NDA restrictions applied

User Entity Behavioral Analytics

User and Entity Behavior Analytics (UEBA) uses behavioral analytics, machine learning, and automation to detect abnormal activity across both users and devices, strengthening security and supporting zero trust strategies. UEBA expands beyond user activity to include systems like servers, routers, and IoT devices. It is especially effective at identifying insider threats, where attackers use legitimate credentials to evade traditional detection.

My Role

UX Designer and Strategist

Company

IBM - Corporate Enterprise

My Actions

At IBM, I led a forward-facing UEBA initiative, defining a scalable and user-centric approach to threat detection for SOC analysts. I drove market research, identified key differentiators, and aligned cross-functional teams on product strategy. This work resulted in the creation of intuitive workflows that help analysts understand system impact and make faster, more informed security decisions.

Results

36% workflow increase based on current UBA workflow

88% increase in data transparency and architecture

The Problem

Analysts lack confidence in UEBA solutions due to lack of understanding and misconfiguration of the tool, excessive false positives and lack of context around the alert.

The Solution

Deliver a differentiated UEBA experience that enables SOC analysts to quickly review, analyze, and act on threats at a glance.

NDA restrictions applied

User Entity Behavioral Analytics

User and Entity Behavior Analytics (UEBA) uses behavioral analytics, machine learning, and automation to detect abnormal activity across both users and devices, strengthening security and supporting zero trust strategies. UEBA expands beyond user activity to include systems like servers, routers, and IoT devices. It is especially effective at identifying insider threats, where attackers use legitimate credentials to evade traditional detection.

My Role

UX Designer and Strategist

Company

IBM - Corporate Enterprise

My Actions

At IBM, I led a forward-facing UEBA initiative, defining a scalable and user-centric approach to threat detection for SOC analysts. I drove market research, identified key differentiators, and aligned cross-functional teams on product strategy. This work resulted in the creation of intuitive workflows that help analysts understand system impact and make faster, more informed security decisions.

Results

36% workflow increase based on current UBA workflow

88% increase in data transparency and architecture

The Problem

Analysts lack confidence in UEBA solutions due to lack of understanding and misconfiguration of the tool, excessive false positives and lack of context around the alert.

The Solution

Deliver a differentiated UEBA experience that enables SOC analysts to quickly review, analyze, and act on threats at a glance.

NDA restrictions applied

User Entity Behavioral Analytics

User and Entity Behavior Analytics (UEBA) uses behavioral analytics, machine learning, and automation to detect abnormal activity across both users and devices, strengthening security and supporting zero trust strategies. UEBA expands beyond user activity to include systems like servers, routers, and IoT devices. It is especially effective at identifying insider threats, where attackers use legitimate credentials to evade traditional detection.

My Role

UX Designer and Strategist

Company

IBM - Corporate Enterprise

My Actions

At IBM, I led a forward-facing UEBA initiative, defining a scalable and user-centric approach to threat detection for SOC analysts. I drove market research, identified key differentiators, and aligned cross-functional teams on product strategy. This work resulted in the creation of intuitive workflows that help analysts understand system impact and make faster, more informed security decisions.

Results

36% workflow increase based on current UBA workflow

88% increase in data transparency and architecture

The Problem

Analysts lack confidence in UEBA solutions due to lack of understanding and misconfiguration of the tool, excessive false positives and lack of context around the alert.

The Solution

Deliver a differentiated UEBA experience that enables SOC analysts to quickly review, analyze, and act on threats at a glance.