Application owner for both EDR and email security solution.
Lead all daily operations, configuration, tuning and troubleshooting efforts for both EDR and email security solution.
Heavily supported blue-team efforts during multi-month red team operation: helped perform IR investigations, fully scoping incident impact, created documentation on findings, and created detections to detect future red team efforts.
Helped design new threat detection road map for security organization.
Provide tier 2/3 incident response as part of an on-call rotation.
Helped scope deployment of EDR solution to ephemeral cloud resources.
Senior Cyber Security Threat Detection Engineer
Rivian
10.2021 - 01.2023
Helped lead companies threat detection program with deploying and creating ~50+ internal use-cases in Splunk and creating data pipelines to bring in multiple 3rd party tools alerting.
Technical expert on threat detection, acting as liaison between Rivian and third party vendors.
Owner of SOAR program with 100+ automation workflows.
Owner of two other tools that help with malware analysis and data enrichment.
Helped maintain Splunk, and data pipeline.
Created automations within SOAR to automate security tasks.
Research and create threat detections for company environment. Including creating threat detections on new and emerging threats.
Provided tier 2/3 incident response.
Created technical documentation for tool design, SOPs, and articles on how to use certain security technologies.
Reversed malware, and created documentation and threat detections based on TTPs.
Analyst, Security Operations Center
Ciena
08.2020 - 10.2021
Provided tier 2 and 3 Incident Response (IR).
Created multiple API scripts to automate security tasks.
Built numerous dashboards within Splunk for various security monitoring tasks, and to report on company metrics.
Tuned and created various security use cases within Splunk to detect malicious/unwanted activity within companies environment
Reviewed and written runbooks and security documentation to help improve and streamline security investigations
Conducted threat hunts within company environment
Integrated third party threat intelligence into the SIEMs current threat intel framework
Project: Helped design a Botnet for a masters course
Project: Created a data-mining model to help predict optimal time to remove a starting pitcher from a game. (Accepted to ICMLA 2019, and published by IEEE)
Project: Analyzed a Ransomware sample, and made scripts for IDA Pro to help analysis
CTF: Won FSU Cyber Forensics CTF (Capture the Flag) Competition Spring 2019.