I work on the defensive side of cybersecurity — building, running, and automating the systems that detect and respond to threats before they become incidents.
With 16+ years in IT and over a decade focused on security operations within the remittance / fintech industry, I lead detection, response, and privileged-access initiatives — and I'm increasingly bringing AI-assisted workflows into the SOC to cut analyst toil and sharpen signal.
A life-long learner and results-oriented team lead, I care about least-privilege design, fail-closed systems, and automation that scales the people, not just the alerts.
"Automating repetitive work so analysts can focus on real threats."
🔍 Detection Engineering → Building and tuning high-fidelity detections
🚨 Security Operations (SOC) → Monitoring, triage, and operational defense
🧯 Incident Response → Investigating breaches, containment & remediation
🐾 Threat Hunting → Proactively chasing adversary behavior
🔐 Privileged Access (PAM) → Securing & governing privileged credentials
🤖 Security Automation → SOAR-style workflows, scripting & AI-assisted ops
Languages & Query
Security Operations
Cloud, Infra & Automation
- 🛠️ Building security tooling and automation projects
- 🤖 Learning AI-assisted Security Operations and Detection Engineering
- 🧪 Tinkering with a defense-in-depth, fail-closed self-hosted home lab