Build · Detect · Respond

Security operations. Built on evidence.

Hands-on security operations work across detection engineering, incident response, and identity security — built with real tooling, documented with analyst rigor, and structured for repeatable outcomes.

3 Security lab tracks
80+ Failed logons detected
5+ Years enterprise IT
2 Professional credentials

Threat scenarios. Documented outcomes.

Each lab is built around an authentic security scenario and documented through detection logic, triage decisions, analyst response steps, and measurable results.

Detection Engineering

Published

SOC Automation with Splunk

Brute-force credential attack detection using Windows Security Event Logs, SPL-based alert logic, structured triage decisions, and repeatable analyst response documentation.

Splunk SPL Windows Logs

Incident Response

Staged

Phishing-to-Malware Incident Response Lab

End-to-end phishing intrusion scenario covering initial delivery, host-based indicator analysis, containment decisions, and executive-ready incident documentation.

IR Sysinternals Containment

Identity Security

Staged

Identity & Access Management Security Lab

Operational access-control scenarios covering MFA enforcement, least-privilege principles, account lifecycle governance, privileged access management, and recovery workflows.

IAM MFA Active Directory

Applied AI engineering beyond the security lab.

Production-level projects demonstrating multi-agent AI orchestration, platform API integration, autonomous workflow design, and operational security practices.

View Projects

AI Automation

Published

AI Etsy Product Pipeline

Autonomous AI commerce pipeline using CrewAI, Anthropic, Canva Connect, Etsy REST workflows, SQLite state tracking, SEO review, daily health reporting, and VPS loop automation.

Python CrewAI Anthropic API Canva Etsy API

The analyst framework behind every case.

Analyst Standard

From signal to response

This portfolio emphasizes the components that define effective security operations work: evidence quality, repeatable decision-making, clear analyst communication, and structured containment methodology.

Scenario

Model a realistic threat or access-control situation with actionable telemetry.

Detection

Develop and validate alert logic that isolates meaningful signal from background noise.

Triage

Translate raw events into documented findings with defined scope, severity, and decision criteria.

Response

Record analyst actions and outcomes as reusable case documentation for future incidents.

Security operations practitioner.

Five-plus years of enterprise IT experience in high-demand environments — including Columbia University and NYC Health + Hospitals — supporting mission-critical infrastructure and security operations workflows.

Technical Focus

Core focus areas include threat detection engineering, security event log analysis, identity and access management (IAM), and structured SOC investigation methodology.

Professional Approach

Technical work is executed with analytical rigor, thorough documentation, and evidence-based decision-making aligned with established security operations standards and best practices.

Certifications & professional credentials.

Let's connect.

Actively pursuing SOC Analyst roles, detection engineering positions, and security internship opportunities.