Security and risk analyst working across governance, risk and compliance, vulnerability management, and security operations. Current work centers on third-party and software security assessment: scoping vendor reviews, producing severity-rated risk registers with remediation guidance, mapping findings to internal policy and recognized control frameworks, and carrying them through to closure with business owners. Prior security operations experience covers SIEM and endpoint monitoring on Splunk and Microsoft Sentinel, incident response and forensic investigation, and vulnerability remediation aligned to NIST SP 800-171 and DFARS 252.204-7012, and that operational grounding is what makes the risk work practical rather than theoretical. I also build the tooling: detection-as-code pipelines, purple-team validation against MITRE ATT&CK, secure CI/CD with supply-chain signing, and an AI-governance audit tool built for EU AI Act, SOC 2, and ISO 42001 evidence. Assessment work routinely covers cryptographic and encryption software, certificate and key dependencies, and the handling of personally identifiable information. Active in coordinated vulnerability disclosure.
Professional Experience
- Own software and vendor security assessments end to end, including cryptography and encryption software, from intake and scoping through a severity-rated risk register with documented remediation guidance, reviewed with IT leadership before purchasing or deployment decisions are made.
- Assess cryptographic posture in vendor and application reviews: identify the libraries, protocols and certificate dependencies a product relies on, flag weak or deprecated algorithms and expiring trust, and record them as tracked findings with remediation owners. The same enumeration work that feeds a post-quantum migration inventory.
- Review how vendors and applications handle personally identifiable information, covering data flows, storage locations, retention and third-party onward transfer, and hold the finding open until the business owner evidences a control.
- Conduct third-party due diligence on prospective vendors, including security questionnaires, external posture review, and written risk memos that give decision makers a clear recommendation rather than a list of raw findings.
- Administer the enterprise security awareness training program, running user audits, tracking campaign compliance, and following up directly with business owners to close gaps.
- Map assessment findings to internal policy and recognized control frameworks, and document control gaps with the evidence needed to support them under audit.
- Manage assessment intake, tracking, and closure through the IT service management system, maintaining an audit-ready record for each engagement.
- Conduct coordinated vulnerability disclosure on Bugcrowd and HackerOne across managed bug-bounty programs.
- Submitted research to programs spanning managed databases (PostgreSQL, MySQL, ClickHouse, Valkey, Kafka), MPC and blockchain platforms, and major web services.
- Work from source-code analysis, protocol-level review, and reproducible proof-of-concept development across cryptographic libraries, database engine internals, blockchain consensus, and OAuth / MCP authorization-bypass chains.
- Built an autonomous, multi-agent vulnerability-research platform that reproduced proof-backed findings across more than 20 open-source projects under a strict reproduce-before-report standard, spanning access-control, SSRF, path traversal, injection, and memory-safety classes.
- Run an AI, IT, and web consulting practice for small businesses from Scottsdale, AZ: client websites, AI agent and automation builds, and IT systems support. Retainer details under NDA.
- Monitor and triage 150 to 300 alerts per shift across Splunk, Microsoft Sentinel, SentinelOne, and Stellar Cyber at an MSSP, supporting compliance against documented client security policies and federal control baselines.
- Investigated ransomware intrusions, producing timeline analysis, IOC documentation, and evidence packaging that supported a successful cyber-insurance claim resolution.
- Perform vulnerability analysis on Windows and Linux endpoints, validate findings, map them to MITRE ATT&CK and NIST controls, and author remediation guidance for client tenants.
- Track and validate more than 100 vulnerability remediation actions, sustaining a 90 percent or better on-time patching rate with audit-ready evidence of control effectiveness.
- Reduced false-positive escalations by roughly 35 percent through detection-rule tuning and parameterized KQL notebook workflows in Microsoft Sentinel.
- Author incident reports, remediation playbooks, and policy-to-control mappings aligned with NIST SP 800-171, and maintain full SOP compliance across incident documentation.
- Supported senior analysts with alert validation, log review, and incident documentation in a managed security services environment serving multiple client organizations.
- Monitored endpoint security, antivirus, and email threat feeds while learning escalation, evidence collection, and response procedures. Promoted to SOC Analyst I.
- Performed daily digital security and compliance checks, verified transactions, and authenticated customer identities with multi-factor procedures at full policy compliance.
- Multiple government and private contracts, including Department of Defense work. Details under NDA.
Security Projects & Research
Full write-ups with screenshots and code are in the index.
Personal Infrastructure Lab
- Operate a self-hosted Proxmox VE cluster with GPU passthrough, running more than 14 LXC containers and VMs across Debian, Ubuntu, and RHEL-family guests, hosting a VPN gateway, a DNS sinkhole, a backup server, a full Wazuh SIEM stack, and automated security workloads.
- Hands-on with hypervisor administration, LXC and KVM orchestration, GPU passthrough, VLAN segmentation, firewall policy, automated backups, headless Linux deployment, and systemd service management.
Core Technical Skills
Certifications
- CompTIA Security+ (SY0-701), DoD 8140 / 8570 IAT Level II baseline
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Fundamentals (AZ-900)
- SentinelOne Incident Responder Certification
Education
High School Diploma, 2021. Self-directed study in security engineering, applied cryptography, and detection engineering.
Get in touch: [email protected]