About
Professional Summary
Security operations-focused analyst with hands-on lab and project experience in incident response, network threat detection, Windows/Linux infrastructure, and telemetry integration. In controlled labs and course simulations, I correlate endpoint, network, memory, and Windows event evidence to reconstruct attack chains, determine incident scope, and document containment-focused recommendations. Supporting work demonstrates Python automation, cross-platform troubleshooting, and clear technical documentation.
Certifications
- GIAC Certified Incident Handler (GCIH) — 92%
- GIAC Security Essentials (GSEC) — 98%
- GIAC Foundational Cybersecurity Technologies (GFACT)
Applied Cybersecurity Certificate (ACS) — Expected November 2026
SANS Technology Institute
SOC Level 1 Path — Expected September 2026
TryHackMe
Google Cybersecurity Professional Certificate — 2024
Google / Coursera
Bachelor of Management (Honours), Minor in Psychology — 2023
University of British Columbia (UBC)
National Cyber League — Spring 2025
Ranked 521st individually (Top 6%) and 63rd as a team (Top 1.3%).
Technical Skills
- Security Operations & Incident Response: Alert triage, incident investigation, scope expansion, IOC enrichment, playbooks/runbooks, containment recommendations, incident reporting, MITRE ATT&CK, PICERL
- SIEM, Endpoint & Identity: Wazuh SIEM/XDR, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration; Microsoft Learn SC-200 labs covering Microsoft Sentinel/KQL and Defender XDR/Defender for Endpoint; Splunk/SPL in guided labs
- Network Detection & DFIR: Wireshark, Zeek, RITA, PCAP analysis, TCP/IP, DNS, HTTP/S, C2 beacon analysis, Volatility 3, Procmon, Regshot, malware triage
- Systems & Infrastructure: Windows 11, Windows Server 2022, Ubuntu/Linux, Active Directory/DNS, VMware, network segmentation, static addressing, LVM, Netplan
- Cloud & Platforms: AWS security labs covering S3, IAM, IMDS/SSRF, AWS CLI, and ScoutSuite configuration assessment; GCP and Azure fundamentals
- Scripting & Automation: Python, PowerShell, SQL, Git/GitHub, triage automation, log parsing, evidence extraction
- AI-Assisted Development: Codex, Claude Code
Featured Projects
HTTP Cookie Data Exfiltration Investigation
Analyzed a TryHackMe packet capture containing covert HTTP-cookie exfiltration, preserved and reduced the evidence set, extracted encoded values in packet order, and reversed the XOR/Base64 transformation to reconstruct the stolen data.
Enterprise Incident Response & Threat Hunting Simulation
Investigated simulated ransomware and destructive malware during SANS SEC504 using PowerShell live triage, PCAP and proxy analysis, Volatility 3, Procmon, Regshot, Hayabusa/Sigma, Zeek, and RITA. Reconstructed the execution chain, identified persistence and 60-second C2 beaconing, and expanded incident scope from one endpoint to four.
SOC Architecture & Telemetry Integration
Configured an isolated dual-homed VMware lab with Windows Server 2022 Active Directory/DNS, Windows 11, Ubuntu Server, Kali Linux, Wazuh, Zeek, and Sysmon. Validated endpoint and network telemetry ingestion while troubleshooting storage, dependency, networking, and parsing issues.
SOC Investigation: TA505 MirrorBlast Campaign
Triaged a high-priority IDS alert in a TryHackMe lab, analyzed the supplied packet capture, identified staging infrastructure and host artifacts, mapped the observed behavior to MITRE ATT&CK, and documented containment and detection recommendations.
Additional Work
Browse my Security Operations posts and all categories for full technical write-ups, investigation notes, playbooks, implementation decisions, validation evidence, and repeatable project documentation.