Johnathan Dempsey
Experience
Seven roles building detection programs and, most recently, securing the AI agents and automation that security operations now depend on, across regulated fintech, nonprofit, enterprise, and industrial environments.
Detection Engineer
2026 to present
FinTech, remote
Securing the AI agents and automation behind detection and response, and putting about 157 detection rules under CI governance.
- Hardened agentic security operations: found Claude Code safety rules silently dropped past a 2,000-character cutoff and fixed them, then shipped an agent-monitoring playbook, a Cloudflare account-takeover response skill, and recurring audits of agent instructions.
- Built an in-house AI pull request reviewer that cut shared review cost 55-60%, then capped review-fleet spend and corrected cost-tracking errors, including a 1.45x error on one model.
- Built detection-as-code pipelines for SentinelOne and Uptycs from scratch: moved all 22 live SentinelOne detections into Git behind CI gates and brought ~157 previously ungoverned rules, including 81 builder rules and 13 YARA groups, under version control with a Sigma backend.
- Deployed live canaries and tenant probes that exposed silent detection failures, such as wrong output columns and enable calls reporting success on disabled rules, and drift checks that recovered two unmanaged production YARA rules, including Shai-Hulud v2 npm detection.
- Closed a fail-open in phishing auto-close automation, locked down AI instruction governance, and added insider-risk monitoring on the detection-rules repository.
- Serve as incident commander on rotation, run hypothesis-driven threat hunts across endpoint, identity, and cloud telemetry, and act as the human-in-the-loop auditor for AI-generated investigation narratives.
Read the full story
The platform is a cloud-native digital banking provider serving roughly eight million consumer accounts across ninety financial institutions. In a regulated environment, AI agents and automation are only useful if they can be trusted, so much of the work is making them auditable: instructions under version control, guardrails that are tested instead of assumed, and cost and behavior that are monitored.
AI-driven triage and SOAR handle routine alert processing. The job is building the detections those platforms run, proving they actually fire, and hunting what evades them. The recurring theme is silent failure: a safety rule that gets truncated, a rule that reports enabled but is not, an automation that fails open. Canaries, drift checks, and CI gates exist to turn those into loud failures. Coverage is mapped to MITRE ATT&CK and gaps are tracked in the detection backlog.
Focus: Agentic AI security, LLM guardrails, AI cost governance, detection-as-code, Sigma and YARA, SentinelOne and Uptycs, MITRE ATT&CK, incident command.
Senior Manager, Security Operations
2024 to 2026
National Audubon Society, remote
Built a SOC from zero on AI-native tooling: 99.2% detection fidelity, 95% fewer false positives, MTTD down 65%.
- Sole security engineer and architect responsible for all aspects of information security.
- Built the SOC from scratch on AI SOC and AI-native tooling: 99.2% detection fidelity, 95% fewer false positives, MTTD down 65%.
- Wrote the AI governance roadmap for secure GenAI adoption.
- Moved the organization to AI-powered email security, cutting business email compromise incidents 99%.
- Multi-cloud monitoring across AWS, Azure, and GCP with centralized threat intelligence, improving cloud security posture 70%.
- Phishing-resistant MFA at 100% across 1,000+ users; MDR migration savings of $32,000 redeployed into a new vulnerability management program.
Read the full story
When I joined National Audubon Society in 2024, there was no SOC, no formal detection program, and security tooling spread across disconnected point solutions. The first architectural decision was SOC model: traditional MDR vs. AI-native. MDR requires analyst headcount to triage, a model that fails on cost before it fails on coverage for a single-person security team. I selected an AI-native platform that could deliver consistent detection fidelity without the analyst-to-alert ratio that makes MDR viable only at scale. The result: 99.2% detection fidelity and a 95% reduction in false positives.
Detection coverage was built MITRE ATT&CK-first, starting with the highest-probability attack paths for a hybrid cloud environment: identity-based attacks, credential stuffing, OAuth abuse, and business email compromise. Okta is the enterprise IdP and I led the rollout of phishing-resistant MFA across 1,000+ users, removing the credential-theft risk that email compromise campaigns rely on. SAML and OAuth integrations provided detection visibility into identity-based lateral movement that endpoint telemetry alone misses.
The AI governance roadmap gave the organization a path to adopt generative AI securely instead of discovering unsanctioned use after the fact, and the move to AI-powered email security cut business email compromise incidents by 99%.
The $32,000 MDR contract savings were reinvested into Tenable One, building a vulnerability management program across endpoint, cloud, web application, and attack surface management domains. A program that can only detect is incomplete; understanding the full attack surface is what lets you prioritize detection coverage correctly.
Focus: AI-driven detection, AI governance, SOC build-out, MITRE ATT&CK, Okta IAM, Tenable One, multi-cloud.
Security Engineer
2022 to 2024
CrowdStrike, remote
Detection-as-code and SOAR automation on the TIDE team: deployment cycle time down 80%.
- Internal enterprise defense on the TIDE team.
- Insider threat false positives down 50% with behavior-based tuning.
- Engineered and implemented detections against Scattered Spider.
- Analyst response time down 80% and MTTR down 70% via automation through Tines and ServiceNow Flow Designer.
- 30% of enterprise alerting personally migrated from Splunk to Falcon LogScale.
Read the full story
CrowdStrike's TIDE (Threat Intelligence and Detection Engineering) team defends the company's own internal infrastructure, a threat model distinct from most enterprise environments, since sophisticated adversaries actively go after security vendors for the access and intelligence that comes with it. The structural change with the most lasting impact was implementing Detection-as-Code via Bitbucket pipelines. Detection logic that previously lived in a UI moved into version-controlled files with peer review, syntax validation, and automated deployment. Deployment cycle time dropped 80%. Peer review consistently caught logic errors and coverage gaps that single authors missed.
Scattered Spider presented a specific detection challenge. The campaign used social engineering via SMS phishing and SIM swapping to compromise Okta and Azure AD environments. I engineered targeted detections against those exact TTPs: not broad behavioral rules, but specific patterns drawn from threat intelligence. Precision matters: broad rules generate noise that burns analyst capacity; precise rules that fire accurately are the ones analysts actually act on. During the Splunk to Falcon LogScale migration, I covered 30% of the enterprise alerting rules, improving detection latency on high-volume telemetry streams. Tines SOAR automation reduced analyst response time 80% by converting repetitive triage steps into automated playbooks.
Focus: Detection-as-code, SOAR automation, Falcon LogScale, Splunk migration, threat intel.
Senior Security Engineer
2022
U.S. Bank, remote
Rebuilt Azure detection coverage during an on-prem migration: coverage up 20%.
- Azure cloud security detection coverage during an on-prem migration.
- Detection backlog down 39% in three months.
- Coverage grew 20% and was mapped to MITRE ATT&CK.
- Led a team of four security engineers through the migration program.
Read the full story
Cloud migrations create detection coverage gaps. Legacy SIEM rules written for on-prem telemetry don't translate to cloud-native log sources. Azure Monitor, Defender for Cloud, and Entra ID produce different formats and expose different attack patterns than on-prem Active Directory. Attackers know defenders are distracted during migrations. The work at U.S. Bank was specifically about closing those gaps as the data center moved to Azure: rebuilding detection coverage for Azure-specific attack paths including service principal abuse, conditional access policy bypass, and storage account misconfiguration.
Detection backlog dropped 39% in three months. Coverage grew 20% with every new detection mapped to a MITRE ATT&CK technique, not just for optics, but to systematically surface remaining gaps and communicate coverage to security leadership in a framework they could act on.
Focus: Cloud migration, detection engineering, team leadership.
Security Engineer
2021 to 2022
Sunbelt Rentals, remote
Deployed Sysmon telemetry across 10k+ endpoints and built the SIEM parsers that made it usable.
- Deployed Sysmon across 10k+ endpoints.
- Wrote custom SIEM parsers and PowerShell workflows.
- Main escalation point for all incidents.
Read the full story
Sunbelt Rentals operates across industrial environments including OT sites, a threat surface most security tooling isn't designed for. The detection challenge was foundational: without reliable endpoint telemetry, you can't write meaningful detection rules. Deploying Sysmon across 10,000+ endpoints standardized collection. Sysmon's process creation, network connection, file creation, and registry modification events provided the raw telemetry data that Windows Event Logs don't capture by default. Custom SIEM parsers normalized log formats across an environment with mixed OS versions, network architectures, and application stacks. PowerShell workflows automated repetitive triage steps.
Focus: Sysmon telemetry, SIEM engineering, NIST CSF, MSSP.
Security Engineer
2020 to 2021
CyberMaxx, remote
Tuned SIEM detection and MDR platforms across 10-15 healthcare and banking clients.
- Deployed and tuned SIEM detection and MDR platforms across 10–15 healthcare and banking clients.
- Automated KPI reporting in Bash and Python, replacing manual SOC reporting.
Read the full story
CyberMaxx is a managed detection and response provider. I worked across 10–15 healthcare and banking clients simultaneously, which meant understanding the difference between a detection that's technically correct and one that's operationally useful for a specific environment. Vendor-default SIEM rules generate thousands of false positives in any real deployment because they don't account for baseline behavior. Administrative login activity looks different in a hospital than in a financial institution. Detection tuning is the work of encoding each client's real baseline and threat model into detection logic, not the theoretical baseline the vendor assumed when writing the default rule. Automated KPI reporting in Bash and Python replaced a manual process that was consuming several analyst hours per week, improving accuracy and freeing capacity for actual detection work.
Focus: MDR, SIEM tuning, incident response.
Systems and Network Engineering
2013 to 2020
Various companies, on site
Seven years of systems and network engineering across retail, OT, and finance.
- Systems and network engineering across retail, OT, and finance.
- The technical base for the security work that followed.
Read the full story
Seven years in systems and network engineering across retail, OT, and finance built the infrastructure knowledge that makes detection engineering possible. Understanding how Active Directory authentication works at a protocol level, how traffic flows across network segments, how Windows services interact with the registry: that foundation is what lets a detection engineer write rules specific enough to catch real threats without generating false positives. Most detection engineers come from one of two directions: security operations (strong threat knowledge, weaker infrastructure) or infrastructure (strong systems, weaker threat modeling). That background is what made the security work possible. You can't define anomalous until you know exactly what normal looks like.
Credentials
Education
| M.S. Cybersecurity | Georgia Institute of Technology | Expected 2027 |
| B.S. Cybersecurity and Information Assurance | Western Governors University | 2024 |
Affiliations
| GIAC Advisory Board | Member |
Certifications
| GASAE | GIAC AI Security and Automation Engineer | SANS and GIAC |
| CISSP | Certified Information Systems Security Professional | (ISC)² |
| CISM | Certified Information Security Manager | ISACA |
| GCIH | GIAC Certified Incident Handler | SANS and GIAC |
| GDAT | GIAC Defending Advanced Threats | SANS and GIAC |
| CDPSE | Certified Data Privacy Solutions Engineer | ISACA |