I build detections that hold up in production — multi-platform, MITRE-mapped, and tuned against real adversary behavior.
Currently engineering detections and automations across Google SecOps (Chronicle), Microsoft Sentinel, and Splunk in a cleared environment supporting U.S. federal operations.
| Domain | Tools & Languages |
|---|---|
| Detection | YARA-L · KQL · SPL · Sigma |
| Platforms | Google SecOps · Microsoft Sentinel · Splunk · Defender XDR |
| Automation | Python · AWS Lambda · Cribl Stream |
| Identity | SailPoint · ThreatLocker |
| Cloud | AWS · Azure |
light-from-the-shadows — Production-grade detection rules, enrichment scripts, SOC response templates, and MITRE ATT&CK coverage across Google SecOps, Sentinel, Defender XDR, and Splunk.
detection-engineering-lab — Lab environment builds and experimental detection work.
- Detection Engineer · Peraton (supporting U.S. Department of State) · TS/SCI
- Detection Engineer · Nelnet
- Prior adversary pursuit · CISA · nation-state tracking
- MARFORCYBER · NSM · KQL · threat hunting · IR
- GCFA · CASP+ · Cribl Certified User
- B.S. Cybersecurity · WGU
"Detection is the art of making the invisible visible."
