Detection and SIEM
Wazuh, Splunk, Sigma, Falcon EDR, Wireshark.
Resume
A recruiter-ready summary of my security operations, detection engineering, and automation work. Open the PDF to review it in your browser, or download a copy for later.
One-page PDF, updated August 2026.
Credentials
Active May 2026 to May 2029.
Active October 2025 to October 2028.
With Cisco IT Essentials.
Alongside the A.S. in Cybersecurity and Information Assurance.
Project ownership
Custom Sigma-to-Wazuh compiler, 87 tests, GitHub Actions CI/CD, Wazuh API deployment, stable ID registry, and threat model.
SAML/SSO failure-diagnosis pipeline: deterministic checks, Gemini and Ollama drafting, a grounding gate that vetoes unproven root causes, and a documented self-correction of its own injection-resistance claim.
Approval-gated operations environment covering identity lifecycle, MFA enrollment, ticketing and SLAs, separation of duties, vulnerability remediation, and hash-chained audit evidence, with a policy layer implemented twice and tested for parity.
MCP traffic capture, ten Wazuh rules, stateful drift detection, a measurement framework, and documented blind spots.
Authentik SSO, self-hosted Canarytokens on ARM64, Python webhook processing, and threat-intelligence enrichment in a lab.
ADB and package-timeline analysis, APKTool, JADX, VirusTotal correlation, remediation, and a published write-up.
Technical focus
Wazuh, Splunk, Sigma, Falcon EDR, Wireshark.
Python, Bash, basic PowerShell, Rego and OPA.
Linux, Windows, TCP/IP, Cisco IOS, Docker Compose, PostgreSQL, GitHub Actions.
Authentik, Keycloak, OIDC and TOTP enrollment, MCP telemetry, OWASP MCP Top 10, AbuseIPDB.