Security & Detection Engineering · Technical Operations Leadership
I build and defend the systems attackers go after — from Active Directory and identity to cloud infrastructure, detection pipelines, and the operations that keep them running. CompTIA SecurityX-certified, with a decade spanning hands-on engineering, incident response, and leading teams under pressure.
01 — Profile
My work sits at the intersection of security engineering and operational leadership. I've spent years administering the enterprise stack that most attacks route through — Active Directory, Microsoft Entra ID, Microsoft 365, Windows endpoints, VPN and authentication, identity lifecycle, and least-privilege access — and building detection and response capability on top of it with Wazuh, Sysmon, PowerShell, and the MITRE ATT&CK framework.
Alongside the engineering, I lead. I currently direct cybersecurity operations and incident response across technical, operational, and customer-facing teams, coordinating vendors and partners and owning a multi-million-dollar technology budget. That combination — I can build the detection, run the incident, and brief the executive on the risk — is what I bring to a security or platform team.
I also serve on the incident response team of the Ohio Cyber Security Reserve, supporting public-sector organizations through cyber incidents, and I hold a B.S. in Information Technology earned while working full time.
02 — Experience
From leading an airborne infantry squad to running enterprise security operations — leadership and technical depth reinforced at every step.
Technical Operations Manager
WiseSight AI
Lead cybersecurity operations and incident response across technical, operational, and customer-facing teams. Directly manage a team of 8 and coordinate 18 vendors and external partners — municipalities, on-site installation technicians, and shipping partners. Own a $2M annual technology operations budget across hardware, vendor contracts, SaaS and software licensing, and infosec, driving budgeting, forecasting, vendor negotiation, and cost optimization.
IT Operations Specialist
Datafield → Bath & Body Works HQ
Delivered identity and access management across Active Directory, Azure AD / Entra ID, and Microsoft 365 for a large retail enterprise — provisioning, lifecycle management, access controls, and endpoint support with rigorous documentation.
Information Security Lead
TIBA Parking Solutions
Led a team of 8, providing technical leadership, mentoring, and cross-team guidance. Owned incident management and drove process improvement across the security function.
Airborne Infantry Squad Leader
United States Army
Led a 6-member heavy weapons squad. Responsible for training, readiness, and decision-making in high-stakes environments — the foundation of how I lead technical teams today.
Incident Response Team
Ohio Cyber Security Reserve (OhCSR)
Volunteer responder supporting Ohio public-sector organizations through cybersecurity incidents.
03 — Flagship work
The centerpiece of my portfolio: a full-scale Active Directory attack-and-defense lab paired with a structured detection-engineering practice — not a tutorial, but an engineered body of work with evidence, metrics, and governance.
I built an integrated collection of security labs, ATT&CK case studies, governance artifacts, operational plans, risk-management materials, and executive reporting. A standardized playbook framework generates each case study with a consistent structure — objectives, lab environment, attack simulation, Wazuh and Sysmon telemetry, hunting queries, SOC notes, metrics, evidence, lessons learned, and engineering improvements — so the work reads like a real detection program, not a scrapbook.
Spanning Wazuh, Sysmon, and PowerShell tooling, with published detection rules, hunting and incident-response templates, a delivery roadmap, and a capstone — plus tailored resume packages for Security Engineer, System Administrator, Windows Administrator, and Platform Engineer tracks.
Every one of the 25 case studies is generated against the same ten-part structure, so the output is comparable, auditable, and reviewable the way a real detection program is.
Objectives
What the study sets out to detect, and the threat behaviour it maps to in ATT&CK.
Lab environment
The Active Directory domain, endpoints, and tooling the scenario runs against.
Attack simulation
The technique executed end to end, with the commands and conditions recorded.
Telemetry
The Wazuh and Sysmon events the activity actually produced.
Hunting queries
Queries written against that telemetry to surface the behaviour at scale.
Detection rules
Wazuh rules published with MITRE mappings.
SOC notes
Analyst-facing context: what fires, what it means, what to do next.
Metrics
Coverage and outcome measures for the study.
Evidence
Captured artifacts backing every claim in the write-up.
Lessons & improvements
What the run exposed, and the engineering changes it drove.
04 — Capabilities
Skills demonstrated across employment and hands-on portfolio work.
05 — Credentials
06 — Contact
Open to Security Engineer, System Administrator, and Platform Engineer roles. The fastest way to see the depth of the work is the portfolio site and repository.