Skills
Competencies across agentic AI security, AI-driven detection, detection-as-code, cloud security, and governance, each reflecting hands-on production work, not certifications alone.
AI security and automation
Agentic AI security, LLM guardrails, Claude Code, AI agent governance, human-in-the-loop AI validation, AI-assisted code review, AI cost governance, AI-powered threat detection, AI security governance, AI-powered email security.
AI agents are now part of both the attack surface and the defense, and the work covers both. That means finding guardrails that fail silently, such as safety rules truncated past a character limit, and putting agent instructions under audit. It means validating AI-generated investigation narratives with a human in the loop, building an AI pull request reviewer and then governing its cost, and writing the governance roadmap for secure GenAI adoption. On the defense side, AI-driven detection at National Audubon Society reached 99.2% detection fidelity and cut false positives 95%, and AI-powered email security cut business email compromise incidents 99%.
Security frameworks and governance
NIST CSF 2.0, NIST SP 800-53, NIST SP 800-207 Zero Trust, ISO 27001, NERC-CIP, MITRE ATT&CK, PCI DSS 4.0, risk management, GRC, third-party risk.
NIST CSF 2.0 and MITRE ATT&CK serve different functions in a mature program: CSF provides the governance structure and maturity model; ATT&CK provides the threat model for detection coverage prioritization. At Sunbelt Rentals, NIST CSF alignment gave the security program a compliance posture for external stakeholders while keeping operations threat-focused. At National Audubon Society, MITRE ATT&CK was used to systematically map existing detection coverage against enterprise TTPs and identify gaps — not as a reporting checkbox, but as the actual method for deciding what to build next. NERC-CIP exposure from OT environments and PCI DSS 4.0 from financial services clients completes the regulatory surface.
Technical domains
SOC development, detection engineering, Sigma and YARA detection rules, threat hunting, AI security governance, cloud security architecture, identity and access management, Zero Trust implementation, incident response, threat intelligence, SIEM and SOAR optimization, vulnerability management.
Detection engineering is the primary technical discipline — building, testing, and deploying detection logic against specific threat actor TTPs rather than relying on vendor-default rules. At CrowdStrike's TIDE team, this meant Detection-as-Code: detection logic in version-controlled files, peer-reviewed, deployed through CI/CD pipelines. Falcon LogScale processed high-volume endpoint telemetry at lower latency than the Splunk deployment it partially replaced. Tines and ServiceNow Flow Designer automated CSIRT workflows, reducing analyst response time 80%. Sysmon telemetry across 10,000+ endpoints at Sunbelt Rentals provided the process-level visibility — command-line execution, network connections, registry modifications — that Windows Event Logs alone don't deliver. Tenable One unified vulnerability management across endpoint, cloud, web application, and ASM domains at Audubon.
Platforms and cloud
CrowdStrike Falcon, SentinelOne, Uptycs, Falcon LogScale, Splunk, Elastic Security, Tines, ServiceNow Flow Designer, Okta, Tenable One, AWS, Azure, GCP.
Detection-as-Code brings version control, peer review, and CI gates to detection logic that used to live in a UI and drift without accountability. Falcon LogScale handled high-volume endpoint telemetry at lower latency than the Splunk deployment it partly replaced, and Tines with ServiceNow Flow Designer automated CSIRT workflows. Multi-cloud monitoring across AWS, Azure, and GCP depends on each provider's distinct attack surface: Azure service principal abuse, AWS IAM privilege escalation, and GCP service account key exposure.