
Security Analyst with experience in endpoint detection, incident response, identity security, and vulnerability management. Leads investigations into email and account compromise incidents, supports web and network penetration testing engagements, and advises clients on Microsoft Entra hardening and risk mitigation. Integrates offensive expertise with defensive operations to strengthen enterprise security posture.
Investigate and triage endpoint and identity-based security alerts in CrowdStrike and Microsoft Entra, performing analysis and supporting containment and remediation efforts.
• Handle a consistent volume of incident response cases, including phishing
investigations and business email compromise scenarios, conducting mailbox scoping,log analysis, and coordinating credential resets and hardening actions.
• Analyze suspicious emails using Proofpoint and Microsoft 365 tooling, identifying
malicious indicators and advising on remediation and prevention strategies.
• Scope and support web application and network penetration tests, assisting in
vulnerability validation and client-facing reporting.
• Advise clients on Microsoft Entra hardening, including Conditional Access
configuration, MFA enforcement, and identity protection best practices.
• Complete cybersecurity insurance documentation and risk assessment questionnaires, aligning client environments with security and compliance requirements.
• Investigated and responded to security alerts across endpoint and network environments, performing threat analysis, coordinating remediation efforts, and supporting compliance requirements.
• Conducted vulnerability and risk assessments to identify critical exposures, prioritizing remediation and implementing both manual and automated mitigation strategies across client systems.
Bug Bounty & Security Research (Ongoing)
• Active security researcher on HackerOne, identifying web application vulnerabilities through manual testing and targeted exploitation techniques.
• Perform application-layer assessments using Burp Suite, custom payload development, and fuzzing methodologies to uncover logic and access control flaws.