Virtual CISO / Sr. Security Engineer - Uncomplicate IT - Boston, MA
(2021-03 - 2026-07)
Built and deployed full-stack security controls (EDR/MDR, SIEM, IAM, SASE) across client environments, improving detection coverage and reducing incident volume.
- Engineered Azure/Entra and AWS security baselines; implemented Conditional Access, MFA, and Zero Trust controls to harden identity and reduce attack surface.
- Automated onboarding, remediation, and deployment workflows using PowerShell, Python, and n8n, reducing manual workload and response time by 40%.
- Led IR for 50+ ransomware outbreaks, account compromise, insider threats, and malware cases; reduced containment time by 40% through automation.
- Built custom detections and performed threat hunting, improving alert fidelity and reducing false positives by 30%.
Sr. Security Engineer - Focus Technology Solutions - Boston, MA
(2018-08 - 2021-03)
- Co-developed the company's cybersecurity practice; served as technical lead for security engineering and IR.
- Delivered vCISO services, security assessments, and policy/control implementation.
- Led SOC operations for internal and client environments.
IT Help Desk Supervisor & Sr. Helpdesk Engineer - Focus Technology Solutions - Boston, MA
(2015-06 - 2018-04)
- Managed and mentored Help Desk team; improved response times through workflow automation and metrics.
Applied Security Engineering Projects - Focus Technology Solutions - Boston, MA
(2015-06 - 2021-03)
- Adcole Aerospace (2018–2019): Guided DoD/NIST compliance using Exostar; maintained POA&M; led cybersecurity risk meetings.
- Braintree Electric Light Dept. (2019–2021): Ran bi‑weekly cybersecurity risk meetings; maintained POA&M; supported long‑term risk reduction, ransomware incident response.
- Granite Telecommunications (2020–2021): Delivered vulnerability management for 400+ endpoints and government systems; managed Tenable scans, patching, remediation, and custom deployment scripts; led Linux system management.
- Implemented a local LLM‑driven IR assistant that summarizes event logs, correlates suspicious activity, and recommends triage actions while maintaining full offline privacy.
- Developed a Retrieval Augmented Generation (RAG) platform enabling secure document search and question answering across internal knowledge bases.
- Automated SOC workflows using LLMs to classify alerts, enrich telemetry, and generate analyst‑ready summaries, reducing manual triage time.
- Developed AI‑assisted security tooling that automates vulnerability enumeration and Sysmon logs to produce prioritized attack‑surface summaries and exploit‑path hypotheses.
- Built a RAG‑based security analysis system using ChromaDB to index scan results and provide natural‑language risk assessments for faster triage.
- Designed preprocessing pipelines for large text datasets to support LoRA fine‑tuning for security‑specific model behavior.