Summary
Security engineer with 9+ years across threat hunting, detection engineering, and incident response, focused on purple teaming and active defense. BLUF: I emulate adversary TTPs in controlled environments to measure detection efficacy, close coverage gaps, and ship ATT&CK-mapped detections — turning attacker behavior into measurable defensive improvements. Incident-commander experience brings an assumed-breach mindset. Seeking Active Defense / Purple Team roles where emulation-driven validation strengthens detection and response.
Skills
- Adversary emulation & purple team
- MITRE ATT&CK (emulation plans, Navigator)
- Detection engineering (Sigma, detection-as-code)
- Detection validation & gap analysis
- Threat hunting
- Incident response / incident command
- SIEM (Splunk, Microsoft Sentinel / KQL)
- EDR (SentinelOne, Trend Vision One, Defender)
- Threat intelligence & IOC enrichment
- Malware triage
- PCAP / network analysis
- Cyber deception (honeypots, canaries)
- AWS security (GuardDuty, CloudTrail, Athena)
- Scripting — Python, Bash, PowerShell (familiar)
Experience
Staff Pro-Active Threat Hunter & Detection Engineer
Undisclosed · Remote · Oct 2022–Present
- Run purple team and adversary-emulation exercises across cloud and on-premises environments — researching attacker TTPs, emulating them in controlled windows, and measuring whether they are prevented, logged, or alerted to validate and improve detection coverage.
- Plan and execute structured, hypothesis-driven threat hunts using MITRE ATT&CK across SIEM, EDR, and cloud telemetry to surface activity consistent with sophisticated attacker methodologies and close visibility gaps.
- Author ATT&CK-mapped detection-as-code (Sigma/Splunk) and validate it against emulated techniques; ship campaign-aware rules for supply-chain and credential-abuse activity.
- Lead incident response as incident commander in cloud and hybrid environments; drive intrusion and root-cause analysis and convert findings into new detections.
- Built a multi-source alert-triage and IOC-enrichment pipeline (21+ TI sources) that informs emulation prioritization and feeds attacker-behavior context into detections and hunts.
- Built and operate an internal attack-surface / network-reconnaissance monitoring program to identify external exposure and prioritize remediation.
- Promoted to Staff (Jan 2025) for closing security gaps with engineering solutions; mentor junior analysts and brief technical and non-technical stakeholders with fact-based, BLUF findings.
Cyber Security Consultant
PacketWatch · Remote · Nov 2020–Oct 2022
- Developed structured threat hunts from active threat intelligence aligned to the cyber kill chain — targeting external exposure, lateral movement, and data exfiltration.
- Delivered managed detection and response: continuous monitoring, daily threat hunting, and verification of anomalous activity across client networks.
- Built detections from TTPs and client-relevant threat intelligence; reviewed findings with stakeholders and implemented preventive controls.
- Conducted network security assessments exposing policy violations, rogue devices, misconfigurations, and data leakage paths.
- Led incident response using EDR and network evidence; performed threat analysis, intrusion analysis, and remediation planning with client IT and security teams.
- Matured client security programs — patch management, asset management, defense-in-depth, and change management across vertical-specific threat landscapes.
Security Operations Engineer
PayPal · San Jose, CA · Jul 2019–Nov 2020
- Participated in incident response for cybersecurity events; investigated malware, intrusion, brute force, and denial-of-service activity to determine scope.
- Partnered with the bug bounty program to recreate exploits, extract IOCs, and implement mitigations (rate limiting, WAF policies, correlation rules).
- Reviewed patterns of abuse against PayPal API endpoints and developed mitigation strategies with business units to close security gaps.
- Provided security feedback on application fixes to ensure releases met or exceeded cybersecurity best practices.
Sr. Cyber Security Analyst
Mosaic451 (MSSP) · Remote · Sep 2017–Jul 2019
- Investigated security events across Splunk, QRadar/QRoC, FortiSIEM, McAfee ESM, and ELK; integrated new log sources and tuned SIEM correlation rules.
- Curated threat intelligence IOC lists (IP, hash, domain) for alerting on malicious activity; developed IDS/IPS and SIEM detection content from threat data.
- Performed malware triage with EnCase, Autopsy, and LogMD; correlated Nessus/Nexpose vulnerability data during incident investigations.
- Conducted network traffic and PCAP analysis with Wireshark; authored regex parsing logic for QRadar and Splunk log ingestion.
Information Security Operations Analyst
University of Phoenix (Apollo Education Group) · Phoenix, AZ · Oct 2016–Sep 2017
- Developed Splunk queries and reports for threat detection (escalated privileges, honey profiles); performed threat modeling and use-case development.
- Tuned McAfee SIEM products (ESM, ePO, DLP, MWG); monitored web and network traffic for suspicious behavior.
- Implemented Check Point firewall rules and MWG web proxy updates per change requests; managed security event monitoring and response.
Projects
Built an internal multi-source alert-triage and IOC-enrichment platform: ingest cloud security and exposure findings, normalize events, enrich with 21+ TI sources and activity attribution, apply YAML disposition logic (FP/BTP/TP), and automate SOC triage workflows with close-loop updates to monitoring and ticketing systems.
22 auto-discovered, pluggable TI enrichers (VirusTotal, Shodan, GreyNoise, AbuseIPDB, OTX, ThreatFox, and others) with parallel execution and TTL caching — reusable across exposure scans, triage, and standalone investigations.
~57 detection-as-code rules (YAML + Sigma) mapped to MITRE ATT&CK — AWS CloudTrail, GuardDuty, Linux audit, DNS IOC, and multi-source correlation — with SIEM artifact generation and campaign-aware rules for supply-chain and credential-abuse scenarios.
70+ partition-aware Athena hunt queries and a YAML Hunt Catalog with MITRE technique IDs; Python orchestrator for multi-account, date-bounded hunts with structured JSON output for SOAR integration.
Designed and operate a multi-repository security automation platform that unifies alert triage, IOC enrichment, detection-as-code, and threat hunting into a single workflow used in day-to-day SOC operations. Authored the SOC & Security Program master plan — IR gap analysis, log-source inventory, and ATT&CK-aligned coverage tracking — to align tooling and detections with measurable program goals.
Education
- B.S. Information Technology — Concentration in Information Systems Security (GPA 3.23) University of Phoenix · 2011