Security engineer with 8 years defending Department of the Air Force networks as a Cyber Defense Operations specialist (1D7). I have run detection engineering and incident response for a 40,000-user enterprise, automated triage in Python, and led a 9-person defensive team. Google Cloud Professional Cloud Security Engineer. Targeting Security Engineer, Google Cloud.
Security:Detection engineering, Incident response, Threat hunting, Vulnerability management, MITRE ATT&CK, Zero trust
Cloud & Tools:Google Cloud (IAM, VPC Service Controls, Security Command Center), Splunk, Chronicle SIEM, CrowdStrike, Palo Alto NGFW
Code:Python, SQL, Bash, YARA-L, Terraform
- Reduced mean time to detect intrusions from 19 hours to 4 hours, as measured in quarterly red-team exercises, by writing 60+ detection rules mapped to MITRE ATT&CK and tuning out 70% of false positives.
- Saved 25 analyst hours per week, as measured by ticket-handling time, by building a Python triage pipeline that pulls threat intel and enriches SIEM alerts automatically.
- Brought a 9-person defensive team to 100% mission-ready in 5 months (the standard is 8), as measured by unit certification records, by designing a lab-based qualification track.
- Closed 1,200 critical vulnerabilities across 3,400 hosts with zero mission downtime, as measured by weekly scan data, by phasing patch windows around flight-operations schedules.
- Contained 14 confirmed incidents with no data loss, as measured by after-action reports, by running containment playbooks across firewall, endpoint, and identity tools.
- Cut firewall rule sprawl 38% (4,100 to 2,540 rules), as measured by a config audit, by leading a rule-recertification review with 12 system owners.
- Moved 3 legacy logging servers to a cloud log pipeline 6 weeks early, as measured against the program schedule, by scripting the migration and validation checks.
- Google Cloud Professional Cloud Security Engineer
- CompTIA Security+
- GIAC Certified Incident Handler (GCIH)