Cybersecurity · Network Operations · AI Governance

I turn ambiguous security problems into operational controls.

I’m Paul Altamirano, a security-focused network administrator working across threat intelligence, detection engineering, cloud monitoring, data governance, and infrastructure. I build the process around the technology.

Explore my work

Selected professional work

The work behind the job title

A conventional résumé compresses the breadth of the role. These sanitized case studies show how I approach risk, evidence, implementation, and operational handoff without exposing client-sensitive details.

Security operationsCurrent

Threat hunting and detection engineering

Investigate suspicious activity across DNS, endpoint, threat-intelligence, and cloud telemetry, then convert findings into detection logic and repeatable response steps.

  • Hunt through Cisco Umbrella DNS telemetry and correlate indicators.
  • Develop and tune Recorded Future alerts for relevance and impact.
  • Test and maintain Microsoft Sentinel analytic rules.
  • Use Defender telemetry to support triage and incident response.

Value: stronger signal quality and clearer analyst action.

Risk & resilienceCurrent

Security assessment and incident readiness

Assess non-enterprise environments where visibility, tooling, and support models vary, then recommend controls that are realistic for the site rather than theoretically perfect.

  • Review network topology, monitoring coverage, and access-control gaps.
  • Assess endpoint, network, and operational risks for international sites.
  • Partner with security leadership on practical risk-reduction measures.
  • Contribute escalation, detection, and remediation procedures to incident planning.

Value: defensible priorities tied to actual operating conditions.

AI governanceCurrent

Identity-aware data access for AI workloads

Design governance patterns for human users and AI service identities accessing governed data through Snowflake and Immuta, with emphasis on centralized policy and low user friction.

  • Develop tag- and group-driven subscription policy patterns.
  • Evaluate purpose-based access and project membership workflows.
  • Design service-identity provisioning where standard directory sync is insufficient.
  • Test semantic-view and agent access while preserving governance enforcement.

Value: scalable access decisions without duplicating policy across tools.

Network securityDesign review

Guest-network segmentation and captive access

Evaluate a guest wireless design spanning Cisco wireless infrastructure, an external portal, and Palo Alto security policy while protecting internal user and management networks.

  • Validate guest VLAN addressing, policy paths, DNS, NAT, and application controls.
  • Harden guest-to-internal deny rules and logging boundaries.
  • Trace unreliable captive-portal behavior across client, controller, and firewall layers.
  • Document rollback and decommission steps when the user experience failed acceptance.

Value: security preserved even when the preferred workflow was not production-ready.

Cloud & Zero TrustDelivery

Cloud security migration and private application publishing

Support cloud-security platform transition work and apply the same zero-trust principles to private web applications: narrow exposure, identity before access, and explicit validation.

  • Support migration from Microsoft Defender for Cloud Apps to Cloudflare.
  • Separate public static content from private interactive services.
  • Use outbound-only tunnels and loopback-bound origins for private applications.
  • Define Access policy and signed-token validation requirements.

Value: reduced origin exposure with clearer trust boundaries.

OperationsDelivery

Security reporting, remediation tracking, and handoff

Turn technical findings into artifacts that operators and decision-makers can use after the initial investigation is over.

  • Build Power BI views for operational and vulnerability reporting.
  • Track remediation work through Azure DevOps.
  • Write SOPs, test plans, rollback procedures, and current-state documentation.
  • Translate technical risk into decisions for non-specialist stakeholders.

Value: work remains repeatable, reviewable, and transferable.

Experience

Progression toward security ownership

July 2025 — Present

CoHo Consulting · Bureau of International Narcotics and Law Enforcement Affairs

Network Administrator · Threat Intelligence & Security Operations

Own and support work across threat hunting, detection engineering, cloud security monitoring, incident readiness, network-risk assessment, reporting, and emerging AI governance requirements.

April 2025 — July 2025

ZenPoint Solutions · Bureau of International Narcotics and Law Enforcement Affairs

Systems Administrator

Connected infrastructure, cybersecurity, and support operations through cloud-security migration work, Power BI reporting, vulnerability-remediation tracking, topology review, and standardized operating procedures.

Independent systems work

Projects built to learn the full lifecycle

These are personal projects, separate from employer environments. They demonstrate how I design, test, operate, document, and recover systems—not just how I configure them once.

01

Private self-hosted AI platform

Built a private inference environment with separate production and coding workloads, local-only APIs, system services, a private mesh network, and structured health checks.

Linuxllama.cppVulkansystemdTailscale
02

Local-first health data pipeline

Collects Garmin and RENPHO data, preserves raw source payloads, normalizes records into SQLite, produces deterministic trend analysis, and delivers a private Telegram review.

PythonSQLiteAPIsData modelingTelegram
03

News-agent publishing pipeline

Built and later retired a private-first RSS and local-AI workflow that generated sanitized static output for Cloudflare Pages while keeping models, data, and APIs off the public site.

PythonRSSSQLiteCloudflare PagesAutomation

Technical toolkit

Platforms and disciplines

Security operations

Microsoft Sentinel, Defender for Endpoint, Defender for Cloud Apps, Recorded Future, Cisco Umbrella, Qualys, KQL

Cloud and identity

Microsoft Azure, Microsoft 365, Entra ID, AWS, Cloudflare, Zero Trust access patterns

Network and systems

DNS, DHCP, VPNs, TCP/IP, network monitoring, topology analysis, Windows Server, Active Directory, Linux

Governance and data

Immuta, Snowflake, access policy design, Power BI, Azure DevOps, SQLite, technical documentation

Certifications

  • CompTIA Security+2023
  • CompTIA Network+2023
  • AWS Certified Cloud Practitioner2025
  • Microsoft Certified: Azure FundamentalsMicrosoft

Education

Bachelor of Science, Cybersecurity

University of Maryland Global Campus · 2023

Let’s connect

Looking for someone who can bridge security, networks, and operations?

Email Paul