[+] BOOZ ALLEN HAMILTON
Senior Security Engineer | 2023–Present
- └─ Led Zero Trust modernization for USSOCOM, identifying security gaps and aligning controls across identity, cloud, and endpoint layers
- └─ Implemented IAM, EDR, and SIEM tooling to enforce least privilege, MFA, and real-time threat detection across hybrid infrastructure
- └─ Built automated pipelines for audit-ready access governance, anomaly detection, and mission risk reduction
- └─ Advised senior DoD stakeholders on cyber posture, detection maturity, and control design during live mission support
[+] GENERAL DYNAMICS INFORMATION TECHNOLOGY
Endpoint Security Engineer | 2021–2023
- └─ Tuned EDR and SIEM to detect malware, lateral movement, and credential misuse across 15K+ classified endpoints
- └─ Developed custom detection rules and alerting for privilege escalation, code injection, and persistence techniques
- └─ Enhanced incident response workflows by correlating host-based signals with attacker TTPs and anomaly patterns
- └─ Supported DLP enforcement, rogue device monitoring, and continuous endpoint compliance
[+] U.S. NAVY (RESERVES)
Cyber Threat Intelligence Specialist | 2019–Present
- └─ Produced high-confidence intelligence on APT campaigns, credential theft, and infrastructure targeting
- └─ Integrated MISP and CTI sources into Splunk to enrich detection for cloud, endpoint, and identity abuse
- └─ Conducted threat modeling and tracking of adversary TTPs to prioritize detection engineering and hunt missions
- └─ Briefed joint cyber leadership on operational risk, evolving tradecraft, and threat actor capabilities
TECHNICAL SKILLS
Programming
Python, Bash, PowerShell, JavaScript, SQL, HTML/CSS
Web Security
Burp Suite, OWASP ZAP, SSRF/IDOR, JWT manipulation, Recon tooling
Cloud & Infrastructure
AWS, Azure, GCP, Docker, Kubernetes, GitHub Actions, Terraform
Identity & Access
Azure AD, AWS IAM, Okta, Entra ID, Conditional Access, SAML, SCIM, RBAC, JIT
Detection & Monitoring
SIEM, EDR tuning, Threat Hunting, Detection-as-Code, Log Engineering, Sysmon
Automation & CI/CD
Python, PowerShell, Bash, GitHub Actions, Jenkins, REST APIs
Adversary Simulation
MITRE ATT&CK, Threat Modeling, Red/Blue Team Ops, TTP Validation
Compliance & Frameworks
Zero Trust (NIST 800-207), NIST 800-53, ISO 27001, FedRAMP, SOC 2
[EOF]