SUMMARY
Cybersecurity professional with hands-on experience in security monitoring, endpoint protection, and policy enforcement. Administered EDR platforms and vulnerability scanning tools to detect, assess, and protect enterprise environments against emerging threats. Conducted phishing analysis and investigated security exceptions to maintain compliance and reduce risk. Eager to contribute to a results-driven team through monitoring and continuous improvement of security controls.
PROFESSIONAL EXPERIENCE
Managed Service Provider | Technology Support Specialist II | February 2025 – Present
- Monitored and investigated endpoint threats using SentinelOne, Datto AV/EDR/RMM, and Windows Defender, enforcing security policies, automating threat responses, and remediating malicious activity on employee workstations; maintained a controlled malware analysis environment mapping behavior to MITRE ATT&CK to validate and update detection and response policies.
- Conducted vulnerability assessments using Nessus across enterprise networks and applications, analyzing network traffic with Wireshark and TCPView to identify, investigate, and document suspicious activity.
- Deployed and administered Fortinet and UniFi network infrastructure, configuring firewall rules, secure network segmentation, and access controls; administered Active Directory users, groups, and Group Policy to enforce least privilege access controls and maintain compliance.
- Developed cybersecurity documentation including incident response plans, information security policies, and business continuity plans, ensuring alignment with organizational security requirements and regulatory standards.
PROJECTS
Homelab Security Infrastructure | May 2026
- Architected a pfSense-based network environment across three subnets hosting simulated employee workstations, implementing firewall policies, micro-segmentation, and Zero Trust principles. Deployed Snort for intrusion detection, prevention, and security event logging. Conducted penetration testing with Metasploit and Claude Code to assess and validate security control effectiveness.
- Designed and deployed a Wazuh SIEM server on a Raspberry Pi to support continuous security monitoring of endpoint devices, network traffic, and application activity. Configured alerting and detection rules to identify suspicious behavior and support incident investigation across a simulated enterprise environment.
TryHackMe SOC Training | January 2026
- Completed TryHackMe SOC learning path across 8 modules and 70+ hands-on labs, gaining practical experience in alert triage, SIEM investigation, threat detection, and incident escalation. Developed proficiency in Splunk, Elastic Stack, Wireshark, and MITRE ATT&CK while analyzing Windows/Linux event logs, network traffic, phishing artifacts, and malware behavior aligned with real-world SOC operations.
AI Workflows (n8n) | August 2025
- Built end-to-end automation workflows integrating email platforms, cloud storage, AI-powered content extraction (OpenAI, Gemini, Deepseek, Claude), and security tooling (VirusTotal, urlscan.io) to process attachments, generate reports, and deliver notifications. Achieved 21,000 views and 10,000 active users, streamlining document handling and reducing manual workload across organizations.
TECHNICAL SKILLS
Security Monitoring | Vulnerability Management | Policy Enforcement | Microsoft Defender | Microsoft Sentinel | Datto EDR/AV | SentinelOne | Wireshark | Nessus | Splunk | Wazuh | Fortinet | UniFi | Azure | Active Directory | Windows Server | Office 365 | Python | n8n | Claude Code | Kali Linux
EDUCATION & CERTIFICATIONS
M.S. Cybersecurity – Private University (2026) B.S. Criminal Justice – Private University (2026) B.S. Criminal Justice – Private University (2023)
Certifications: CompTIA Security+ | TryHackMe SOC | Microsoft SC-900 | Microsoft AZ-500