Start with the evidence
Build the timeline first. Identity, endpoint, email, network, and cloud activity often tell different parts of the same story.
Corporate Security · Security Engineering
Senior Security Engineer with 7+ years of experience building, operating, and improving security across identity, endpoints, SaaS, cloud environments, and third-party services.
My work sits between security operations and engineering. I investigate incidents, evaluate risk, improve controls, and build practical ways to make security easier to operate at scale.
Senior Security Engineer at Lime, previously Cyber Security Analyst at Parallel.
Progression
Work across corporate security with a focus on security operations, incident response, identity and access, endpoint and SaaS security, vulnerability management, third-party risk, and security automation.
My role includes investigating security issues, improving controls and processes, driving remediation with technical teams, and helping address security risk across the corporate environment.
Worked across day-to-day security operations, investigations, identity and access, endpoint and email security, vulnerability management, SaaS security reviews, third-party risk, and security awareness.
Supported the implementation and improvement of security controls while working with IT, Engineering, and business teams through investigation and remediation.
Worked across identity, endpoint, email, cloud, network, vulnerability management, and third-party security in a cloud-based environment.
Implemented and operated security controls, investigated security events, supported Zero Trust initiatives, developed security processes and policies, and worked with technical and business teams to address identified risk.
Led technical support in an MSP environment across identity, Microsoft 365, endpoints, networking, servers, and security.
Supported corporate IT, vulnerability remediation, change management, infrastructure security, ITGC and SOX activities, penetration testing, and PCI compliance.
Core Areas
I investigate security events by building a timeline across identity, email, endpoint, network, SaaS, and cloud telemetry to determine what happened, what was affected, and what response is required.
My work has included account compromise, suspicious authentication, phishing, malicious activity, unexpected access changes, and externally reported security issues. I review identity and audit activity to understand user and administrative actions and determine whether activity is expected or suspicious.
I use RunReveal as the current SIEM for monitoring, investigation, evidence collection, and event analysis. I previously performed SIEM monitoring and investigation in Rapid7 InsightIDR before the transition to RunReveal. Across both platforms, I have onboarded and validated log sources, developed investigation queries, and reviewed incoming telemetry to ensure useful context is available for investigations and detection analysis.
The work continues from initial triage through containment, remediation, and documentation, including identifying whether a control, detection, data source, or process should change afterward.
I work across identity and access from both an operational and security perspective.
That includes investigating authentication and account lifecycle events, reviewing privileged and application access, evaluating MFA and SSO controls, validating group and permission changes, and identifying access that no longer matches a user's role or business need.
My experience includes Okta, Google Workspace, Microsoft 365, AWS, and SaaS environments.
I have also worked on Zero Trust initiatives that bring identity, device posture, and endpoint security together so access decisions are based on more than a username and password.
My endpoint security work has evolved from hardening systems, encryption, patch management, and endpoint protection into designing controls that use device posture and security telemetry as part of broader access decisions.
I have worked with CrowdStrike, Workspace ONE, Microsoft Intune, Cisco Secure Endpoint, and other endpoint technologies across macOS and Windows environments.
I also review SaaS applications, integrations, and service accounts to understand how they authenticate, what they can access, and whether permissions and lifecycle controls match the business need.
At Lime, I designed automated enforcement using CrowdStrike Fusion SOAR and Real Time Response to identify and remediate unauthorized VPN software across more than 1,000 endpoints.
The rollout used staged enforcement and validation rather than immediately applying a blocking control across the entire environment.
I investigate threats that begin both inside and outside the corporate environment, including phishing, business email compromise, account takeover, brand impersonation, malicious and lookalike domains, and exposed information.
I use CrowdStrike Falcon Recon for external threat and brand monitoring and have coordinated investigation, blocking, escalation, and domain takedown activity.
I also supported the implementation and integration of Abnormal Security with Google Workspace to strengthen phishing, business email compromise, and account takeover detection and investigation.
My vulnerability management work includes reviewing penetration testing results, dependency findings, application issues, and security researcher submissions through Bugcrowd. I validate whether reported behavior is actionable and separate meaningful findings from duplicate, informational, invalid, or otherwise non-actionable submissions.
When reviewing application and externally reported findings, I use established application security concepts, including the OWASP Top 10, alongside exploitability, exposure, and potential business impact to assess severity and priority.
I identify the appropriate technical owners, coordinate remediation, track findings through resolution, and validate closure where appropriate. The goal is to understand actual risk and determine whether the response requires a fix, control change, compensating control, or long-term process improvement.
Not every security problem begins with an alert.
I review SaaS applications, integrations, service accounts, third parties, and architecture changes to understand what they can access, how they authenticate, what data they handle, and what a compromise would mean to the environment.
I have built third-party security review processes, designed a risk based vendor assessment program, supported PCI DSS and SOC 2 work, and helped translate security requirements into controls that can be operated and verified.
My approach is to understand the actual risk first, then determine the control or remediation that makes sense for the environment.
I build security workflows that route detections from RunReveal and other security tools into dedicated Slack channels using integrations and webhooks. Alerts include relevant context so responders can quickly understand what triggered the detection and begin triage.
I also use SIEM integrations and CrowdStrike Fusion SOAR to automate appropriate repetitive tasks and response actions, reducing manual monitoring while keeping investigation and security decisions with the engineer.
I am exploring practical uses of AI and Model Context Protocol to reduce repetitive work, make security information easier to retrieve and act on, and leave more time for investigation and security decisions.
I have built MCP tooling to support third-party risk workflows involving assessments, vendor information, risk evaluation, and findings. I am also exploring CrowdStrike Falcon MCP capabilities for common security operations and investigation workflows.
The goal is to bring useful information and routine actions closer to the task at hand, reducing unnecessary movement between platforms. These tools support the work; they do not replace security judgment or independently make security decisions.
Examples
An unexpected identity event rarely exists in one log source.
I use Okta System Logs and Google Workspace audit and investigation data to reconstruct authentication activity, administrative actions, lifecycle changes, and group membership events.
When needed, I correlate those records with endpoint, network, or SIEM telemetry to determine whether the activity was expected, automated, or potentially malicious.
The result is a defensible timeline that can be used to determine containment and whether access can safely be restored.
I designed a CrowdStrike based workflow to identify unauthorized VPN software across more than 1,000 endpoints and automate remediation using Fusion SOAR and Real Time Response.
Rather than immediately enforcing the control everywhere, the rollout was staged so detections and potential false positives could be validated before broader enforcement.
The goal was not automation for its own sake. It was to make a recurring security control consistent and scalable without creating unnecessary disruption.
I investigate malicious and lookalike domains, brand impersonation, credential phishing infrastructure, and exposed information using CrowdStrike Falcon Recon and supporting evidence.
When activity represents a risk, I coordinate the appropriate response, which may include internal blocking, additional investigation, takedown activity, or escalation to Legal.
I also use email and identity security telemetry to determine whether an external campaign has resulted in activity inside the environment.
Principles
Build the timeline first. Identity, endpoint, email, network, and cloud activity often tell different parts of the same story.
A security control has to work operationally. Understand the risk, the users, the systems involved, and where a compensating control may make more sense than forcing a standard solution.
Containment solves the immediate problem. The long-term work is understanding why the issue occurred and improving detection, ownership, automation, or process so the organization is better prepared the next time.