Start with the evidence
Build the timeline first. Identity, endpoint, email, network, and cloud activity often tell different parts of the same story.
Corporate Security · Security Engineering
Senior Security Engineer working across Corporate Security and Enterprise Security to protect workforce identities, endpoints, SaaS applications, email, company data, and the systems employees rely on.
I combine hands-on security operations and incident response with improving the controls, integrations, and workflows that make enterprise security more effective and scalable.
Senior Security Engineer at Lime, previously Cyber Security Analyst at Parallel.
Progression
I work across Corporate Security, investigating security issues and improving controls across workforce identity, endpoints, SaaS applications, email, company data, and third-party services.
My role includes leading investigations, driving remediation with technical owners, and improving the controls, integrations, and processes used to manage security risk across the corporate environment.
My time at Lime has also included operating through IPO readiness and the company's transition to operating as a public company, where security controls, evidence, access governance, risk decisions, and repeatable processes came under increased scrutiny. This required close coordination across Security, IT, Engineering, Legal, Privacy, Finance, Compliance, Procurement, HR, and business teams.
Worked across day-to-day security operations, investigations, identity and access security, endpoint and email security, vulnerability management, SaaS security, third-party risk, security awareness, and control improvement.
Investigated and remediated security issues while working with Security, IT, Engineering, and business teams to improve controls and make security processes more consistent and repeatable.
Investigated security alerts and incidents across endpoints, email, user accounts, and network activity.
Administered and monitored tools supporting endpoint protection, email security, vulnerability management, and network security. Performed vulnerability scanning and tracked findings through remediation.
Managed security awareness activities, including phishing simulations and employee training, and supported security assessments and compliance efforts.
Led Tier 1 and Tier 2 support in an MSP environment across endpoints, servers, networks, Active Directory, Microsoft 365, and customer infrastructure, including managing technical escalations.
Configured and secured Microsoft 365 environments using MFA, directory synchronization, email encryption, SPF, DKIM, and DMARC.
Performed network discovery and security assessments and helped customers remediate identified gaps.
Served as the primary technical liaison for the Popeyes corporate environment, coordinating between corporate users, IT teams, vendors, and service providers.
Coordinated patching and change activities and worked with technical teams and vendors to address identified vulnerabilities. Supported infrastructure teams during the migration of critical systems between data centers.
Supported Internal Audit by providing technical evidence, validating IT controls, and coordinating remediation of identified gaps.
Credentials
Core Areas
I investigate account compromise, suspicious authentication, phishing and business email compromise, unauthorized access, endpoint activity, and SaaS security events.
I correlate evidence across identity, email, endpoint, SaaS, network, cloud, and SIEM sources to reconstruct the timeline, determine scope and impact, contain the issue, and drive remediation.
RunReveal is the current SIEM in my environment. I previously performed SIEM monitoring and investigation in Rapid7 InsightIDR before the transition to RunReveal. My work across both platforms has included source onboarding and validation, investigation queries, telemetry review, and ensuring useful context is available for investigations and detection analysis.
The work continues beyond containment by identifying whether a control, detection, data source, or process should change afterward.
I work on the security side of identity and access controls in partnership with the teams that own and administer the underlying platforms.
My work includes investigating authentication and account activity, evaluating SSO and MFA controls, reviewing privileged access and service accounts, validating group and permission changes, supporting access reviews and identity lifecycle controls, and identifying access that no longer matches a user's role or business need.
I apply least-privilege principles across workforce identity and SaaS environments while accounting for operational requirements and platform ownership.
My endpoint security work includes device protection, hardening, encryption, patching, security telemetry, and controls that incorporate device posture into broader access decisions.
At Lime, I designed automated enforcement using CrowdStrike Fusion SOAR and Real Time Response to identify and remediate unauthorized VPN software across more than 1,000 endpoints.
The rollout used staged enforcement and validation so detections and potential operational effects could be evaluated before broader enforcement.
I also evaluate SaaS applications, integrations, permissions, service accounts, authentication, access, and lifecycle controls to understand what they can reach and whether that access matches the business need.
I investigate phishing, business email compromise, account takeover, employee and vendor impersonation, lookalike domains, brand threats, and related activity using email, identity, SaaS, and external-threat telemetry.
My experience includes Abnormal Security and Google Workspace for email investigation, CrowdStrike Falcon Recon for external threat and brand monitoring, and Netskope in the context of SaaS access and data exposure.
I review sharing, permissions, service accounts, data handling, and security configuration to understand how company data may be exposed or misused.
When an external campaign presents a risk, I coordinate the appropriate response, including internal blocking, expanded investigation, domain takedown activity, or escalation to Legal.
I work with SIEM configuration and operations, security telemetry and source onboarding, investigation queries, detection workflows, alert tuning, routing, and security-tool integrations.
My SIEM experience includes RunReveal and Rapid7 InsightIDR, working with detection content and supporting telemetry to improve alert quality and investigation context.
I build lightweight workflows that route alerts and relevant context into appropriate response channels and use integrations, webhooks, and CrowdStrike Fusion SOAR to automate suitable repetitive actions.
I also use AI-assisted and MCP-based workflows where appropriate to reduce repetitive investigation work and make security context easier to retrieve across approved tools, while maintaining access controls, auditability, and human judgment around security decisions.
My work includes validating findings, assessing exposure and business impact, identifying the appropriate technical owners, tracking remediation, and confirming closure. This includes findings from penetration testing, security tooling, assessments, and external researchers through platforms such as Bugcrowd.
I designed a risk-based third-party security program covering assessment routing, critical security requirements, exceptions, continuous monitoring, renewals, and findings management.
I manage and drive the security awareness program, including annual training and phishing simulations.
I improve security programs by clarifying requirements, ownership, evidence, exceptions, and remediation workflows so controls can be operated and verified consistently.
I contribute to PCI DSS, SOC 2, and Zero Trust efforts through security-control validation and remediation while partnering with the teams responsible for the broader programs.
Examples
An unexpected identity event rarely exists in one log source.
I use Okta System Logs and Google Workspace audit and investigation data to reconstruct authentication activity, administrative actions, lifecycle changes, and group membership events.
When needed, I correlate those records with endpoint, network, or SIEM telemetry to determine whether the activity was expected, automated, or potentially malicious.
The result is a defensible timeline that can be used to determine containment and whether access can safely be restored.
I designed a CrowdStrike-based workflow to identify unauthorized VPN software across more than 1,000 endpoints and automate remediation using Fusion SOAR and Real Time Response.
Rather than immediately enforcing the control everywhere, the rollout was staged so detections and potential false positives could be validated before broader enforcement.
The goal was not automation for its own sake. It was to make a recurring security control consistent and scalable without creating unnecessary disruption.
I investigate malicious and lookalike domains, brand impersonation, credential phishing infrastructure, and exposed information using CrowdStrike Falcon Recon and supporting evidence.
When activity represents a risk, I coordinate the appropriate response, which may include internal blocking, additional investigation, takedown activity, or escalation to Legal.
I also use email and identity security telemetry to determine whether an external campaign has resulted in activity inside the environment.
A detection is less useful when the responder has to reconstruct its meaning before beginning the investigation.
I have worked with RunReveal, security-tool integrations, and webhooks to route detections into dedicated response channels with relevant event and investigation context.
The work includes validating telemetry sources, reviewing alert quality, tuning routing, and determining which repetitive actions can be automated without transferring security judgment to the workflow.
The result is a more consistent path from detection to triage while keeping investigation and response decisions with the engineer.
Principles
Build the timeline first. Identity, endpoint, email, network, and cloud activity often tell different parts of the same story.
A security control has to work operationally. Understand the risk, the users, the systems involved, and where a compensating control may make more sense than forcing a standard solution.
Containment solves the immediate problem. The long-term work is understanding why the issue occurred and improving detection, ownership, automation, or process so the organization is better prepared the next time.