ABOUT ME
Experienced U.S. Veteran and security engineer with nearly 10 years of experience spanning detection engineering, threat hunting, incident response, and APT analysis.
Designs and tunes high-fidelity detections and SPL/EQL queries across endpoint, cloud, network, identity, and DLP telemetry, and builds the security data pipelines that feed and enrich SIEMs. Conducted threat hunts across NATO systems at scale and mitigated dozens of intrusions on allied networks.
Holds a TS/SCI with CI Poly, builds out large networks and cyber ranges as code with Terraform, and brings strong Python, PowerShell, forensics, and cloud-security skills to every engagement.
Certifications
  • CISSP
  • GCFA
  • GCED
  • GCIH
  • Security+
Education
  • A.A.S. Intelligence Studies - CCAF
Detection Engineering
SPL/EQL
Sigma/YARA
MITRE ATT&CK
SIEM Engineering
Endpoint/Cloud/Network
Identity & DLP
SIEM Ingest/Enrich
ETL Pipelines
Varonis MDDR
SOAR (DFIR-IRIS)
Incident Response
Adversary Emulation
CI/CD
DevSecOps
Python/PowerShell/C++
Terraform/Ansible
SQL/VQL
Bash
Git
AWS/Azure/GCP
Splunk/Elastic
CrowdStrike/SentinelOne
Velociraptor/Arkime
Ghidra/IDA/Volatility
Checkout my projects

experience

09/2024 - Current

Lead Engineer | Team Lead - ********

Leading the engineering and delivery of enterprise-scale cyber ranges and the telemetry pipelines that feed them, translating adversary tradecraft into realistic, MITRE ATT&CK-mapped training environments for hundreds of trainees.

Projects:

  • Built large SIEM and NSM telemetry environments (100-200+ endpoints) with realistic user activity, engineering the logging and data pipelines that prepared endpoint, network, and host telemetry for threat hunting, DFIR, and analytics.
  • Designed and delivered repeatable adversary-emulation attack chains mapped to MITRE ATT&CK across enterprise cyber ranges for hundreds of trainees, producing realistic attack telemetry for detection development.
  • Automated range deployment and adversary emulation with Terraform and Ansible, and built a custom Caster/VM tooling app that cut repeatable configuration and deployment time by over 25%.
  • Performs red team threat emulation engagements to certify USCYBERCOM threat hunters and digital forensics analysts.

12/2023 - 09/2024

Forensics Escalation Engineer - Varonis Systems

Forensics and incident commander for escalated enterprise cases, building the artifact-collection and SIEM-ingest pipelines that turned raw forensic data into actionable detection and response capability.

Projects:

  • Served as lead architect and incident commander for a Managed Data Detection and Response (MDDR) service valued at over $100M, a data-centric DLP and detection-and-response capability.
  • Built a security data pipeline that converted raw forensic artifacts into normalized, enriched telemetry for online/offline SIEM ingestion, helping open over $50M in new business.
  • Built an extensible artifact-collection app (including third-party binaries) for diverse endpoint operating systems, running point as incident commander on escalated enterprise cases.

06/2020 - 11/2023

Senior Cyber Threat Hunter - USCYBERCOM/USAF

Led international threat-hunting operations across NATO and allied networks, designing and tuning high-fidelity detections against live telemetry while reverse-engineering APT malware into shareable detection content.

Projects:

  • Led a team of 10+ analysts hunting across allied and NATO networks, mitigating 33 intrusions while analyzing 193M logs from 1,000+ endpoints and 720+ hours of network traffic.
  • Reverse-engineered APT malware and wrote detection content for it in YARA, CrowdStrike, and Elastic/Endgame, sharing the resulting signatures and IOCs with the broader defensive community.
  • Built a SOAR-style automation in DFIR-IRIS that generated hunt tickets from hunt-plan logic and MITRE ATT&CK techniques, saving hundreds of hours across investigations and contributing fixes upstream to the open-source project.
  • Uncovered 9 adversary implants (7 previously undiscovered) in 3 days - about 5 months faster than the national average - exposing an APT campaign targeting foreign dignitaries across 44 international sites.

09/2016 - 05/2020

Senior Data Link & Threat Intelligence Analyst

Provided threat intelligence and data link analysis in support of national-level security operations, while self-teaching Python to build automation tooling and developing training curricula for the next generation of intelligence officers.

Projects:

  • Self-taught Python and built a documented, extensible automation tool used by 45 personnel that cut report analysis time by about 90% (from 4+ minutes to under 50 seconds).
  • Delivered threat intelligence on advanced adversary activity to national-level stakeholders and earned recognition from the Director of the NSA (DIRNSA).
  • Wrote a threat-intelligence training curriculum used to develop 100+ new intelligence officers.
Xynaptik
© 2024 Xynaptik. All rights reserved.