
Security Engineer with experience in endpoint detection and response (EDR), incident response, identity security, email security engineering, and vulnerability management. Leads investigations into phishing, business email compromise, and account compromise incidents while supporting internal, external, and web application penetration testing engagements. Designs and advises on Microsoft Entra security hardening, Conditional Access, MFA enforcement, and risk mitigation strategy. Combines offensive security expertise with defensive operations to improve enterprise security posture and reduce organizational attack surface.
Security operations: CrowdStrike, Microsoft Entra, Incident response and identity management
Offensive security: Burp Suite, Cobalt Strike,
Active Directory exploitation
Vulnerability management: Nessus risk prioritization and remediation
Programming and scripting: Python
Domains: Web application security and network security
Domains: Web Application Security, Network
Security
Bug Bounty & Security Research (Ongoing)
• Active security researcher on HackerOne, identifying web application vulnerabilities through manual testing and targeted exploitation techniques.
• Perform application-layer assessments using Burp Suite, custom payload development, and fuzzing methodologies to uncover logic and access control flaws.