At the US Navy’s Cyber National Mission Force, I lead threat hunts and incident response against nation-state adversaries across full-packet capture, endpoint, and SIEM telemetry.
I’ve deployed as the sole analyst on four networks, reconstructed intrusions through host, memory, disk, and traffic forensics, and turned findings into Sigma rules, detection content, enrichment workflows, and analyst playbooks. I built an OpenCTI-to-Splunk threat intelligence integration processing roughly 10 GB per day and used daily by the team for IOC enrichment and pivoting.
I also build Python, REST API, SOAR, and CI/CD automation connecting Splunk, Elastic, Velociraptor, OpenCTI, Carbon Black, and VirusTotal to improve alert fidelity and reduce investigation friction.
Beyond operations, I’ve led digital forensic investigators, mentored engineering teams, built a DFIR training range used by 100+ DoD personnel, and maintain a personal purple-team lab to test adversary techniques and validate detections. I’m GIAC GCFA certified, earned first place in the 2024 DoD-wide CTF, and was named Navy Sailor of the Year in FY2024 and FY2025.
