16 min
average time to investigation
Fast, evidence-led alert ownership
Security Operations · Incident Response · Detection Engineering
I investigate threats, improve detection quality, and build practical workflows that help analysts move from alert to defensible action.
01Impact
16 min
Fast, evidence-led alert ownership
300+
Across identity, email, endpoint, and cloud
500+
KVP and regex logic reducing recurring noise
02Experience
Promoted from Security Analyst to Principal Security Analyst through three roles of increasing scope in investigations, customer response, detection tuning, remediation, and analyst mentorship.
Jul 2026 - Present
Jul 2025 - Jul 2026
Oct 2024 - Jul 2025
03Projects
The SOC analyst's toolbox
A containerized investigation workspace for URL detonation, multi-source IP enrichment, and Defender XDR/Sentinel KQL generation.
Detection-as-code for Sigma rules
A pipeline that validates, converts, tests, and maps Sigma detections before they reach production SIEMs.
Live homelab detection engineering
A Proxmox-hosted ELK detection platform that routes OPNsense and Proxmox telemetry through Logstash into Elasticsearch, Kibana, and analyst-ready alerts.
04Credentials
In progress
ISACA CISM — In Progress
Education
M.S. Cybersecurity & Information Assurance
Western Governors University
B.S. Information Systems
The University of Texas at Arlington
Engineering capabilities developed through active hands-on projects and continued technical development.