Professional Summary
Results-oriented cybersecurity professional with a Master’s degree in Cybersecurity, CompTIA Security+ and CySA+ certifications, and federal government experience in IT audits, risk management, and controls assessment. Proven ability to identify security weaknesses, implement process improvements, and support compliance initiatives. Actively building hands-on defensive security capabilities through enterprise-grade home lab projects focused on SIEM, Active Directory threat hunting, and incident response.
Professional Experience
IT Security & Compliance Analyst
- Executed comprehensive IT security audits and assessed contractor compliance against federal Service Level Agreements (SLAs) and strict data protection requirements.
- Leveraged the Risk Management Framework (RMF) to evaluate and implement NIST 800-53 security controls across federal information systems and network endpoints.
- Conducted risk assessments for new software and AI-powered assistive technologies to ensure secure integration within the federal environment.
- Engineered a secure Problem Management lifecycle that mitigated recurring vulnerabilities, reduced exposure windows, and streamlined incident triage.
- Drafted and disseminated critical security advisories and system update documentation to a distributed workforce of over 17,000 federal employees and contractors.
Identity & Access Administrator
- Administered Identity and Access Management (IAM) protocols across on-premises Active Directory and Microsoft Azure cloud environments.
- Enforced Mobile Device Management (MDM) and endpoint security policies using Microsoft Intune to secure corporate data and remote assets.
- Audited hardware inventory and enforced principle-of-least-privilege access controls to prevent unauthorized data exposure and streamline offboarding procedures.
Cybersecurity Research Fellow
- Researched and reported on cybersecurity postures, data privacy vulnerabilities, and IT staffing challenges across national K-12 school districts.
- Conducted threat intelligence interviews with CTOs and security directors; presented executive threat landscape briefings to trustees and leadership.
- Authored technical documentation and security advisories regarding data governance, access controls, and mitigating emerging ransomware threats.
Graduate Research Assistant
- Supported faculty research in the Department of Cybersecurity with a focus on network security, data privacy, and cyber threat analysis.
- Assisted in designing and conducting experiments on intrusion detection systems (IDS) and secure network protocols.
- Reviewed academic literature to identify trends in cybersecurity governance and risk management frameworks.
- Contributed to a departmental study on cloud security architectures and Identity and Access Management (IAM) in hybrid environments.
- Prepared research summaries, technical reports, and presentations, while providing instructional support to undergraduate networking and cybersecurity students.
Independent Research & Publications
Insider Threats & Social Engineering Research
- Authored an extensive analysis examining how foundational technical illiteracy expands an organization's attack surface, leading to increased Business Email Compromise (BEC) and phishing success rates.
- Researched vulnerabilities in modern Security Awareness Training programs and proposed actionable policy updates for data privacy governance and insider threat mitigation.
Education & Certifications
- CompTIA CySA+ (CS0-003) – November 2025
- CompTIA Security+ (SY0-701) – November 2024
- M.S. in Cybersecurity – Old Dominion University, June 2022
Core Competencies & Skills
Security Operations & Defense
- SIEM Operations (Wazuh, Splunk)
- Threat Hunting & Log Aggregation
- Vulnerability Scanning (OpenVAS, Nessus)
- Network Traffic Analysis (Wireshark)
- Incident Triage & MITRE ATT&CK Mapping
- Intrusion Detection Systems (IDS)
Governance, Risk, & Compliance
- NIST 800-53 & ISO 27001
- Risk Management Framework (RMF)
- IT Auditing & Vendor Management
- Data Privacy Governance
- Security Awareness Training
Identity & Endpoint Architecture
- Microsoft Azure AD (Entra ID)
- Microsoft Intune (MDM)
- Active Directory & Group Policy (GPO)
- Identity & Access Management (IAM)
- Principle of Least Privilege
Languages
- English (Native)
- Spanish (Professional C1)
- Arabic (Elementary A1)