Paul Altamirano

Cybersecurity · Network Operations · AI Governance

I’m a security-focused network administrator working across threat intelligence, detection engineering, cloud monitoring, data governance, and infrastructure. I build the process around the technology.

Professional Work

Security operationsCurrent

Threat hunting and detection engineering

Investigate suspicious activity across DNS, endpoint, threat-intelligence, and cloud telemetry, then convert findings into detection logic and repeatable response steps.

  • Hunt through Cisco Umbrella DNS telemetry and correlate indicators.
  • Develop and tune Recorded Future alerts for relevance and impact.
  • Test and maintain Microsoft Sentinel analytic rules.
  • Use Defender telemetry to support triage and incident response.

Value: stronger signal quality and clearer analyst action.

Risk & resilienceCurrent

Security assessment and incident readiness

Assess non-enterprise environments where visibility, tooling, and support models vary, then recommend controls that are realistic for the site rather than theoretically perfect.

  • Review network topology, monitoring coverage, and access-control gaps.
  • Assess endpoint, network, and operational risks for international sites.
  • Partner with security leadership on practical risk-reduction measures.
  • Contribute escalation, detection, and remediation procedures to incident planning.

Value: defensible priorities tied to actual operating conditions.

AI governanceCurrent

AI Governance and Identity-Aware Data Access

Designed and implemented centralized governance and data-access policies for human users and AI workloads accessing governed Snowflake data through Immuta.

  • Implemented tag- and group-driven Immuta policies to consistently control access to governed Snowflake data.
  • Developed an access model connecting organizational identity groups, Immuta entitlements, and Snowflake roles for Cortex AI use cases.
  • Created and evaluated purpose-based access and project-membership workflows to strengthen governance without adding unnecessary user friction.
  • Designed a provisioning approach for AI service identities when standard Entra ID and SCIM synchronization could not support service principals.
  • Tested semantic views and Cortex AI agent access while preserving Immuta as the centralized policy-enforcement layer.

Value: Established a centralized governance model that applies consistent access decisions to human users and AI workloads while reducing duplicated policies and manual access administration.

Cloud & Zero TrustDelivery

Cloud security migration and private application publishing

Support cloud-security platform transition work and apply the same zero-trust principles to private web applications: narrow exposure, identity before access, and explicit validation.

  • Support migration from Microsoft Defender for Cloud Apps to Cloudflare.
  • Separate public static content from private interactive services.
  • Use outbound-only tunnels and loopback-bound origins for private applications.
  • Define Access policy and signed-token validation requirements.

Value: reduced origin exposure with clearer trust boundaries.

OperationsDelivery

Security reporting, remediation tracking, and handoff

Built Power BI dashboards to give operators and leadership visibility into asset trends, vulnerability remediation, and network security activity across sites.

  • Built asset dashboards to track new and existing devices and changes in the asset inventory over time.
  • Tracked asset risk scores and compared aggregate device scores across locations before and after vulnerability patching to assess remediation impact.
  • Created a centralized Power BI dashboard for leadership to review network security blocks across all sites.
  • Tracked remediation work through Azure DevOps and documented SOPs, test plans, rollback procedures, and current-state configurations.
  • Translated technical findings into reporting that supported remediation priorities and leadership decisions.

Value: Centralized visibility into asset inventory, security-score trends, patching impact, and blocked network activity across locations.

INFRASTRUCTURESECURITY

Network Administration and Windows Security

  • Created Group Policies for Windows workstations and servers to implement security settings aligned with DISA STIG requirements.
  • Resolved DNS and domain-discovery issues preventing a hardened Windows laptop from joining Active Directory.
  • Troubleshot internal DNS resolution and management access for two Cisco Umbrella virtual appliances.
  • Reviewed Cisco switching and VLAN configurations and adjusted Palo Alto firewall policies to troubleshoot connectivity across management, user, and guest networks.
  • Configured and tested Cisco guest wireless and an IIS-hosted portal, investigated authentication and redirect failures, and documented rollback procedures.

Value: Strengthened Windows security configuration, restored domain connectivity, and documented network troubleshooting and recovery procedures.

Experience

Progression toward security ownership

July 2025 — Present

CoHo Consulting · Bureau of International Narcotics and Law Enforcement Affairs

Network Administrator · Threat Intelligence & Security Operations

THREAT INTELLIGENCE

Recorded Future

  • 25–30 alerts / week
  • IOC validation
  • Threat prioritization

THREAT HUNTING

Cisco Umbrella

  • DNS telemetry
  • Anomaly investigation
  • Exposure validation

DETECTION ENGINEERING

Microsoft Sentinel

  • Analytics rules
  • Detection tuning
  • False-positive reduction

SECURITY ASSESSMENT

International environments

  • Architecture review
  • Visibility gaps
  • Incident readiness
April 2025 — July 2025

ZenPoint Solutions · Bureau of International Narcotics and Law Enforcement Affairs

Systems Administrator

VULNERABILITY MANAGEMENT

Remediation planning

  • RACI development
  • Azure DevOps
  • Progress tracking

CLOUD SECURITY

MDCA → Cloudflare

  • Migration support
  • Security visibility
  • Platform transition

SECURITY REPORTING

Power BI

  • Operational metrics
  • Vulnerability trends
  • Leadership reporting

NETWORK OPERATIONS

Topology analysis

  • Risk identification
  • Documentation
  • Knowledge transfer
October 2024 – April 2025

IntelliDyne LLC

Tier 2 Desktop Support Technician

Falls Church, Virginia

Show earlier experience at IntelliDyne LLC
  • Performed operating-system and software updates, remediated vulnerabilities, and helped maintain endpoint compliance with organizational security requirements.
  • Identified and remediated endpoint security violations, restoring affected systems to approved configurations.
  • Diagnosed Tier 1 network and workstation connectivity issues, including network-port assignments, cabling faults, and endpoint configuration problems.
  • Administered Active Directory user accounts, including account creation, modification, access troubleshooting, and deactivation.
  • Escalated complex infrastructure and network problems while documenting completed troubleshooting and remediation work.
July 2023 – October 2024

TekSynap

Tier 2 Deskside Technician

White Oak, Maryland

Show earlier experience at TekSynap
  • Delivered remote and deskside technical support for Cisco AnyConnect, Microsoft 365 applications, Windows systems, and Dell hardware.
  • Installed and supported specialized software used by multiple FDA centers.
  • Used Active Directory to resolve account lockouts, troubleshoot user access, and verify Group Policy application.
  • Managed incidents and service requests in ServiceNow while maintaining detailed troubleshooting and resolution records.
  • Supported mobile devices through IBM MaaS360, including device enrollment, application installation, remote wipes, and cellular-connectivity troubleshooting.
December 2022 – July 2023

Open Technology Group

Software Installer

Rockville, Maryland

Show earlier experience at Open Technology Group
  • Installed FDA-specific software and verified that managed endpoints met McAfee encryption requirements.
  • Supported Windows imaging operations and collaborated with multiple teams to identify and document image-related failures.
  • Analyzed technical data and network-connectivity problems that interrupted workstation imaging and deployment.
  • Installed and configured office peripherals, including printers, scanners, keyboards, monitors, and related workstation equipment.

Independent systems work

Projects built to learn the full lifecycle

These are personal projects, separate from employer environments. They demonstrate how I design, test, operate, document, and recover systems—not just how I configure them once.

01 · AI INFRASTRUCTURESELF-HOSTED

Private self-hosted AI platform

Built and operated a private AI platform with separate production and coding inference services, local application integrations, and explicitly separated private-compute and public-presentation trust boundaries.

  • Deployed separate llama.cpp and Vulkan inference services for production and coding workloads, managed with systemd and bound to loopback-only service and health endpoints.
  • Integrated local inference with Telegram and automated news-processing workflows while keeping workloads separated to reduce interference and simplify troubleshooting.
  • Used Tailscale for private administration and published only sanitized static artifacts through Cloudflare Pages, leaving models, databases, and local APIs inaccessible to public browsers.
  • Developed current-state inventories, health checks, service-success criteria, logging procedures, checkpoints, rollback documentation, and a prioritized security and recovery risk register.
02 · HEALTH DATALOCAL-FIRST

Local-first health data pipeline

Built an automated pipeline that collects Garmin and RENPHO data, preserves raw source records, normalizes measurements into SQLite, and produces private deterministic health reporting.

  • Created independent Garmin and RENPHO collectors that preserve raw JSON, normalize supported fields, prevent duplicate records, and continue operating when the other source fails.
  • Designed unified SQLite views that combine Garmin daily metrics with the latest same-day RENPHO measurement while preserving missing values instead of incorrectly treating them as zero.
  • Implemented seven-day rolling trends and CSV exports covering weight, sleep, heart rate, HRV, stress, activity, and data-availability indicators.
  • Automated collection with systemd oneshot services and timers and delivered a read-only seven-day review through an authorized private Telegram command without using an LLM for calculations.
03 · AUTOMATIONRETIRED

News-agent publishing pipeline

Built and later retired a private-first pipeline that ingested news feeds, processed articles with local AI agents, and published sanitized static output without exposing the home inference environment.

  • Ingested RSS feeds and linked article pages into SQLite, recording articles, agent messages, run history, and a seen-item ledger that prevented immediate reprocessing.
  • Orchestrated five local AI personas to generate structured reactions and directed replies while keeping model execution, source data, and the database on the private host.
  • Automated ingestion, processing, publishing, and deployment with systemd, then generated sanitized static HTML and JSON for publication through Cloudflare Pages.
  • Completed a controlled retirement by archiving the application and database, disabling and masking service units, removing automatic refresh and the local deployment credential, and preserving the final static snapshot.
04 · FULL-STACKSELF-HOSTED

Crumb — Multi-User Recipe Vault

Built and deployed a mobile-first application for capturing, organizing, and journaling sourdough recipes from websites, social content, pasted text, and manual entries.

  • Built the application with Next.js, TypeScript, Tailwind CSS, Prisma, SQLite, Docker, and server-side OpenAI integration.
  • Implemented invitations, account activation, and separate user Libraries with ownership isolation for recipes, bake records, uploaded media, and AI context.
  • Developed structured recipe import using JSON-LD, Open Graph metadata, direct HTML extraction, pasted social content, AI-assisted parsing, and manual fallback.
  • Secured the application with Cloudflare Access and JWKS validation, hardened the container runtime, added versioned database migrations, and tested isolation and restart persistence.

Technical toolkit

Platforms and disciplines

Security operations

Microsoft Sentinel, Defender for Endpoint, Defender for Cloud Apps, Recorded Future, Cisco Umbrella, Qualys, KQL

Cloud and identity

Microsoft Azure, Microsoft 365, Entra ID, AWS, Cloudflare, Zero Trust access patterns

Network and systems

DNS, DHCP, VPNs, TCP/IP, network monitoring, topology analysis, Windows Server, Active Directory, Linux

Governance and data

Immuta, Snowflake, access policy design, Power BI, Azure DevOps, SQLite, technical documentation

Certifications

  • CompTIA Security+2023
  • CompTIA Network+2023
  • AWS Certified Cloud Practitioner2025
  • Microsoft Certified: Azure FundamentalsMicrosoft

Education

Bachelor of Science, Cybersecurity

University of Maryland Global Campus · 2023

Contact Paul

Connect by email or LinkedIn.

Email

paul.j.altamirano@gmail.com

LinkedIn

LinkedIn (opens in a new tab)