Disney
Splunk / IAM / SIEM / Security Analytics Contributor
Context
Delivered Splunk-focused IAM and SIEM work for Disney, debugging identity and access-control alerts, building a custom Splunk app, and creating executive dashboards across access-control and identity solutions spanning Disney campuses and offices.
Problem
Disney needed better visibility into identity, access-control, and SIEM alert behavior across a broad physical and enterprise footprint. IAM and access-control systems generate noisy, fragmented, and context-dependent alerts. Without normalization, debugging, and executive reporting, security teams and leadership cannot quickly understand what is broken, what matters, where access-control signals are failing, or how identity/security operations are trending across sites.
What I did
- - Debugged IAM and SIEM alerts across Disney identity and access-control environments.
- - Analyzed alert behavior from access-control and identity systems spanning Disney campuses and offices.
- - Identified noisy, broken, misfiring, duplicated, unclear, or low-signal alert conditions.
- - Built or contributed to a custom Splunk app focused on IAM/security monitoring workflows.
- - Created Splunk dashboards that translated identity and access-control telemetry into usable operational and executive views.
- - Helped normalize and organize IAM/security events so teams could understand trends, alert quality, and access-control posture.
- - Connected low-level SIEM alert debugging to higher-level reporting for security stakeholders and leadership.
- - Focused on practical security analytics: what is firing, why it is firing, where it is happening, whether the signal is trustworthy, and what leaders need to see.
- - Worked with security-sensitive access-control data while preserving confidentiality around internal systems, campus details, facilities, and identity infrastructure.
- - Built experience that later connects directly to Splunk product-security work, Devo SIEM research, Forescout Device Cloud analytics, and AI-driven security evidence systems.
Outcome
- - Improved visibility into Disney IAM and access-control alert behavior through Splunk-based analysis and dashboards.
- - Created a custom Splunk app or app-like Splunk workflow for IAM/SIEM monitoring and reporting.
- - Helped security teams debug and interpret identity and access-control alert behavior across campus and office environments.
- - Created executive dashboarding that made complex identity/security telemetry more understandable to leadership.
- - Strengthened the user's early SIEM/security-analytics foundation before later Splunk, Forescout, and Devo roles.
- - Created a strong portfolio case connecting IAM, SIEM alert debugging, Splunk app development, access-control telemetry, and executive security reporting.
Evidence
- - Worked across Disney access-control and identity solutions spanning campuses and offices.
- - Debugged IAM and SIEM alert behavior.
- - Built or contributed to a custom Splunk app for IAM/security monitoring workflows.
- - Created executive dashboards for identity and access-control security visibility.
- - Public-safe metric language; exact systems, office/campus details, alert rules, source names, event volumes, dashboard screenshots, internal architecture, and sensitive security telemetry are omitted.
Public-safe caveat
This case study is based on user-provided project clarification. It intentionally avoids facility details, internal system names, alert logic, source names, campus/office specifics, screenshots, event volumes, and sensitive identity/access-control telemetry.