Josh Liburdi on Brex’s Innovative Approach to Data Quality in SecOps
Apr 24, 2024
In this episode, Jack Naglieri speaks to Josh Liburdi, Staff Security Engineer at Brex. Josh explains the process of developing their new security data pipeline toolkit, Substation and how it has been working. He also discusses the importance of quality data, highlighting the impact of data transformation.
Josh also shares his insights on the value of human analysis in SecOps and modern incident response strategies, from handling alerts to understanding program gaps.
Topics discussed:
The development process of Substation, a security data pipeline toolkit to enhance log collection and data quality for threat detection
The importance of quality data in security operations and how sometimes it is helpful to collect it even if you don’t analyze it right away.
The data transformation process and its impact on threat detection, as well as how it’s made the team at Brex more efficient.
Enhancing the ability to write better rules after implementing Substation.
Josh's advice for security practitioners: it’s ok to seek help and “soft skills” are important.
By continuing to use this website you consent to our use of cookies.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.