Full SIEM stack across 17+ endpoints: Security Onion, Wazuh, Suricata. Custom Python agents for log ingestion and anomaly correlation. Detections mapped to MITRE ATT&CK.
SIEM·detection engineering·incident response·AI security testing
Full SIEM stack across 17+ endpoints: Security Onion, Wazuh, Suricata. Custom Python agents for log ingestion and anomaly correlation. Detections mapped to MITRE ATT&CK.
Adversarial test suite for a client LLM deployment. 92 cases across 10 OWASP-style categories: prompt injection, jailbreak, data exfiltration, output manipulation, context hijacking.
Python threat hunting automation with IOC collection and cross-reference against MISP and ThreatConnect feeds. Built during BMO tenure for C-level targeted phishing investigation.
Splunk SOAR and Tines workflows for automated phishing triage, IOC enrichment, and user containment. Cut analyst manual-triage load across multi-client SOC engagements.
Security consulting, penetration testing, detection engineering, and AI security assessments. Typically available for project-based and retainer engagements.