At Optiv Security, I automated security-alert enrichment workflows in Tines using API integrations, data transformation, and conditional logic, saving approximately 20 minutes of manual effort per enriched alert. I also wrote Python scripts to parse and normalize endpoint telemetry ahead of SOAR ingestion.
Using Microsoft Defender for Endpoint, I investigated activity across 33 endpoints and triaged 21 security alerts. I analyzed process execution and endpoint telemetry, documented findings, and supported escalation and incident-response workflows.
At Elevate Labs, I analyzed approximately 500 MB+ of PCAP data daily with Wireshark and Tshark, and used Nmap and Burp Suite for network reconnaissance and web application security analysis. I also configured Linux UFW firewall rules; this work contributed to an estimated 20% reduction in potential attack surface within the assessed environment.
In my projects, I deployed Wazuh across three endpoints, correlated endpoint and network telemetry, and used VirusTotal threat intelligence to enrich investigations. I’ve also presented to fellow analysts on AI red-teaming and AI-assisted threat hunting with PyRIT, Garak, Promptfoo, and MITRE ATLAS.

