Defensive systems online
Alex Morgan / 2026
01 - Cybersecurity portfolio

Protect theconnected.

I design security operations that turn noisy signals into decisive action, from detection logic and threat hunting to incident response and cloud hardening.

Profile

Defense is
a lattice.

Strong security is not a single control. It is a connected structure of visibility, identity, detection, response and recovery, designed so one weak point does not collapse the whole system.

42Detection rules shipped
18Response playbooks
31Cloud workloads hardened
7Years in security
Expertise

Signals.
Controls.
Response.

Capabilities shown as a modular security lattice rather than generic percentage bars.

NODE / 01 📊

Detection Engineering

Build high-signal detections across endpoint, identity, network and cloud telemetry, with tuning loops that reduce alert fatigue.

SIEMEDRSigmaThreat Intel
NODE / 02 🚨

Incident Response

Contain, scope, eradicate and document incidents with calm, repeatable playbooks.

NODE / 03 ☁️

Cloud Defense

Identity-first controls for AWS and Azure workloads, secrets, logging and least privilege.

NODE / 04 🔍

Threat Hunting

Hypothesis-led hunts connect behavioral indicators across identity, endpoint and network layers.

86%
Hunt coverage across priority data
Experience

From noise
to signal.

Selected security roles across SOC operations, detection engineering and cloud security programs.

Lead Detection Engineer · Northstar Cloud

Own detection strategy across identity and cloud telemetry. Built rule lifecycle standards, threat-hunting workflows and response integrations for a distributed SaaS environment.

Senior Security Analyst · Meridian Fintech

Led investigations for account compromise, malware and suspicious authentication activity while improving triage quality and incident documentation.

SOC Analyst · BluePeak Systems

Monitored enterprise security telemetry, enriched alerts with threat intelligence and helped turn recurring incidents into durable controls.

Casework

Inside the
defense grid.

Selected projects framed around the threat, intervention and measurable security outcome.

CASE / 001

Identity attack-path reduction

Mapped privileged access paths, introduced conditional access controls and rebuilt high-risk authentication detections, reducing exposed administrative routes across critical workloads.

IAMZero TrustCloud
CASE / 002

High-signal ransomware detection

Combined endpoint process behavior, file activity and identity context into a compact detection chain for faster escalation.

CASE / 003

Incident response lattice

Created severity-based playbooks connecting triage, containment, evidence capture, communications and recovery ownership.

Contact

Let's secure
the next layer.

For security leadership, detection engineering, incident response or defensive architecture conversations, send a note.

Open to security-focused opportunities, advisory conversations and technical collaborations.

✉ alex.sec@example.com
◈ Toronto, Canada
in GH