Omar Younis
Work About Resume
Exabeam
Exabeam · 2017 — 2018 Archive

One design system across three security products

Exabeam's traction came from Advanced Analytics, a machine-learning behavioral analytics tool. The logs product was in its infancy and Incident Response hadn't shipped. Together the three formed a SIEM platform — and they didn't look or behave like one product.

I joined as the first product design lead, as the team began introducing a scalable pattern library and platform-wide journey maps to close the gaps. The goal was a design system consistent across every product and flow, and extensible according to the principles we'd set.

RoleFirst product design lead
ProductsAdvanced Analytics, logs, Incident Response
UsersSecurity analysts and incident responders
What I shippedFour workstreams
Research Customer interviews, solution research, and an audit of the existing platform against accumulated user feedback.
Planning User stories mapped per roadmap initiative — asset timelines, for instance, letting analysts monitor risky assets and not only risky users.
Playbook builder A UI system for Incident Response's logic-driven playbook builder, so automation could take remediation work off analysts — and so developers could customize the visual framework they built on.
Style guide Master style guides and searchable component libraries, so the team could assemble high-fidelity work fast without drifting apart across products.
ResearchInterviews, solution research, platform audit
Artifacts

In addition to primary research by meeting with customers, we did solution research and audited the existing platform for accumulated user feedback.

Feedback from support tickets, CS calls and interviews was sorted into "how might we" columns and voted on by the team, so a quarter's roadmap started from what analysts had already told us was hard — restarting a data pipeline, managing certificates, reading the risk chart, understanding what the models were doing.

Affinity board — user feedback sorted into how-might-we columns
Affinity board — feedback sorted into how-might-we columns
Dynamic peer groupingMaking the model legible in the UI
Problem

Advanced Analytics scored risk by comparing a user or asset against its peers — people in the same role, machines in the same zone. The grouping was computed, not configured, and it changed as behavior changed. That made the scores accurate and the interface opaque: an analyst saw a number and no way to ask which peers it was measured against.

We dug into user needs and identified what data the UI would need to support, and answered how the UI would adapt and scale across varying data sets and customers.

Asset header, collapsed and expanded — peer group surfaced on expand
Asset header — peer group surfaced on expand
Decision

Peer group became a first-class field in the entity header rather than a setting buried elsewhere, and risk reasons were written to name the comparison in plain language — "access to 519 assets, expected around 6 for group IT" instead of a bare score contribution.

The collapsed header keeps the score and the top connections; expanding reveals peer group, first seen, last seen and last location. An analyst under pressure gets the number first and the reasoning on demand.

Asset risk trend and risk reasons naming the peer group comparison
Risk reasons naming the peer-group comparison
Original — asset activity header, lo-fi
Original — asset activity header, lo-fi
Redesigned activity header
Redesigned activity header
Lo-fi component map
Lo-fi component map
Playbook builder
Playbook builder
Chart system
Chart system
Style guide and component library
Style guide and component library
Table component specification — states, type, flag icons
Table component spec — states and redlines
Takeaway

The most transferable work here was the chart system. Deciding how to label axes, when a legend earns its space, what a tooltip owes the reader, and how a view holds up at different zoom levels over time — that is where a security product either becomes readable under pressure or doesn't.

← All work Next — About →
Click anywhere or press Esc to close