Professional Summary
Experienced Cybersecurity Leader and Senior Security Engineer with a proven track record of developing and implementing robust security solutions to protect organizations from cyber threats. Skilled in leading cross-functional teams, conducting risk assessments, and designing secure network infrastructures. Strong expertise in implementing and managing security tools, incident response, and compliance frameworks. Outstanding communication skills and a strategic mindset to effectively mitigate vulnerabilities and safeguard critical data assets. Ready to leverage extensive experience to enhance cybersecurity posture and drive organizational success.
Penetration tested their entire ego-system which took roughly a month and half. I used the latest OSINT, OWASP, and Offensive Security based tooling to find and catalogue all digital assets we should be concerned with and made a report using latest practices.
As DevOps, created terraform modules to expand their current CI/CD pipelines and telemetry to use Lacework, an enterprise security tool.
Expanded our repos to include security.md's and created pipelines to write findings with PR's
Expanded both pre-commit, and post-commit tests to include dataloss checks.
Added Google SSO, and authenticator best practices to the entire org, reducing the many SSO's into one and enforcing MFA for our most privileged human accounts.
Managed and troubleshot active services with K9s, terminal, and linux knowledge
Leveraged NIST CSF, Site Reliability Engineering, and K8's to augment the security practices in AWS and make them as reliable as the services themselves, with 99.9% uptime. These were mostly OSINT tools that were catered to the company and repeatable tasks they normally hire for.
Security+ CompTIA http://verify.comptia.org/ April 2024
CISSP ISC2 https://my.isc2.org/s/MemberVerification April 2024