Work
  • Aug2023 - Present
    Honda
    Senior Incident Response Analyst
    • Lead threat intel and incident response investigations with a team of analysts and reduced critical alert response times to 24 hours.
    • Communicate complex threat insights through clear, actionable reports and presentations for leadership, stakeholders, and external partners.
    • Manage an initiative to improve GRC risk analysis by adding security incident details, resulting in higher fidelity risk scoring.
    • Directed 2 tabletop exercises to assess and refine incident response protocols, consistently raising coordination and preparedness across operational teams.
    • Ensure SEC compliance by participating in assessments, aligning with industry standards, and recommending improvements to security protocols.
  • Jan2020 - Apr2023
    Principal Financial Group
    Senior Cyber Security Engineer III
    • Performed continuous operational support of QRADAR, Splunk, Crowdstrike, and Corelight Zeek/Suricata including architecture, policies, rule recommendations, tuning, and upgrades.
    • Built 10+ high-fidelity incident detections based on threat actor analysis, attack methodologies, and intelligence sources.
    • Performed artifact analysis of suspected threat actors using Crowdstrike Falcon Sandbox, completing 4 incident response investigations.
    • Configured and maintained custom nTop NSM infrastructure on Debian Linux servers, maintaining a 99% uptime.
    • Maintained and configured network monitoring tools, intrusion detection systems, web application firewalls, and data loss prevention tools.
  • Sep2017 - Jan2020
    Pratum
    SOC Analyst II
    • Performed event correlation and analyzed network traffic anomalies on security incidents in Fortinet SIEM appliances.
    • Developed and executed 3 threat mitigation strategies, policies, and incident response procedures consistent with business strategies while effectively protecting data integrity, security, and limiting liability.
    • Actively lead and triaged 5 incident investigations involving malware analysis from Microsoft Defender XDR driven alerts.
    • Validated intrusion detection system (IDS) alerts against network traffic.
    • Deployed infrastructure using Docker, Ansible, and Terraform on Linux systems and cloud-native services.