About Me
I am a technically driven cybersecurity professional specializing in defensive operations, vulnerability management, and enterprise governance. I combine hands-on tactical skills with deep experience navigating federal Risk Management Frameworks (RMF).
My background includes executing IT security audits and enforcing NIST 800-53 controls for the U.S. Environmental Protection Agency (EPA), as well as managing identity and endpoint security (Intune/Azure AD) for national organizations. I hold a Master’s degree in Cybersecurity alongside CompTIA CySA+ and Security+ certifications.
View My SOC Home Lab Architecture
Core Competencies
I specialize in bridging the gap between rigorous technical defense and overarching compliance requirements.
Security Operations & Defense
Wazuh SIEM Log Analysis Vulnerability Scanning (OpenVAS) Wireshark Incident Triage
- Deploying and tuning SIEM solutions for continuous monitoring and threat detection.
- Analyzing network traffic, identifying anomalies, and writing custom detection rules.
- Executing vulnerability scans and prioritizing remediation based on risk exposure.
Governance, Risk, and Compliance (GRC)
NIST 800-53 RMF IT Auditing ISO 27001 SLA Enforcement
- Executing comprehensive IT audits and assessing contractor compliance within federal environments.
- Applying Risk Management Framework (RMF) principles to evaluate system controls.
- Designing secure Problem Management lifecycles to mitigate recurring enterprise incidents.
Identity & Endpoint Security
Azure AD Microsoft Intune IAM Access Control
- Enforcing Mobile Device Management (MDM) and Zero Trust access policies.
- Auditing principle-of-least-privilege access and managing enterprise directory services.