Security operations
Connecting endpoint, network, cloud, and identity telemetry to make sense of suspicious activity.
My experience spans security operations, incident response, threat hunting, detection engineering, threat intelligence, and vulnerability management.
TopSec is where I post security notes and write-ups.
Connecting endpoint, network, cloud, and identity telemetry to make sense of suspicious activity.
Investigating scope and root cause, supporting containment, and turning findings into clear remediation steps.
Developing and tuning detection logic, reducing noise, and asking useful questions of the available evidence.
Putting adversary behavior and emerging threats into context for investigations and defensive decisions.
Assessing weaknesses, understanding exposure, and helping prioritize practical fixes.
Working with SIEM, EDR, and SOAR tooling to support repeatable investigations and response workflows.