THREAT DETECTION · INCIDENT RESPONSE · SECURITY AUTOMATION

Security Engineer | Threat Hunting & Incident Response

I investigate complex security incidents and build automation, detection, and enrichment systems that help security teams respond faster and with better context.

Microsoft Defender · Sentinel · KQL · PowerShell · APIs · Security Automation · AI

FEATURED PROJECT / 01

Automated Security Incident Enrichment Platform

An end-to-end security automation platform that retrieves incident evidence from Microsoft Defender through Microsoft Graph, normalizes evidence into structured objects, enriches indicators through approved sources, and uses AI to generate concise analyst-ready incident context.

MICROSOFT DEFENDER → GRAPH API → EVIDENCE INGESTION → NORMALIZATION → ENRICHMENT ROUTING → VT / CMDB / AUTHORIZED BUSINESS DATA → NORMALIZED ENRICHMENT → AI SUMMARY → ANALYST WORKFLOW

PowerShell · Microsoft Graph API · REST APIs · JSON · VirusTotal · ServiceNow · AI · Security Automation · Incident Response

View Case Study

View Sanitized Code

EXPERIENCE

Response work informed by engineering thinking.

A concise, impact-focused record of incident response, threat hunting, security operations, engineering, automation, detection work, vulnerability management, and leadership experience. Role and organization details remain intentionally editable.

CURRENT

CURRENT

Senior security engineering scope — editable role and organization details. Highlight incident response, detection strategy, automation, systems used, and measurable outcomes here.

Senior security engineering scope — editable role and organization details. Highlight incident response, detection strategy, automation, systems used, and measurable outcomes here.

EARLIER

EARLIER

Vulnerability management, security operations, and threat-hunting scope — editable role and organization details. Capture the systems, technical responsibilities, leadership, and engineering work that shaped the current focus.

Vulnerability management, security operations, and threat-hunting scope — editable role and organization details. Capture the systems, technical responsibilities, leadership, and engineering work that shaped the current focus.

TECHNICAL WORK

Detection, investigation, and automation work.

KQL Detection & Hunting

Sanitized query walkthroughs: hunt objective, data source, detection behavior, investigation notes, false-positive considerations, and detection-engineering improvements.

PowerShell Security Automation

Smaller utilities for indicator enrichment, API integration, incident parsing, normalization, and reporting — designed to make response work repeatable and reliable.

Detection Engineering

Detection logic, tuning methodology, investigation workflows, and ATT&CK mapping where appropriate — with confidential infrastructure and queries intentionally excluded.

ABOUT

Built from investigation, pointed toward systems.

My work began in vulnerability management, expanded through incident response and threat hunting, and is increasingly focused on security engineering, automation, detection, and systems that improve how security operations teams work. I’m curious about the technical details, practical about the outcome, and deliberate about where automation supports — rather than replaces — human judgment.

CURRENT FOCUS

PowerShell · Python · KQL · Windows internals · Security engineering · Detection engineering · AI-assisted security operations

RESUME

A concise record of security engineering work.

Professional summary, experience, technical skills, certifications, selected projects, and education can be maintained here as editable resume sections. Download details are intentionally left ready for the final PDF.

CONTACT

Open to security engineering conversations.

Interested in security engineering, detection and response, threat hunting, and security automation opportunities.

LinkedIn — add link

GitHub — add link

Email — add address

New York City

That Tech Guy BK — security engineering portfolio

New York City