Detection Engineering
Build high-signal detections across endpoint, identity, network and cloud telemetry, with tuning loops that reduce alert fatigue.
I design security operations that turn noisy signals into decisive action, from detection logic and threat hunting to incident response and cloud hardening.
Strong security is not a single control. It is a connected structure of visibility, identity, detection, response and recovery, designed so one weak point does not collapse the whole system.
Capabilities are shown as a modular security lattice rather than generic percentage bars.
Build high-signal detections across endpoint, identity, network and cloud telemetry, with tuning loops that reduce alert fatigue.
Contain, scope, eradicate and document incidents with calm, repeatable playbooks.
Identity-first controls for AWS and Azure workloads, secrets, logging and least privilege.
Hypothesis-led hunts connect behavioral indicators across identity, endpoint and network layers.
Selected security roles across SOC operations, detection engineering and cloud security programs.
Own detection strategy across identity and cloud telemetry. Built rule lifecycle standards, threat-hunting workflows and response integrations for a distributed SaaS environment.
Led investigations for account compromise, malware and suspicious authentication activity while improving triage quality and incident documentation.
Monitored enterprise security telemetry, enriched alerts with threat intelligence and helped turn recurring incidents into durable controls.
Selected projects framed around the threat, intervention and measurable security outcome.
Mapped privileged access paths, introduced conditional access controls and rebuilt high-risk authentication detections, reducing exposed administrative routes across critical workloads.
Combined endpoint process behavior, file activity and identity context into a compact detection chain for faster escalation.
Created severity-based playbooks connecting triage, containment, evidence capture, communications and recovery ownership.
For security leadership, detection engineering, incident response or defensive architecture conversations, send a note.
Professional network
Connect on Linkedin ↗
Open to security-focused opportunities, advisory conversations and technical collaborations.