Detection development
I start with attacker behavior and the evidence needed to distinguish it from legitimate activity, then test the logic and tune it for the environment.
Detection · Engineering · Automation
I build better detection capabilities, automate security work, and turn complex security problems into practical solutions.
I've worked inside enterprises and with security vendors, bringing infrastructure knowledge to defensive engineering. I learn new platforms quickly and work with the stack your team already uses.
01 / Detection engineering
I look at what an alert tells the analyst, what information is missing, and what the team can do when it fires.
I start with attacker behavior and the evidence needed to distinguish it from legitimate activity, then test the logic and tune it for the environment.
I check whether the required data is present, timely, and usable. Missing logs, incorrect mappings, and ingestion delays can undermine otherwise sound detection logic.
I bring supporting context into triage and investigation, using integrations to reduce repeated lookups and help analysts decide what to investigate or escalate.
Selected experience
Selected work from enterprise roles at the State of Wisconsin Investment Board and American Solutions for Business, and MDR roles at Alert Logic and Arctic Wolf.
Developed and refined hundreds of detections across enterprise and customer environments. Translated threat intelligence and incident findings into SIEM analytics and network rules, mapped detections to MITRE ATT&CK, and used adversary simulation to identify coverage gaps and guide remediation.
Experience includes SQL-style analytics, KQL, Snort, and Suricata; managed network detection content and sensor configurations in Git.
Implemented SIEM platforms and onboarded infrastructure, application, and security data. Built custom parsers and reports, deployed network and identity sensors, and resolved issues with sensor health, normalization, and log-source coverage.
SIEM experience includes Microsoft Sentinel, AlienVault, and Alert Logic. Infrastructure experience includes administering Linux, Windows desktops, and Windows Server, plus work with VMware, Docker, and containerized services.
Hardened identity and endpoint environments across organizations collectively supporting thousands of users. Reduced unnecessary administrator access and legacy authentication exposure, implemented just-in-time privilege controls, and strengthened endpoint baselines, application controls, and remote-access safeguards.
Examples include Active Directory hardening, Entra ID access controls, Windows LAPS, and BeyondTrust privilege management for Windows and Linux systems.
Built Azure configuration guardrails and exposure monitoring. Secured Microsoft 365 email and collaboration through external-sharing controls, sensitivity labels, and data-loss prevention, combining policies with user notifications, tuning, and exception procedures.
Experience includes Azure Policy and RBAC reviews, Defender for Cloud, Microsoft Purview, Exchange Online, SharePoint, OneDrive, and Teams.
Conducted regular threat hunting across enterprise MDR customer environments. Investigated ransomware, business email compromise, suspicious identity activity, and network attacks, including major cases involving external incident-response firms and law enforcement.
Correlated endpoint, identity, network, and cloud evidence, communicated findings, and guided response and remediation. Deployed and used AI-assisted investigation and response alongside endpoint detection and response (EDR) tooling.
Tools include CrowdStrike Falcon and Microsoft Defender XDR; AI-assisted tooling includes Wraithwatch and Microsoft Security Copilot.
Across multiple MDR roles, I've advised 50+ enterprise customers, working with their analysts, engineers, and security leaders to understand each environment. I help teams interpret findings, understand how their controls affect the risk, and decide what to address first.
During investigations and major vulnerability response efforts, I explain what the evidence shows and where questions remain. I recommend next steps that fit the people and tools the customer has available.
Experience includes incident communication, visibility reviews, and guidance during Log4Shell, ProxyShell, and PrintNightmare response.
Integrated enrichment into triage and investigation workflows. Automated recurring reports, vulnerability data retrieval, and configuration monitoring through scripts, SIEM queries, and APIs. Used managed identities for authenticated integrations and event-driven services to deliver findings.
I write and troubleshoot basic Python scripts and use PowerShell and Bash shell scripting for operational tasks. I've also built Model Context Protocol (MCP) integrations for ChatGPT users with delegated Microsoft Graph permissions.
Integration tools include REST APIs, Microsoft Graph, and Azure Logic Apps.
02 / Security engineering & consulting
I help teams define the work, implement the controls, and document how to operate and maintain them.
I review the environment and existing controls with the team, then agree on the gaps to address and the scope of the work.
I configure the controls and integrations, test them, and adjust where they interfere with how the team needs to work.
I document the configuration, routine tasks, and troubleshooting steps so the team can support the work after handoff.
Additional security tooling: CrowdStrike, Zscaler, BeyondTrust, Tenable, and Mimecast.
How I work
I've spent more than 20 years in IT, including 9+ years focused on security. That background helps me trace problems through the systems behind the alerts.
I've mentored analysts and engineers on detection development and security tooling, and worked with infrastructure, networking, and application teams to resolve findings and implementation issues.
I've developed detections, written scripts, built custom logging pipelines, and supported investigations with AI assistance.
Tools I've used include Claude Code, OpenAI Codex, self-hosted LLMs, and Copilot. I review generated code, check findings against the evidence, and test changes before using them.
GIAC: GCIA (Gold) · GCIH · GSEC
Graduate Certificate in Cybersecurity Engineering, SANS Technology Institute
Next step
I'm interested in fully remote senior detection engineering roles and security engineering roles in consulting or professional services, with limited travel.
Send me the role or the problem your team needs to solve. Let's see where my experience fits.
My resume provides employment history and additional technical detail.