At Edgewater Federal Solutions, I build and maintain enterprise detections across Splunk, Microsoft Defender, Carbon Black, Trellix, and Cofense for a federal environment of approximately 30,000 users.
I've developed SPL, KQL, and YARA detection logic, risk-based correlation rules, and detection standards across endpoint, identity, email, cloud, and network telemetry. I use incident findings, threat intelligence, and MITRE ATT&CK to close coverage gaps, improve alert quality, and strengthen analyst workflows.
Previously, I led high-severity incident response as an Incident Commander in a 24×7×365 SOC handling approximately 500 incidents monthly. I modernized suspicious-email operations from 0% to approximately 90% automation, rewrote incident-response playbooks, and mentored approximately 15 analysts.
