Principal Security Specialist driving Microsoft Sentinel, Defender XDR and Zero Trust programs across critical Australian industries
About
Marco Park is a Principal Security Specialist at Data#3 with deep expertise in Microsoft Sentinel, Microsoft Defender XDR, and Zero Trust architecture. He has successfully led multiple SOC transformation programs and security architecture engagements for clients in energy, banking, defence and mining. With 14 years of industry experience, Marco brings a pragmatic, risk-focused approach to building resilient security operations and modernising threat detection capabilities.
Experience
- 2022-03 — PresentCurrentPrincipal Security SpecialistData#3
Lead security consulting engagements focusing on Microsoft security platforms, Zero Trust strategy and SOC transformation for enterprise clients in regulated industries.
- Architected and delivered two full SOC build programs from requirements through to operational handover
- Developed Zero Trust roadmaps adopted by major energy and mining clients
- Mentor for mid-level security consultants across the national practice
- 2019-01 — 2022-02Senior Cyber Security ConsultantDeloitte Australia
Delivered complex security transformation projects for banking and government clients with a focus on Microsoft cloud security and threat detection platforms.
- Led Microsoft Sentinel deployment for a Tier-1 Australian bank
- Conducted Zero Trust maturity assessments for two defence-related agencies
- Contributed to national security thought leadership on XDR technologies
- 2016-06 — 2018-12Cyber Security AnalystWoodside Energy
Provided operational security support and project delivery within the OT and enterprise environments of a major Australian energy producer.
- Designed and implemented SIEM use cases covering both IT and OT environments
- Played key role in incident response during a significant ransomware attempt
- Developed security monitoring capability for upstream mining operations
- 2013-07 — 2016-05Security Operations EngineerCommonwealth Bank of Australia
Operated within the bank's 24x7 Security Operations Centre managing detection technologies and responding to advanced threats.
- Managed Splunk and Microsoft security tooling for enterprise-wide visibility
- Reduced mean-time-to-detect by 45% through custom correlation rules
- Participated in red team exercises and purple teaming initiatives
- 2010-02 — 2013-06Graduate Security EngineerThales Australia
Early career role supporting defence industry security projects and gaining foundational experience in secure systems engineering.
- Supported delivery of protected network solutions for Australian Defence Force programs
- Gained exposure to classified environments and formal security accreditation processes
Projects
- Microsoft XDR and Sentinel Deployment2023-05 — 2024-04Fortescue Metals Group · Mining & Resources · as Security Architect
Deployed unified XDR across 12,000 endpoints and 3 data centres; improved visibility into OT/IT convergence and reduced critical severity incidents by 55%.
Microsoft Defender XDRMicrosoft SentinelAzure MonitorEntra IDWindows 11 Enterprise - Enterprise SOC Transformation2023-02 — 2024-01Confidential Major Energy Retailer · Energy & Utilities · as Lead Security Architect
Designed and delivered a new 24x7 SOC capability; reduced alert volume by 68% and achieved 40% faster mean-time-to-respond within six months of go-live.
Microsoft SentinelMicrosoft Defender XDRAzure ADAzure LighthouseLogic AppsKQL - Zero Trust Architecture Program2022-09 — 2023-08Western Australian Government Department of Defence · Defence · as Principal Consultant
Developed a three-year Zero Trust roadmap and implemented initial controls across identity and endpoint; successfully passed IRAP assessment for protected-level workloads.
Microsoft Defender for CloudAzure AD Conditional AccessMicrosoft SentinelIntunePower BI - SOC Build & Operationalisation2021-03 — 2022-02National Australia Bank · Banking & Finance · as Solution Lead
Led end-to-end SOC build including people, process and technology; delivered 180+ automated response playbooks resulting in 70% reduction in manual triage effort.
Microsoft SentinelMicrosoft 365 DefenderAzure Logic AppsSOAR playbooksKusto Query Language - Threat Detection Modernisation2020-08 — 2021-05Confidential Mining Services Company · Mining & Resources · as Senior Security Consultant
Replaced legacy SIEM with Microsoft Sentinel; achieved 99.7% uptime for security monitoring across global operations and improved detection of credential-based attacks by 82%.
Microsoft SentinelDefender for EndpointAzure AD Identity ProtectionPower Automate - Security Architecture Review & Zero Trust Pilot2019-11 — 2020-06Chevron Australia · Energy & Utilities · as Security Architect
Conducted comprehensive architecture review and piloted Zero Trust controls for LNG operations; identified and remediated 14 high-risk misconfigurations.
Azure ADConditional AccessMicrosoft Defender for IdentitySentinel
Beyond the day job
Skills and experience from outside the day job — community, volunteering, hobbies and more.
- Cyber Security MentorVolunteeringCyber Security Cooperative Research Centre (CSCRC)
Mentors university students and early-career professionals from diverse backgrounds entering the cyber security field.
CommunicationKnowledge TransferMentoring - Perth Coastal Kayaking ClubSport / coachingPerth Coastal Kayaking Club
Regular participant in ocean paddling and occasional volunteer safety officer for club events.
Crisis ResponseRisk ManagementTeam Coordination - Dungeon MasterHobbyWeekly D&D group
Runs a long-running Dungeons & Dragons campaign — improvises narrative, adjudicates rules on the fly, and keeps six players engaged for hours.
Conflict ResolutionFacilitationImprovisationStorytelling
Peer endorsements
No endorsements yet.