Investigating activity across modern environments
I triage and correlate security activity across SIEM, cloud, endpoint, network, identity and device-management environments to determine what happened, why it matters and what should happen next.
Security work
My security practice spans alert investigation, threat monitoring, exposure management and clear reporting across enterprise and public-sector environments.
I triage and correlate security activity across SIEM, cloud, endpoint, network, identity and device-management environments to determine what happened, why it matters and what should happen next.
I research suspicious infrastructure, exposed assets, vulnerabilities and emerging threats, then turn the findings into reports and recommendations that stakeholders can act on.
I support recurring vulnerability assessments, compare findings over time and help turn technical weaknesses into priorities that can be followed through.
I investigate recurring patterns, validate findings and contribute to tuning work that improves detection quality and reduces unnecessary noise.
I led a practical session for 12 analysts on finding exposed information and infrastructure with open-source methods. The session introduced additional AI-related exposure paths and led to an update of the team’s attack surface monitoring playbook.
Monitored and investigated security events protecting state ministries, departments and agencies, using threat intelligence to support analysis and security recommendations.
Hiring