Sentinel
2024Lightweight SIEM pipeline that ingests, parses, and correlates logs from AWS CloudTrail, VPC Flow Logs, and syslog. Detects anomalies via rule-based and ML heuristics, with Slack/PagerDuty alerting.
Cybersecurity Engineer
Offense-minded. Defense-built.
Five years in offensive security and detection engineering. Pen tests, honeypots, SIEM pipelines. Currently at ArcSec — the CVEs are a side effect.
Selected work
Lightweight SIEM pipeline that ingests, parses, and correlates logs from AWS CloudTrail, VPC Flow Logs, and syslog. Detects anomalies via rule-based and ML heuristics, with Slack/PagerDuty alerting.
SSH honeypot with full session capture, geolocation tagging, and credential-spray detection. Deployed across 12 decoy nodes; surfaces active threat actor TTPs in real time.
Zero-trust secrets manager for developer machines. AES-256-GCM encryption, biometric unlock via OS keychain, and audit log export for compliance. Used by 300+ engineers internally.
Automated attack-surface enumeration tool. Chains subdomain discovery, port scanning, TLS fingerprinting, and CVE matching into a single declarative YAML pipeline.
Experience
2022 — Present
ArcSec
Lead security engineer for a cloud-native SaaS platform. Own the threat model, red team operations, and incident response playbooks. Reduced MTTD from 4 hours to 18 minutes by rebuilding the detection pipeline.
2020 — 2022
IronWall Security
Conducted network, web application, and cloud infrastructure pen tests for fintech and healthcare clients. Authored detailed findings reports and remediation roadmaps. OSCP-level engagements.
2019 — 2020
Stratos
SOC analyst on a team monitoring 50M+ daily events. Built custom Sigma detection rules, triaged escalations, and automated tier-1 playbooks — cutting analyst toil by 40%.
Skills
Get in touch
Open to security consulting, freelance engagements, and interesting full-time roles. Drop me a message or reach out directly.