Architected an enterprise-scale, zero-trust SIEM framework using Splunk Enterprise on AWS EC2. Engineered cross-account ingestion pipelines using Kinesis, S3, and CloudTrail to automate continuous log monitoring, real-world threat detection, and active incident response.
Technical Breakdown (The Details)
Data Sources: Centralized log collection across multiple production, dev, and auxiliary AWS accounts (CloudTrail, CloudWatch, EC2 Logs).
Ingestion Layer: Built structured pipelines utilizing Amazon Kinesis Data Firehose, automated S3 Log Archives, and AWS Security Hub findings.
Processing Layer: Managed log ingestion, universal forwarders, data indexing, and automated threat correlation analytics within Splunk Enterprise Security hosted on EC2.
Automated Response: Formed instant actionable alert workflows triggering AWS Lambda functions for isolated containment and real-time ServiceNow ticketing.
Governance & Zero Trust: Enforced strict validation protocols including multi-account SCP guardrails, IAM least-privilege roles, private VPC Endpoints, and KMS data-at-rest encryption.
Like this project
Posted Jun 23, 2026
Project Title
AWS Cloud Security Architect: Splunk & EC2 SIEM
Project Description
Architected an enterprise-scale, zero-trust SIEM framework using Splunk Ent...