Jason Vasquez

Senior Detection Engineer at Bloomberg

Building LLM agents for detection engineering. Sigma contributor. Detection-as-code across Splunk and LogScale. DFIR.

About

I'm a detection engineer at Bloomberg. I have spent 13 years there, moving from the service desk through security architecture, threat hunting, and incident response into my current role, so I write detections with a working memory of how alerts get triaged, escalated, and investigated.

Lately most of my time goes into agentic tooling for the detection lifecycle: an LLM-powered tuning agent that validates its own suggestions against live SIEM data, and an agent-driven detection engineering environment wired into our security stack.

Experience

Bloomberg L.P. 2012 to present

Senior Detection Engineer

Detection Engineering, Princeton, NJ (hybrid)

  • Built and shipped an LLM-powered detection tuning agent. It reads false-positive investigation notes and validates its own suggested changes by running them in Splunk and LogScale, and saves the team an average of 3.5 hours per day on tuning work.
  • Built an agent-driven detection engineering environment: an LLM coding agent as the orchestration layer, connectors into the security stack, reusable skills for repeatable patterns, and subagents for research, detection writing, and false-positive analysis.
  • Used a data source migration to review and rework the macOS detection set, improving the 20% that were ineffective or stale.
  • Maintain a large detection library across a dual-SIEM environment (Splunk and LogScale); own threat and detection research and process improvement for the function.

Cyber Incident Response Team

New York City metro area (hybrid)

  • Handled escalations from Triage and Threat Hunting; led or contributed to digital forensics and incident response.
  • Owned detection research and detection library maintenance (tuning, enhancing, pruning).
  • Onboarded an ITDR platform to extend identity-based threat detection.
  • Worked with Engineering to stand up an S3-compatible forensic storage platform able to retrieve artifacts from any internal cloud, simplifying artifact collection during IR.
  • Wrote a Python tool that flags stored hashes as malicious in the in-house threat intel platform using VirusTotal data, and pulls IoCs from VT by threat actor or other criteria.
  • Supported a new EDR rollout: selected training for SOC teams, integrated alerts into the SIEM, and tuned the initial detections.

Threat Hunting and Intelligence Analyst

New York, NY

  • Threat hunting, incident handling and response, alert escalations, and testing of new rules and alerts.

Security Analyst / Architect

Security Architecture and Engineering, New York City metro area

  • Responsible for security on the corporate LAN: investigated non-standard access requests, monitored and responded to non-standard changes, built and audited security controls, and ran security reviews on new systems and devices.
  • Identified gaps in security coverage and designed and built controls to close them; found vulnerabilities in systems and applications and drove remediation with owners.
  • Authored security procedures for infrastructure and operations teams so new systems were built and administered to policy.

Service Desk Analyst

New York City metro area

Projects and open source

Sigma rules, open source contributor

Ongoing contributor to Sigma, the open standard for portable, vendor-agnostic detection rules. Contributions come out of day-to-day detection engineering work across a dual-SIEM environment.

Certifications

SANS training

Skills