network Security
- Dos
- Servers
- Switches
- Workstations
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.