Columbia, Maryland · Senior technical cybersecurity roles

Security operations grounded in evidence and operational context.

I investigate complex security activity, connect evidence across tools and teams, and turn findings into practical response decisions. My independent projects extend that enterprise SecOps foundation into AI security and agentic systems.

Professional profile

Enterprise security experience built on a foundation in 24/7 network operations and team leadership.

That combination brings cross-domain context to security investigations and engineering work, with a practical understanding of how technical decisions affect teams, services, and customers.

Capability map

Where I contribute

Enterprise security experience, complemented by independent projects applying those practices to AI security and automation.

01

Security operations

Enterprise alert triage and multi-source investigations using evidence from SIEM, EDR, network and cloud controls, vulnerability findings, and threat-intelligence sources to support escalation, threat hunting, and incident response.

02

Vulnerability management

InsightVM deployment and administration, recurring and ad hoc scan design, findings prioritization and reporting, remediation coordination, and follow-up validation.

03

Threat intelligence

TIP administration, indicator research and contextual analysis, open-source and vendor threat monitoring, and application of threat intelligence to SOC investigations and threat-hunting support.

04

Security engineering and assurance

Internal product-security assessments and penetration testing, coordination of external penetration-testing engagements, and PCI DSS and SOC 2 audit support through documented procedures and control evidence.

05

AI security and automation

Independent lab and project work applying security controls to agentic workflows, Model Context Protocol integrations, local-model gateways, prompt guardrails, bounded agent authority, and adversarial control validation.

06

Operational resilience and leadership

Leadership in 24/7 network operations spanning customer-impact assessment, incident escalation, service restoration, continuity of operations, mentoring, technical training, and cross-team coordination.

Selected experience

Evidence from enterprise security operations

Hughes Network Systems · Network Security Engineer III · 2015–2026

01

Correlated evidence across security domains

Correlated data from SIEM, EDR, network, and cloud-security tools with vulnerability findings and threat intelligence to determine the scope and potential impact of security activity, assess risk, and support escalation and incident-response decisions.

02

Improved alert actionability

Initiated alert-review meetings and provided tuning feedback that reduced false positives and made security alerts more actionable.

03

Applied threat intelligence to SOC investigations

Administered Recorded Future and Rapid7 IntSights and used both platforms to research and contextualize indicators, monitor threat reporting, and support SOC investigations and threat hunting.

04

Built repeatable vulnerability operations

Deployed and supported InsightVM, designed scans, prioritized findings, tracked remediation, and performed follow-up assessments.

05

Applied AI to investigation workflows

Designed and configured two task-specific Microsoft Copilot agents to assist with Cortex XDR alert analysis and threat-intelligence research during indicator investigations.

Operational foundationNetwork Operations Senior Supervisor and Associate Engineer · 2000–2015

Earlier work in 24/7 network operations encompassed technical troubleshooting, incident escalation, service restoration, team leadership, and technical mentoring. That experience continues to inform my security operations work.

Selected work

Independent projects with practical security evidence

The work applies established security practices across AI systems, agentic workflows, and operational threat intelligence through AI-assisted development and documented hands-on validation.

01
AI security controls

AI Security Gateway

An independently deployed and validated gateway for local AI services that centralizes model access, applies sensitive-data controls, and enforces operational guardrails.

LiteLLM · Microsoft Presidio · Ollama · PostgreSQL
  • Scoped gateway access and rate limiting
  • Presidio-based sensitive-data controls
  • Prompt guardrails and policy enforcement
  • Network restrictions and direct-model bypass testing
02
Bounded agent authority

OpenClaw Secure Agent Lab

An independently deployed and secured OpenClaw environment that constrains filesystem, network, GitHub, and case-evidence access through MCP, validates authority boundaries, and applies the bounded agent to investigation and detection-engineering work.

OpenClaw · MCP · Docker · GitHub · Ollama / OpenAI
  • Scoped MCP tools and credentials
  • Repository-isolation, prompt-injection, and approval-enforcement testing
  • Bounded GitHub-write remediation
  • AI-assisted PowerShell investigation and Office-to-PowerShell detection engineering
03
Operational threat intelligence

SOC Threat Intelligence

A threat-intelligence site organized around a rolling seven-day review window, bringing together multi-source reporting, vulnerabilities, infrastructure, and framework mappings for structured SOC review. Developed and maintained through a ChatGPT-supported workflow, with human review and approval before each update goes live.

CTI analysis · Structured data · Framework mapping · Web publishing
  • Multi-source intelligence collection and structured review
  • Separate criticality, sector relevance, confidence, and recency signals
  • MITRE ATT&CK, ATLAS, and OWASP LLM mappings for threats affecting enterprise and AI-enabled systems
  • Human-reviewed, approval-controlled publishing workflow
Credentials

Certifications, education, and professional development

Credentials and education supporting work across security operations, threat intelligence, penetration testing, and applied AI security.

CompTIA SecAI+Valid through 2029
GIAC Cyber Threat Intelligence (GCTI)Valid through 2027
GIAC Penetration Tester (GPEN)Valid through August 2030
Recorded Future Certified AnalystIssued 2021
Contact

Let’s connect.

I’m interested in senior technical cybersecurity roles across security operations, security engineering, threat intelligence, and applied AI security.