Detection · Engineering · Automation

Senior Security
Engineer

I build better detection capabilities, automate security work, and turn complex security problems into practical solutions.

I've worked inside enterprises and with security vendors, bringing infrastructure knowledge to defensive engineering. I learn new platforms quickly and work with the stack your team already uses.

01 / Detection engineering

From attacker behavior
to useful detections

I look at what an alert tells the analyst, what information is missing, and what the team can do when it fires.

Detection development

I start with attacker behavior and the evidence needed to distinguish it from legitimate activity, then test the logic and tune it for the environment.

Telemetry & reliability

I check whether the required data is present, timely, and usable. Missing logs, incorrect mappings, and ingestion delays can undermine otherwise sound detection logic.

Enrichment & response automation

I bring supporting context into triage and investigation, using integrations to reduce repeated lookups and help analysts decide what to investigate or escalate.

Selected experience

Experience behind the approach

Selected work from enterprise roles at the State of Wisconsin Investment Board and American Solutions for Business, and MDR roles at Alert Logic and Arctic Wolf.

Detection development & validation

Developed and refined hundreds of detections across enterprise and customer environments. Translated threat intelligence and incident findings into SIEM analytics and network rules, mapped detections to MITRE ATT&CK, and used adversary simulation to identify coverage gaps and guide remediation.

Experience includes SQL-style analytics, KQL, Snort, and Suricata; managed network detection content and sensor configurations in Git.

Security platforms & visibility

Implemented SIEM platforms and onboarded infrastructure, application, and security data. Built custom parsers and reports, deployed network and identity sensors, and resolved issues with sensor health, normalization, and log-source coverage.

SIEM experience includes Microsoft Sentinel, AlienVault, and Alert Logic. Infrastructure experience includes administering Linux, Windows desktops, and Windows Server, plus work with VMware, Docker, and containerized services.

Platform hardening & privileged access

Hardened identity and endpoint environments across organizations collectively supporting thousands of users. Reduced unnecessary administrator access and legacy authentication exposure, implemented just-in-time privilege controls, and strengthened endpoint baselines, application controls, and remote-access safeguards.

Examples include Active Directory hardening, Entra ID access controls, Windows LAPS, and BeyondTrust privilege management for Windows and Linux systems.

Cloud, collaboration & data protection

Built Azure configuration guardrails and exposure monitoring. Secured Microsoft 365 email and collaboration through external-sharing controls, sensitivity labels, and data-loss prevention, combining policies with user notifications, tuning, and exception procedures.

Experience includes Azure Policy and RBAC reviews, Defender for Cloud, Microsoft Purview, Exchange Online, SharePoint, OneDrive, and Teams.

Incident investigation & response

Conducted regular threat hunting across enterprise MDR customer environments. Investigated ransomware, business email compromise, suspicious identity activity, and network attacks, including major cases involving external incident-response firms and law enforcement.

Correlated endpoint, identity, network, and cloud evidence, communicated findings, and guided response and remediation. Deployed and used AI-assisted investigation and response alongside endpoint detection and response (EDR) tooling.

Tools include CrowdStrike Falcon and Microsoft Defender XDR; AI-assisted tooling includes Wraithwatch and Microsoft Security Copilot.

Customer advisory & remediation

Across multiple MDR roles, I've advised 50+ enterprise customers, working with their analysts, engineers, and security leaders to understand each environment. I help teams interpret findings, understand how their controls affect the risk, and decide what to address first.

During investigations and major vulnerability response efforts, I explain what the evidence shows and where questions remain. I recommend next steps that fit the people and tools the customer has available.

Experience includes incident communication, visibility reviews, and guidance during Log4Shell, ProxyShell, and PrintNightmare response.

Enrichment, workflows & integrations

Integrated enrichment into triage and investigation workflows. Automated recurring reports, vulnerability data retrieval, and configuration monitoring through scripts, SIEM queries, and APIs. Used managed identities for authenticated integrations and event-driven services to deliver findings.

I write and troubleshoot basic Python scripts and use PowerShell and Bash shell scripting for operational tasks. I've also built Model Context Protocol (MCP) integrations for ChatGPT users with delegated Microsoft Graph permissions.

Integration tools include REST APIs, Microsoft Graph, and Azure Logic Apps.

Examples of technical delivery

  • Visibility into privileged activity: Built Sentinel analytics to flag privileged identity activity outside expected operating hours.
  • Enrichment during triage: Brought supporting context into the workflow so analysts could assess alerts with the evidence at hand.
  • Telemetry health monitoring: Added ingestion monitoring to identify delayed data before relying on it in investigations.
  • Less standing privilege: Reduced broad administrator access and introduced controlled elevation and managed local credentials.
  • Custom log ingestion: Made application and infrastructure logs available in Sentinel through custom pipelines and KQL parsers.

02 / Security engineering & consulting

A clear problem
A working solution

I help teams define the work, implement the controls, and document how to operate and maintain them.

Assess & design

I review the environment and existing controls with the team, then agree on the gaps to address and the scope of the work.

Implement & harden

I configure the controls and integrations, test them, and adjust where they interfere with how the team needs to work.

Document & hand off

I document the configuration, routine tasks, and troubleshooting steps so the team can support the work after handoff.

Additional security tooling: CrowdStrike, Zscaler, BeyondTrust, Tenable, and Mimecast.

How I work

Technical depth
Clear communication

I've spent more than 20 years in IT, including 9+ years focused on security. That background helps me trace problems through the systems behind the alerts.

I've mentored analysts and engineers on detection development and security tooling, and worked with infrastructure, networking, and application teams to resolve findings and implementation issues.

AI-Assisted, Not AI-Dependent

I've developed detections, written scripts, built custom logging pipelines, and supported investigations with AI assistance.

Tools I've used include Claude Code, OpenAI Codex, self-hosted LLMs, and Copilot. I review generated code, check findings against the evidence, and test changes before using them.

GIAC: GCIA (Gold) · GCIH · GSEC
Graduate Certificate in Cybersecurity Engineering, SANS Technology Institute

Next step

Have a role in mind?

I'm interested in fully remote senior detection engineering roles and security engineering roles in consulting or professional services, with limited travel.

Send me the role or the problem your team needs to solve. Let's see where my experience fits.

Start a conversation Request resume Connect on LinkedIn

My resume provides employment history and additional technical detail.