Detection & Security Automation Engineer
I build reliable triage from noisy telemetry — behavioral Sigma detections, SIEM tuning, identity attack detection, and SOAR automation — each documented with real false-positive scenarios and repeatable response playbooks.
Currently a Service Desk Analyst moving toward a blue-team / detection role, and pursuing an MS in Cybersecurity at Western Governors University (expected October 2026).
Languages & frameworks
Security, cloud & infrastructure
Featured — Stryker / Intune Detection Pack — Detection-as-code for Intune MDM abuse, modeled on the 2026 Stryker/Handala attack: Sigma rules, KV-store enrichment, and response playbooks mapped to MITRE ATT&CK.
Blue Team SOC Monitoring Lab |
SOAR-lite — IR Orchestrator |
Network Behavior Analyzer |
|---|---|---|
|
|
|
More detection work:
- Okta Detection Engine — Python detections for identity attacks: MFA fatigue, impossible travel, and more.
- Phishing Analysis Lab — End-to-end phishing triage: header inspection, link extraction, VirusTotal enrichment, analyst reports.
- AWS Identity Detection Lab — CloudTrail-style detection scenarios with pytest-backed detection logic.
- Security+ Learning Lab · TCM SOC 101 Notes — Hands-on labs and course notes.
Cloud Infrastructure Security Auditor |
Azure Cloud Hardening Lab |
|---|---|
|
|
Where I lean on LLMs as a force-multiplier for security and productivity work:
G3-GPT — Document Retrieval |
AI Log Auditor |
Synapse AI Chat |
|---|---|---|
|
|
|
Also: Whisper Transcribe (local faster-whisper + CUDA transcription) · Claude Code Skills (reusable Claude Code skill packs).
- Master's in Cybersecurity — Western Governors University (Expected October 2026)
- B.S. in Computer Science — California State University, Sacramento
- CompTIA SecurityX (CAS-005) — 2026
- CompTIA PenTest+ (PT0-003) — 2026
- CompTIA CySA+ (CS0-003) — Feb 2026
- CompTIA Security+ (SY0-701) — Jan 2026
- CompTIA CSIE (Secure Infrastructure Expert) — stackable credential









