Trained to watch what others overlook.
I approach security the way an analyst approaches a live incident — methodically, skeptically, with a bias toward evidence over assumption. Hands-on detection work: correlating logs, triaging alerts, tracing anomalies to root cause.
- SIEM correlation & alert triage
- IDS/IPS tuning & threat hunting
- Incident response & root-cause
- Zero-trust & TLS 1.3 enforcement
- Hardened deployments & audits
- Secure AI agents & automation
Security isn't a final checklist item — it's the design constraint everything else is built around. Nothing ships until it's been stress-tested through an attacker's lens.
"Secure by Design means the safeguard isn't bolted on after launch — it's the reason the architecture looks the way it does."
- CompTIA Security+
- CompTIA CySA+
- TryHackMe — Top 1%
- AWS Cloud Practitioner
One standard. Three domains.
Threat Detection & SOC
SIEM correlation, IDS/IPS tuning, alert triage and incident response — built on real lab environments and production-grade frameworks.
Secure Infrastructure
Zero-trust architecture, TLS 1.3 enforcement, DDoS mitigation, and CIS-benchmark hardening from OS to edge.
Secure AI Automation
Custom agents built privacy-first — scoped tokens, field-level redaction, prompt-injection defences, and full audit trails.
The stack, mapped.
- Splunk
- ELK / Wazuh
- IDS/IPS
- MITRE ATT&CK
- Sigma rules
- Log correlation
- Incident triage
- Linux hardening
- TLS 1.3
- DNS security
- AWS / Azure
- Nginx
- Cloudflare
- Terraform
- Python
- REST / GraphQL
- LLM workflows
- OWASP LLM Top 10
- Secrets vaulting
- OpenTelemetry
- NIST CSF
- MITRE ATT&CK
- OWASP Top 10
- CIS Benchmarks