
Security Engineer with 5+ years of enterprise cybersecurity experience across Amazon Robotics, Fisker Automotive, and Boot Barn. Currently lead cloud and enterprise security for a $5B nationwide retail organization, owning Microsoft Sentinel SIEM, CrowdStrike Falcon, AWS GuardDuty, and Fortinet security platforms.
Specialize in detection engineering, threat hunting, and security automation across Azure and AWS environments. Built KQL-based detections, automated incident response workflows using Azure Logic Apps, and cloud threat pipelines integrating AWS GuardDuty into Microsoft Sentinel.
Expert in zero-trust security, identity protection, endpoint detection and response, and cloud security architecture. Known for designing scalable security systems that reduce risk, improve visibility, and enable rapid response to real-world cyber threats.
Lead security engineer responsible for enterprise-wide cybersecurity across a $5B nationwide retail organization. Designed, deployed, and operated Microsoft Sentinel SIEM to centralize security monitoring across Azure, AWS, endpoints, and network infrastructure.
Built advanced KQL detection rules and analytic workflows to identify credential abuse, malicious API activity, firewall attacks, and endpoint threats. Integrated CrowdStrike Falcon (EDR, Identity Protection, USB Control) into Sentinel to enable real-time detection and response.
Architected and deployed AWS GuardDuty export pipelines using encrypted S3, SNS, and Azure ingestion to provide full cloud threat visibility inside Microsoft Sentinel. Enabled GuardDuty Runtime Monitoring, DNS logs, VPC Flow Logs, and Kubernetes audit logs.
Developed automated incident response and reporting using Azure Logic Apps, including Teams alerts, threat-intelligence enrichment, and leadership-level security reports.
Designed zero-trust security controls using Microsoft Entra Conditional Access and CrowdStrike Identity Protection to enforce MFA and device-based access.
Integrated Fortinet FortiGate firewall logs to detect intrusion attempts, botnet activity, IPS events, and malicious traffic across stores, warehouses, and corporate networks.
Own security architecture, detection engineering, cloud threat visibility, and security automation for the organization.
Monitored enterprise systems for security threats, intrusions, and suspicious activity across endpoints, servers, and network infrastructure. Investigated security incidents to determine root cause, impact, and remediation actions.
Performed vulnerability assessments and assisted with remediation efforts to reduce security risk across corporate systems. Maintained security and disaster recovery documentation to support compliance and incident response readiness.
Implemented and maintained security tools used for threat detection, prevention, and analysis. Deployed and managed firewalls and data encryption to protect sensitive systems and company data.
Provided cybersecurity operations and risk management support for Amazon Robotics manufacturing and enterprise environments. Analyzed system and network risk, and implemented security countermeasures to protect critical infrastructure.
Managed user authentication and access control, maintained firewalls and encryption, and ensured systems were patched and hardened against vulnerabilities. Investigated security incidents and data breaches to determine impact and remediation steps.
Conducted vulnerability assessments, penetration testing, and digital forensics to identify security weaknesses. Collaborated with cross-functional teams to implement security policies, disaster recovery plans, and security awareness programs.
Microsoft Sentinel (SIEM)
KQL (Kusto Query Language)
CrowdStrike Falcon EDR
CrowdStrike Identity Protection (IDP)
Endpoint Detection and Response (EDR)
Incident Response & Threat Hunting
AWS GuardDuty
AWS CloudTrail
VPC Flow Logs
Azure Security
Microsoft Entra ID (Azure AD)
Conditional Access & MFA
Zero Trust Architecture
Fortinet FortiGate Firewalls
Network Security Monitoring
SIEM Automation (Azure Logic Apps)
Threat Intelligence Enrichment
USB Device Control
Cloud Security Architecture
Vulnerability Management
Penetration Testing
Digital Forensics
Identity & Access Management (IAM)
Security Operations (SOC)
Risk Management
NIST & CIS Frameworks
Designed and deployed Microsoft Sentinel SIEM for a $5B nationwide retail organization, integrating CrowdStrike, AWS GuardDuty, and Fortinet firewalls.
Built automated incident response and reporting workflows using Azure Logic Apps, reducing manual investigation time.
Architected AWS GuardDuty cloud threat pipeline with encrypted S3 and Sentinel integration for real-time cloud security visibility.
Implemented zero-trust identity security using CrowdStrike Identity Protection and Microsoft Entra Conditional Access.
Led enterprise-wide CrowdStrike EDR and Identity Protection deployment across corporate, store, and warehouse systems.
CompTIA Security+
CompTIA CySA+
CompTIA Security Analytics Professional (CSAP)
CompTIA PenTest+
IBM Cybersecurity Certificate
Google IT Automation with Python
Certified Ethical Hacker (CEH) – In Progress