Security operationsCurrent
Threat hunting and detection engineering
Investigate suspicious activity across DNS, endpoint, threat-intelligence, and cloud
telemetry, then convert findings into detection logic and repeatable response steps.
- Hunt through Cisco Umbrella DNS telemetry and correlate indicators.
- Develop and tune Recorded Future alerts for relevance and impact.
- Test and maintain Microsoft Sentinel analytic rules.
- Use Defender telemetry to support triage and incident response.
Value: stronger signal quality and clearer analyst action.
Risk & resilienceCurrent
Security assessment and incident readiness
Assess non-enterprise environments where visibility, tooling, and support models vary,
then recommend controls that are realistic for the site rather than theoretically perfect.
- Review network topology, monitoring coverage, and access-control gaps.
- Assess endpoint, network, and operational risks for international sites.
- Partner with security leadership on practical risk-reduction measures.
- Contribute escalation, detection, and remediation procedures to incident planning.
Value: defensible priorities tied to actual operating conditions.
AI governanceCurrent
AI governance and identity-aware data access
Designed and implemented centralized governance and data-access policies for human users and AI workloads accessing governed Snowflake data through Immuta.
- Implemented tag- and group-driven Immuta policies to consistently control access to governed Snowflake data.
- Developed an access model connecting organizational identity groups, Immuta entitlements, and Snowflake roles for Cortex AI use cases.
- Created and evaluated purpose-based access and project-membership workflows to strengthen governance without adding unnecessary user friction.
- Designed a provisioning approach for AI service identities when standard Entra ID and SCIM synchronization could not support service principals.
- Tested semantic views and Cortex AI agent access while preserving Immuta as the centralized policy-enforcement layer.
Value: Established a centralized governance model that applies consistent access decisions to human users and AI workloads while reducing duplicated policies and manual access administration.
OperationsDelivery
Security reporting, remediation tracking, and handoff
Built Power BI dashboards to give operators and leadership visibility into asset trends, vulnerability remediation, and network security activity across sites.
- Built asset dashboards to track new and existing devices and changes in the asset inventory over time.
- Tracked asset risk scores and compared aggregate device scores across locations before and after vulnerability patching to assess remediation impact.
- Created a centralized Power BI dashboard for leadership to review network security blocks across all sites.
- Tracked remediation work through Azure DevOps and documented SOPs, test plans, rollback procedures, and current-state configurations.
- Translated technical findings into reporting that supported remediation priorities and leadership decisions.
Value: Centralized visibility into asset inventory, security-score trends, patching impact, and blocked network activity across locations.
Cloud & Zero TrustDelivery
Cloud security migration and private application publishing
Support cloud-security platform transition work and apply the same zero-trust principles
to private web applications: narrow exposure, identity before access, and explicit validation.
- Support migration from Microsoft Defender for Cloud Apps to Cloudflare.
- Separate public static content from private interactive services.
- Use outbound-only tunnels and loopback-bound origins for private applications.
- Define Access policy and signed-token validation requirements.
Value: reduced origin exposure with clearer trust boundaries.
INFRASTRUCTURESECURITY
Network Administration and Windows Security
- Created Group Policies for Windows workstations and servers to implement security settings aligned with DISA STIG requirements.
- Resolved DNS and domain-discovery issues preventing a hardened Windows laptop from joining Active Directory.
- Troubleshot internal DNS resolution and management access for two Cisco Umbrella virtual appliances.
- Reviewed Cisco switching and VLAN configurations and adjusted Palo Alto firewall policies to troubleshoot connectivity across management, user, and guest networks.
- Configured and tested Cisco guest wireless and an IIS-hosted portal, investigated authentication and redirect failures, and documented rollback procedures.
Value: Strengthened Windows security configuration, restored domain connectivity, and documented network troubleshooting and recovery procedures.