Riya Vu
ContractorCybersecurity Consultant (CONTRACTOR)
Brisbane · Brisbane, QLD · riya.vu@data3.com.au
Cybersecurity Consultant specialising in Microsoft Sentinel SOC builds and analytics rule tuning
About
Riya Vu is an experienced cybersecurity specialist with nearly three decades in IT security, risk and compliance. She has delivered complex SOC implementations, threat detection tuning and incident response programs across banking, manufacturing and government sectors. As an independent contractor engaged via her own consultancy, Riya brings deep expertise in Microsoft Sentinel, Palo Alto and Fortinet technologies to Data#3 clients.
Experience
- 2022-03 — PresentCurrentCybersecurity Consultant (CONTRACTOR)Data#3 (via Riya Vu Consulting Pty Ltd)
Long-term contract delivering Microsoft Sentinel SOC solutions, analytics rule development and tuning for enterprise clients.
- Led multiple Sentinel deployments for regulated industries
- Developed custom detection and automated response playbooks
- 2018-01 — 2022-02Senior Security ConsultantDeloitte Australia
Provided cybersecurity advisory and implementation services to large government and enterprise clients with focus on cloud security.
- Designed secure cloud architectures for state government agencies
- Conducted IRAP assessments and remediation programs
- 2014-06 — 2017-12Principal Security ArchitectTelstra Purple (formerly Telstra Enterprise)
Architected security solutions for major enterprise and government customers including next-gen firewall deployments.
- Led Palo Alto and Fortinet firewall modernisation programs
- Delivered managed security services for critical infrastructure
- 2009-05 — 2014-05Cyber Threat Intelligence LeadCommonwealth Bank of Australia
Built and operated the bank's threat detection and SOC capabilities with a focus on advanced persistent threats.
- Developed custom analytics and detection rules reducing mean-time-to-detect by 65%
- Established formal threat intelligence sharing with industry partners
- 2003-02 — 2009-04Information Security ManagerBoeing Australia
Managed security operations and compliance for manufacturing and defence programs.
- Implemented enterprise SIEM platform and associated processes
- Oversaw security for Australian manufacturing sites and supply chain
- 1995-01 — 2003-01Senior Security AnalystQueensland Government (Department of Transport and Main Roads)
Early career role focused on network security, firewall management and incident response for state government infrastructure.
- Managed perimeter security using early Fortinet and Check Point solutions
- Conducted vulnerability assessments and penetration testing
Projects
- Microsoft Sentinel SOC Migration2023-06 — 2024-04Queensland Health · State Government · as Lead Security Consultant
Successfully migrated legacy SIEM to Microsoft Sentinel for 45,000 users, implementing 180+ custom analytics rules and reducing alert volume by 72% while improving detection of ransomware indicators.
Microsoft SentinelAzure MonitorKQLLogic AppsMicrosoft Defender for Cloud - Sentinel Analytics Rule Optimisation Program2022-08 — 2023-05Suncorp Group · Banking & Finance · as Senior SOC Consultant
Tuned and optimised 120 analytics rules resulting in 68% reduction in false positives and 40% improvement in SOC analyst efficiency for the insurance and banking division.
Microsoft SentinelKusto Query LanguageAzure Data ExplorerPower BIMicrosoft 365 Defender - Hybrid SOC Design and Fortinet Integration2021-02 — 2021-12Bluescope Steel · Manufacturing · as Security Architect
Designed and implemented hybrid SOC architecture integrating on-premise Fortinet tools with cloud Sentinel, achieving centralised visibility across 27 manufacturing sites and cutting incident response time by 55%.
Fortinet FortiSIEMFortiAnalyzerPalo Alto Cortex XSOARMicrosoft SentinelAzure AD - IRAP-Aligned Sentinel Deployment2020-03 — 2020-11Department of Environment and Science (QLD) · State Government · as Lead Consultant
Delivered an IRAP-assessed Sentinel environment meeting PROTECTED level requirements for 12 agencies, including automated compliance reporting and 95% automated remediation of security misconfigurations.
Microsoft SentinelAzure LighthouseAzure PolicyPalo Alto Prisma CloudAzure Key Vault - Enterprise SIEM Implementation2019-04 — 2019-12Queensland Treasury · State Government · as Security Lead
Migrated from legacy SIEM to modern Microsoft stack, delivering real-time threat monitoring across 8,500 endpoints with a 60% reduction in operational security costs.
Microsoft SentinelSplunk (legacy migration)Azure AD ConnectPower Automate - Palo Alto Next-Gen Firewall & Threat Detection Enhancement2016-07 — 2017-06National Australia Bank · Banking & Finance · as Principal Security Consultant
Upgraded enterprise firewall estate and introduced advanced threat analytics, blocking 1.2 million additional malicious connections per month and improving threat detection coverage by 82%.
Palo Alto PAN-OSPalo Alto Threat PreventionWildFireAzure Sentinel (pilot)
Beyond the day job
Skills and experience from outside the day job — community, volunteering, hobbies and more.
- Cybersecurity MentorVolunteeringAustralian Cyber Security Centre (ACSC) Cyber Security Awareness Program
Provides guidance to early-career women and students from CALD backgrounds entering the cybersecurity field.
CommunicationKnowledge TransferMentoring - Amateur Radio OperatorHobbyWireless Institute Australia
Holds an Advanced amateur radio licence and participates in emergency communications exercises with state disaster management groups.
Crisis ManagementEmergency ResponseRadio Communications
Peer endorsements
No endorsements yet.