Overview

Signal over noise. Ownership over tickets.

Eight years in cybersecurity taught me that the work that matters is rarely the flashiest dashboard — it's the exception that kills a false-positive flood, the report that turns hours into seconds, and the handoff package that keeps a program alive when one person leaves. I work across detection engineering, vulnerability management, incident response, IAM, and GRC — because municipal and MSSP environments don't get to pick one lane.

Featured work

Outcomes that change how a team operates

From hours to under 30 seconds

Built a Python vulnerability-reporting framework that ingested exports across 40+ network segments, mapped findings to MITRE ATT&CK, and produced dual-format output for operators and leadership.

154 tickets, one exception

Authored a Rapid7 detection exception that ended a fleet-wide false-positive class — stopping an alert flood without giving up coverage for a small security team.

+6.7% posture in six months

Owned a 25+ domain cybersecurity risk program for a city of 100,000 residents, closing critical work across access controls, endpoints, IR, and network segmentation.

Now

What I'm focused on

  • Leading incident response and vulnerability management for municipal MSSP clients at Resultant
  • Deepening AI-security fluency — CISSP (exam scheduled August 2026), then Databricks and Google Cloud AI tracks
  • Shipping practical writing and open tools from the Lab — Wazuh detections, forensics pipelines, AI ops notes
  • Running AI coding agents and MCP-integrated automation in sandboxed, credential-scoped workflows