Four disciplines. One security-first standard.
The same four capabilities from my homepage, expanded into full engagements: how each one runs, the tooling behind it, and the outcome you can hold me to. Every service links straight to field work — proof, not promises.
SOC & Cybersecurity
Most environments don't lack logs — they lack signal. This engagement builds (or overhauls) your detection capability: instrumenting the right sources, writing detection logic mapped to real adversary behaviour, and putting a documented response process behind every alert so an incident becomes a procedure instead of a panic.

- 01Scope & Baseline
Inventory every log source and asset, map current detection coverage against MITRE ATT&CK, and agree a severity and escalation matrix before anything is deployed.
- 02Instrument
Deploy and tune the SIEM (Splunk or Wazuh), roll out Sysmon and forwarders, and wire in threat-intel enrichment so events arrive with context, not just noise.
- 03Detect & Triage
Author Sigma-based detection rules mapped to ATT&CK techniques, tune out false positives against your real traffic, and document a triage runbook for every alert class.
- 04Respond & Report
Contain and eradicate confirmed incidents, write the post-incident report, and deliver monthly coverage reports so you can watch detection measurably improve.
- Splunk
- Wazuh
- Sysmon
- Sigma
- MITRE ATT&CK
- TheHive
- MISP
Hover any tool to see its role in this workflow.
A monitored environment with measurable coverage — in my lab and client work this standard has produced 60+ detection rules across 42 MITRE ATT&CK techniques and cut mean time-to-contain from 4 hours to 22 minutes.
SOC Home Lab: SIEM Deployment & Threat Detection
Fully operational lab producing documented incident write-ups used as portfolio evidence for SOC readiness.
Phishing Response Playbook & Automation
Mean time-to-contain dropped from 4h to 22m across a 30-day window.
Secure Web Deployment
A deployment is a security decision, whether you make it deliberately or not. I build and harden the full path from DNS to origin under the assumption that the site will be scanned within hours of going live — because it will be.
Design & build work → via ArtX Studio ↗
- 01Threat-Model the Stack
Enumerate the real exposure: open ports, DNS records, TLS posture, third-party scripts, and CI/CD secrets. Nothing gets hardened until it's mapped.
- 02Harden the Base
Apply CIS-benchmark hardening to the OS and web server, enforce key-only SSH and least-privilege access, and lock down every service that doesn't need to be public.
- 03Encrypt & Shield
Enforce TLS 1.3 with HSTS, deploy WAF rules and rate limiting at the edge, and put DDoS mitigation in front of the origin before launch — not after the first attack.
- 04Verify & Hand Over
Re-scan with independent tooling, close what's found, and codify the entire hardened state in Terraform so it's reproducible — with documentation your team can actually operate.
- Nginx
- Cloudflare
- Terraform
- Let's Encrypt
- Fail2ban
- Lynis
- OWASP ZAP
Hover any tool to see its role in this workflow.
Infrastructure that survives contact: the last client launch shipped with an A+ TLS grade, 92% of flagged vulnerabilities closed on re-scan, and zero minutes of downtime through launch week.
Technical & Secure SEO
I audit a website the way I audit an attack surface — because to a crawler and an attacker, they're the same thing. Technical SEO done this way fixes rankings and closes exposure at the same time: staging leaks, misconfigured directives, slow render paths, and duplicate content are all the same class of problem.

- 01Crawl & Expose
Run a full technical crawl to see exactly what search engines see: indexation leaks, redirect chains, orphaned pages, duplicate content, and anything exposed that shouldn't be.
- 02Fix the Foundations
Rebuild the robots and sitemap strategy, enforce canonical URLs, implement structured data, and close every indexation leak — staging domains included.
- 03Accelerate
Refactor the render path, image pipeline, and caching strategy until every Core Web Vital is in the green on real mobile devices, not just lab runs.
- 04Monitor & Defend
Wire Search Console and Lighthouse checks into an ongoing report so gains hold, regressions get caught early, and nothing quietly re-leaks.
- Screaming Frog
- Lighthouse
- Search Console
- Schema.org
- Cloudflare
- Next.js
Hover any tool to see its role in this workflow.
Rankings built on infrastructure that's fast and closed: the last audit delivered +38% organic traffic in 90 days, a 1.4s LCP, and zero remaining indexation leaks.
Secure Custom AI Agents
Most AI automation fails one of two ways: it doesn't actually save time, or it quietly becomes a data-leak vector. I build custom agents scoped to one real workflow, engineered against the OWASP LLM Top 10 from the first commit — so the automation compounds and the risk doesn't.

- 01Map the Workflow
Sit with the actual process — the tickets, logs, or CRM entries eating your team's hours — and define exactly what data the agent may touch and what permissions it needs. Nothing more.
- 02Design the Guardrails
Scoped tokens, field-level redaction, prompt-injection defenses, and output validation — designed before the first line of agent logic is written.
- 03Build & Integrate
Python and FastAPI service with vault-backed secrets, containerized deployment, and API integrations that authenticate as the user — never as a god-mode service account.
- 04Observe & Iterate
Full audit logging and OpenTelemetry tracing on every action, plus measured accuracy reviews so the agent improves on evidence, not vibes.
- Python
- FastAPI
- OpenAI API
- Docker
- Redis
- OAuth 2.0
- OpenTelemetry
Hover any tool to see its role in this workflow.
Automation with receipts: a triage agent that cut manual alert review by 68%, and a CRM assistant that ran six months in production with zero PII incidents and a complete audit trail.
Log Triage AI Agent
68% reduction in manual triage volume, freeing analyst time for genuine anomalies.
Secure CRM Assistant with Scoped Access
Zero PII incidents in 6 months, 3x faster note capture per rep.
Freelance project
Fixed-scope engagement with defined deliverables and hardening acceptance criteria.
Retainer
Ongoing monitoring, response, and iterative hardening on your infrastructure.
Consultation
Focused review sessions — architecture, audits, or a second set of eyes.
Have a security gap you want mapped?
Open a channel and I'll respond with a scoped plan — deliverables, timeline, and acceptance criteria — not a sales pitch.
Secure Web Deployment Checklist
The exact 27-point checklist I run before any client site goes live — TLS, headers, DNS, access control, and edge protection. Request it and I'll send it over, along with one free observation about your current setup.
Request the checklist →