Senior Manager, Security Operations
- Sole security engineer and architect responsible for all aspects of information security.
- Built the SOC from scratch utilizing AI SOC and AI-native technology.
- 99.2% detection fidelity, MTTD down 65%, false positives down 95%.
- Phishing-resistant MFA at 100% across 1,000+ users.
- MDR migration savings of $32,000 redeployed into net-new vulnerability management program.
When I joined National Audubon Society in 2024, there was no SOC, no formal detection program, and security tooling spread across disconnected point solutions. The first architectural decision was SOC model: traditional MDR vs. AI-native. MDR requires analyst headcount to triage — a model that fails on cost before it fails on coverage for a single-person security team. I selected an AI-native platform that could deliver consistent detection fidelity without the analyst-to-alert ratio that makes MDR viable only at scale. The result: 99.2% detection fidelity and a 95% reduction in false positives.
Detection coverage was built MITRE ATT&CK-first — starting with the highest-probability attack paths for a hybrid cloud environment: identity-based attacks, credential stuffing, OAuth abuse, and business email compromise. Okta is the enterprise IdP and I led rolling out phishing-resistant MFA across 1,000+ users removing the credential-theft risk that email compromise campaigns rely on. SAML and OAuth integrations provided detection visibility into identity-based lateral movement that endpoint telemetry alone misses.
The $32,000 MDR contract savings were reinvested into Tenable One, building net-new vulnerability management across endpoint, cloud, web application, and attack surface management domains. A program that can only detect is incomplete; understanding the full attack surface is what lets you prioritize detection coverage correctly.