Summary
Security engineer with 9+ years across threat hunting, detection engineering, and incident response, focused on purple teaming and active defense. BLUF: I emulate adversary TTPs in controlled environments to measure detection efficacy, close coverage gaps, and ship ATT&CK-mapped detections — turning attacker behavior into measurable defensive improvements. Incident-commander experience brings an assumed-breach mindset. Seeking Active Defense / Purple Team roles where emulation-driven validation strengthens detection and response.
Projects
Multi-Source Alert Triage Platform
Internal platform: ingest cloud security and exposure findings, normalize events, enrich with threat-intelligence sources and activity attribution, apply YAML disposition logic (FP/BTP/TP), and automate SOC triage with close-loop updates to monitoring and ticketing.
IOC Enrichment Platform
Pluggable TI enrichment (VirusTotal, Shodan, GreyNoise, AbuseIPDB, OTX, ThreatFox, and others) with parallel execution and caching — reused across exposure scans, triage, and investigations.
Detection Engineering Catalog
Vendor-agnostic detection-as-code catalog (YAML + Sigma) mapped to MITRE ATT&CK — CloudTrail, GuardDuty, Linux audit, DNS, and multi-source correlation — with Splunk implementations and additional SIEM/IR targets; campaign-aware rules.
CloudTrail Threat Hunting (Athena)
Athena hunt library and MITRE-mapped hunt catalog; Python orchestrator for multi-account, date-bounded hunts with structured output for SOAR.
Security Platform & SOC Program
Multi-repository security automation that unifies alert triage, IOC enrichment, detection-as-code, and threat hunting for day-to-day SOC work. Program docs cover IR gap analysis, log-source inventory, and ATT&CK-aligned coverage tracking.