Selected professional work
The work behind the job title
A conventional résumé compresses the breadth of the role. These sanitized case studies
show how I approach risk, evidence, implementation, and operational handoff without
exposing client-sensitive details.
Security operationsCurrent
Threat hunting and detection engineering
Investigate suspicious activity across DNS, endpoint, threat-intelligence, and cloud
telemetry, then convert findings into detection logic and repeatable response steps.
- Hunt through Cisco Umbrella DNS telemetry and correlate indicators.
- Develop and tune Recorded Future alerts for relevance and impact.
- Test and maintain Microsoft Sentinel analytic rules.
- Use Defender telemetry to support triage and incident response.
Value: stronger signal quality and clearer analyst action.
Risk & resilienceCurrent
Security assessment and incident readiness
Assess non-enterprise environments where visibility, tooling, and support models vary,
then recommend controls that are realistic for the site rather than theoretically perfect.
- Review network topology, monitoring coverage, and access-control gaps.
- Assess endpoint, network, and operational risks for international sites.
- Partner with security leadership on practical risk-reduction measures.
- Contribute escalation, detection, and remediation procedures to incident planning.
Value: defensible priorities tied to actual operating conditions.
AI governanceCurrent
Identity-aware data access for AI workloads
Design governance patterns for human users and AI service identities accessing governed
data through Snowflake and Immuta, with emphasis on centralized policy and low user friction.
- Develop tag- and group-driven subscription policy patterns.
- Evaluate purpose-based access and project membership workflows.
- Design service-identity provisioning where standard directory sync is insufficient.
- Test semantic-view and agent access while preserving governance enforcement.
Value: scalable access decisions without duplicating policy across tools.
Network securityDesign review
Guest-network segmentation and captive access
Evaluate a guest wireless design spanning Cisco wireless infrastructure, an external
portal, and Palo Alto security policy while protecting internal user and management networks.
- Validate guest VLAN addressing, policy paths, DNS, NAT, and application controls.
- Harden guest-to-internal deny rules and logging boundaries.
- Trace unreliable captive-portal behavior across client, controller, and firewall layers.
- Document rollback and decommission steps when the user experience failed acceptance.
Value: security preserved even when the preferred workflow was not production-ready.
Cloud & Zero TrustDelivery
Cloud security migration and private application publishing
Support cloud-security platform transition work and apply the same zero-trust principles
to private web applications: narrow exposure, identity before access, and explicit validation.
- Support migration from Microsoft Defender for Cloud Apps to Cloudflare.
- Separate public static content from private interactive services.
- Use outbound-only tunnels and loopback-bound origins for private applications.
- Define Access policy and signed-token validation requirements.
Value: reduced origin exposure with clearer trust boundaries.
OperationsDelivery
Security reporting, remediation tracking, and handoff
Turn technical findings into artifacts that operators and decision-makers can use after
the initial investigation is over.
- Build Power BI views for operational and vulnerability reporting.
- Track remediation work through Azure DevOps.
- Write SOPs, test plans, rollback procedures, and current-state documentation.
- Translate technical risk into decisions for non-specialist stakeholders.
Value: work remains repeatable, reviewable, and transferable.