Sr. Security Operations Analyst (SOC Analyst), Security Engineer (Vulnerability Management), Purple Team at Onestream Software (2025-03 – Present)
Led end-to-end security operations including incident response, threat hunting, and vulnerability management.
- Led end-to-end incident response across phishing, malware, insider threat, and cloud-based intrusions, reducing MTTR by 40%.
- Developed and tuned Microsoft Sentinel SIEM detections (alerts) mapped to MITRE ATT&CK, increasing true-positive rates.
- Built custom KQL queries to detect lateral movement, privilege escalation, and persistence activity.
- Created custom SIEM alerting rules and Azure Workbooks.
- Monitored and responded to security incidents using SIEM tools, Microsoft Defender, and Azure Sentinel within SLA.
- Investigated security alerts related to user risk, compromised credentials, and anomalous sign-in activities.
- Conducted log analysis and forensic investigations to determine the root cause of incidents.
- Developed Purple Team department and conducted regular tabletop exercises.
- Conducted proactive threat hunts using EDR and telemetry data (Defender XDR, Microsoft Sentinel, Rapid 7, Sentinel One, Okta), identifying unknown threats and gaps in detection coverage.
- Created hypothesis-driven hunts aligned to MITRE ATT&CK TTPs and documented results for knowledge base.
- Mentored Tier 1–2 analysts on triage and analysis best practices.
- Presented executive summaries of security incidents to management and stakeholders.
- Collaborated with GRC and Risk teams to align detection coverage with NIST 800-61 and ISO 27035 frameworks.
- Defined SOC KPIs including MTTR, false positive rate, and alert handling efficiency.
- Created custom reporting dashboards for CISO and senior leadership in Ironscales, ServiceNow, and SentinelOne.
Security Analyst | Azure Cloud Administrator at Bluelight IT (2022-02 – 2025-03)
Provided security operations and incident response support for phishing, malware, and cloud security.
- Analyzed, remediated and quarantined emails in Microsoft Defender and Avanan, identifying phishing, malware, and business email compromise (BEC) threats.
- Implemented custom anti-phishing rules and policies, reducing false positives and improving detection accuracy.
- Conducted header and message trace analysis to identify malicious senders and suspicious email patterns.
- Provided end-user phishing awareness training, reducing phishing click rates by 70%.
- Monitored and responded to security incidents using SIEM tools, Microsoft Defender, and Azure Sentinel.
- Investigated security alerts related to user risk, compromised credentials, and anomalous sign-in activities.
- Conducted log analysis and forensic investigations to determine the root cause of incidents.
- Managed Conditional Access Policies, Multi-Factor Authentication (MFA), and User Risk Policies to enforce secure authentication.
- Investigated privileged access misuse and potential insider threats.
Cyber Security Support Analyst (Vulnerability Management & SecOps) at Log(N) Pacific (2025-02 – 2025-03)
Internship focused on vulnerability management and security operations with threat hunting and compliance activities.
- Conducted vulnerability scans, provided detailed reports, and implemented PowerShell-based automated remediations, contributing to a 100% reduction in critical, 90% in high, and 76% in medium vulnerabilities.
- Performed vulnerability assessments and risk prioritization using Tenable across Windows and Linux environments.
- Executed secure configurations and compliance audits (DISA STIG) with Tenable to meet industry standards.
- Deep understanding of the "soft" side of Vulnerability Management: rapport, trust, transparency, and business need.
- Performed threat hunting with EDR, detecting IoCs from brute force attacks, data exfiltration, and ransomware.
- Designed, tested, and published advanced threat hunting scenarios for incident response tabletop exercises.
- Developed custom detection rules in Microsoft Defender for Endpoint and Azure Sentinel to automate isolation and investigation of compromised systems and created dashboards to monitor malicious traffic.
- Reduced brute force incidents by 100% by implementing inbound NSG/firewall rules to limit Internet exposure.
- Experienced with KQL (similar to SQL/SPL) which I used to query logs within the SIEM and EDR platform.
Founder | Full Stack Software Engineer (Independent Contractor) at K-ING Tech Solutions, LLC (2021-03 – Present)
Freelance/contract work performed part-time, outside core full-time employment hours. Full stack development, AI/ML application development, and DevOps/security services for small-business clients.
- Designed and delivered 15+ full stack web applications and automation solutions for 8+ small-business clients, owning front-end, back-end, database, API, deployment, and ongoing support end-to-end.
- Built responsive interfaces using React, TypeScript, JavaScript, Next.js, Tailwind CSS, and Bootstrap, improving average page load performance by ~30% and mobile performance scores by 20%+ across optimized client applications.
- Developed 20+ Node.js/Express.js REST API endpoints and backend services, implementing OAuth 2.0/JWT authentication and role-based access control (RBAC) to secure application and administrative functionality.
- Designed and maintained 10+ production databases using PostgreSQL, MySQL, MongoDB, and Redis; optimized schema design, indexing, and queries, reducing response times by up to 35% on high-use application queries.
- Developed AI-powered application features and workflow automations using Python, LLMs, prompt engineering, embeddings, and retrieval-augmented generation (RAG), reducing manual processing time by approximately 40% for targeted client workflows.
- Built and evaluated machine learning models using Python, Pandas, NumPy, and scikit-learn for classification, prediction, and process-automation use cases, including data preprocessing, feature engineering, and model performance tuning.
- Integrated generative AI and LLM APIs into web applications to support document analysis, data extraction, summarization, intelligent search, and conversational interfaces across 5+ client and internal projects.
- Deployed and maintained applications on Azure/AWS using Docker containers and serverless functions, reducing client hosting and infrastructure costs by approximately 20-25% while standardizing deployment environments.
- Built CI/CD pipelines with GitHub Actions and automated test suites (Jest, Cypress, Playwright), reducing manual deployment/QA effort by approximately 40% and catching defects before production release.
- Conducted secure code reviews and application security assessments across 10+ client projects, identifying and remediating 25+ security issues spanning OWASP Top 10 and CWE categories (authentication, authorization, input validation, dependency vulnerabilities).
- Managed 8+ client relationships end-to-end, requirements gathering, technical architecture, estimation, development, testing, deployment, documentation, and post-launch support, consistently delivering within agreed scope and timelines.