THREAT DETECTION · INCIDENT RESPONSE · SECURITY AUTOMATION
Security Engineer | Threat Hunting & Incident Response
I investigate complex security incidents and build automation, detection, and enrichment systems that help security teams respond faster and with better context.
Microsoft Defender · Sentinel · KQL · PowerShell · APIs · Security Automation · AI
FEATURED PROJECT / 01
Automated Security Incident Enrichment Platform
An end-to-end security automation platform that retrieves incident evidence from Microsoft Defender through Microsoft Graph, normalizes evidence into structured objects, enriches indicators through approved sources, and uses AI to generate concise analyst-ready incident context.
MICROSOFT DEFENDER → GRAPH API → EVIDENCE INGESTION → NORMALIZATION → ENRICHMENT ROUTING → VT / CMDB / AUTHORIZED BUSINESS DATA → NORMALIZED ENRICHMENT → AI SUMMARY → ANALYST WORKFLOW
PowerShell · Microsoft Graph API · REST APIs · JSON · VirusTotal · ServiceNow · AI · Security Automation · Incident Response
View Case Study
View Sanitized Code
EXPERIENCE
Response work informed by engineering thinking.
A concise, impact-focused record of incident response, threat hunting, security operations, engineering, automation, detection work, vulnerability management, and leadership experience. Role and organization details remain intentionally editable.
TECHNICAL WORK
Detection, investigation, and automation work.
KQL Detection & Hunting
Sanitized query walkthroughs: hunt objective, data source, detection behavior, investigation notes, false-positive considerations, and detection-engineering improvements.
PowerShell Security Automation
Smaller utilities for indicator enrichment, API integration, incident parsing, normalization, and reporting — designed to make response work repeatable and reliable.
Detection Engineering
Detection logic, tuning methodology, investigation workflows, and ATT&CK mapping where appropriate — with confidential infrastructure and queries intentionally excluded.
ABOUT
Built from investigation, pointed toward systems.
My work began in vulnerability management, expanded through incident response and threat hunting, and is increasingly focused on security engineering, automation, detection, and systems that improve how security operations teams work. I’m curious about the technical details, practical about the outcome, and deliberate about where automation supports — rather than replaces — human judgment.
CURRENT FOCUS
PowerShell · Python · KQL · Windows internals · Security engineering · Detection engineering · AI-assisted security operations
RESUME
A concise record of security engineering work.
Professional summary, experience, technical skills, certifications, selected projects, and education can be maintained here as editable resume sections. Download details are intentionally left ready for the final PDF.
CONTACT
Open to security engineering conversations.
Interested in security engineering, detection and response, threat hunting, and security automation opportunities.
LinkedIn — add link
GitHub — add link
Email — add address
New York City