Resume

One page, application ready.

A recruiter-ready summary of my security operations, detection engineering, and automation work. Open the PDF to review it in your browser, or download a copy for later.

One-page PDF, updated August 2026.

Credentials

Certifications and training.

2026 to 2029
CompTIA CySA+

Active May 2026 to May 2029.

2025 to 2028
CompTIA Security+

Active October 2025 to October 2028.

Cisco
CCNA: Switching, Routing, and Wireless Essentials

With Cisco IT Essentials.

Butte College
Linux Professional Certificate

Alongside the A.S. in Cybersecurity and Information Assurance.

Project ownership

What I designed and shipped.

216Wazuh rules generated from 58 Sigma sources
2,092Control Plane policy-parity test cases
4,727Benign records, zero false positives
3 / 12MCP evasion classes are structurally undetectable
6 / 9Adversarial payloads had a real path to a prompt
2025 to present
Detection-as-Code Pipeline

Custom Sigma-to-Wazuh compiler, 87 tests, GitHub Actions CI/CD, Wazuh API deployment, stable ID registry, and threat model.

2026
Assertion Desk

SAML/SSO failure-diagnosis pipeline: deterministic checks, Gemini and Ollama drafting, a grounding gate that vetoes unproven root causes, and a documented self-correction of its own injection-resistance claim.

2026
Control Plane

Approval-gated operations environment covering identity lifecycle, MFA enrollment, ticketing and SLAs, separation of duties, vulnerability remediation, and hash-chained audit evidence, with a policy layer implemented twice and tested for parity.

2026
MCP-DETECT

MCP traffic capture, ten Wazuh rules, stateful drift detection, a measurement framework, and documented blind spots.

2026
Deceptive Identity Architecture

Authentik SSO, self-hosted Canarytokens on ARM64, Python webhook processing, and threat-intelligence enrichment in a lab.

2025
Android Malware Investigation

ADB and package-timeline analysis, APKTool, JADX, VirusTotal correlation, remediation, and a published write-up.

Technical focus

Tools in active use.

Detection and SIEM

Wazuh, Splunk, Sigma, Falcon EDR, Wireshark.

Programming and automation

Python, Bash, basic PowerShell, Rego and OPA.

Systems and networking

Linux, Windows, TCP/IP, Cisco IOS, Docker Compose, PostgreSQL, GitHub Actions.

Identity and emerging surfaces

Authentik, Keycloak, OIDC and TOTP enrollment, MCP telemetry, OWASP MCP Top 10, AbuseIPDB.