Security Engineer
I build detection systems that find attackers based on how they actually behave not just what tools they use. My work involves threat hunting, detection engineering, and incident response: writing KQL and Sigma logic against MITRE ATT&CK techniques, automating triage workflows, and closing the gap between attacker activity and visibility. I care about understanding adversary tradecraft well enough to anticipate it, detections and sharing the knowledge I gained with the wider security community.
I write behavioral detections grounded in attacker technique: process injection patterns, LOLBin abuse, credential access signals, rather than IOC matching. I map detection logic to MITRE ATT&CK and tune for signal quality over alert volume.
Proactive hunting using KQL across endpoint, identity, and network telemetry. I look for anomalies that signature-based rules miss: unusual parent-child process chains, lateral movement patterns, authentication anomalies.
End-to-end IR from triage through containment. I've built Python and Logic App automation that cut per-incident triage time from an hour to 15 minutes across 200+ monthly alerts — enriching IOCs automatically and routing signal before a human touches it.
Microsoft Sentinel is my primary platform: data connectors, analytic rules, workbooks, and SOAR playbooks. I also have hands-on experience evaluating and standing up SIEM infrastructure from scratch, including open-source alternatives like Wazuh in cloud-native environments.
Joined as the organization's only dedicated security hire and discovered the existing SIEM (Chronicle/Google SecOps, managed by a third-party MSSP) had been decommissioned, leaving no alerting or detection infrastructure across a multi-cloud environment spanning GCP and AWS.
Security review questionnaires, vendor assessments, customer security reviews, and compliance intake forms represented a significant manual workload with repetitive, high-volume responses that consumed engineering time better spent on detection and response work.
AWS environment with 3TB+ of S3 data had no threat detection or logging infrastructure, no CloudTrail, no GuardDuty, no VPC Flow Logs. Attacker activity across IAM, storage, and network layers would have been entirely invisible.
Security team was processing 200+ monthly incidents with manual triage averaging an hour per alert — analysts context-switching between threat intel sources, Sentinel, and EDR before they could even classify severity.
Signature-based detection was missing attacker behaviors that didn't match known IOCs — particularly living-off-the-land techniques, abnormal authentication patterns, and PowerShell abuse that blended with legitimate admin activity.
Over-permissioned accounts and broad role assignments created security risks across Azure infrastructure.
Cloud infrastructure had numerous security misconfigurations flagged by Defender for Cloud, impacting compliance readiness.
Healthcare infrastructure with 200+ heterogeneous servers (Windows/Linux) lacked unified endpoint detection and response capabilities, creating visibility gaps and increasing incident response time.
Designed and executed enterprise-wide EDR deployment with automation focus:
Signature-based detection was missing suspicious behaviors and techniques that warranted investigation in the healthcare environment.
Healthcare organization needed to evaluate security posture of third-party vendor solutions and internal applications before deployment, while maintaining rapid development cycles for security tooling.
Established security review process and leveraged modern development practices:
Security incidents in healthcare environment require rapid investigation to determine scope, contain threats, and protect patient data while minimizing operational disruption to clinical systems.
Developed systematic EDR investigation methodology:
Detected suspicious PowerShell execution spawned from Word.exe → Identified macro-based malware delivery → Traced network connection to known malicious IP → Isolated affected workstation → Prevented lateral movement to clinical systems → Full remediation within 2 hours
City's IT infrastructure had inconsistent security configurations across 600+ devices, creating vulnerabilities and compliance gaps.
Municipal government lacked endpoint detection and response capabilities, creating blind spots in security monitoring.
City systems required compliance with Criminal Justice Information Services (CJIS) security policy for law enforcement data access.
I'm always interested in discussing security engineering opportunities, collaborating on projects, or sharing insights about cloud security and threat detection. Feel free to reach out!