Detection Engineering
PublishedSOC Automation with Splunk
Brute-force credential attack detection using Windows Security Event Logs, SPL-based alert logic, structured triage decisions, and repeatable analyst response documentation.
Build · Detect · Respond
Hands-on security operations work across detection engineering, incident response, and identity security — built with real tooling, documented with analyst rigor, and structured for repeatable outcomes.
Featured Labs
Each lab is built around an authentic security scenario and documented through detection logic, triage decisions, analyst response steps, and measurable results.
Detection Engineering
PublishedBrute-force credential attack detection using Windows Security Event Logs, SPL-based alert logic, structured triage decisions, and repeatable analyst response documentation.
Incident Response
StagedEnd-to-end phishing intrusion scenario covering initial delivery, host-based indicator analysis, containment decisions, and executive-ready incident documentation.
Identity Security
StagedOperational access-control scenarios covering MFA enforcement, least-privilege principles, account lifecycle governance, privileged access management, and recovery workflows.
Personal Projects
Production-level projects demonstrating multi-agent AI orchestration, platform API integration, autonomous workflow design, and operational security practices.
AI Automation
PublishedAutonomous AI commerce pipeline using CrewAI, Anthropic, Canva Connect, Etsy REST workflows, SQLite state tracking, SEO review, daily health reporting, and VPS loop automation.
Operating Method
Analyst Standard
This portfolio emphasizes the components that define effective security operations work: evidence quality, repeatable decision-making, clear analyst communication, and structured containment methodology.
Model a realistic threat or access-control situation with actionable telemetry.
Develop and validate alert logic that isolates meaningful signal from background noise.
Translate raw events into documented findings with defined scope, severity, and decision criteria.
Record analyst actions and outcomes as reusable case documentation for future incidents.
About
Five-plus years of enterprise IT experience in high-demand environments — including Columbia University and NYC Health + Hospitals — supporting mission-critical infrastructure and security operations workflows.
Core focus areas include threat detection engineering, security event log analysis, identity and access management (IAM), and structured SOC investigation methodology.
Technical work is executed with analytical rigor, thorough documentation, and evidence-based decision-making aligned with established security operations standards and best practices.
Credentials
CompTIA
Validates knowledge across threat analysis, security architecture, network security, operations, governance, and risk management.
IT Service Management
Demonstrates fluency in IT service management frameworks, service value chains, and continual improvement practices.