Security analysis grounded in evidence.
Hands-on lab and project experience across security operations, network analysis, incident investigation, Windows/Linux infrastructure, and telemetry integration.

Professional summary
Security operations-focused analyst with hands-on lab and project experience in incident investigation, network analysis, Windows/Linux infrastructure, and telemetry integration. In controlled labs and course simulations, I correlate endpoint, network, memory, and Windows event evidence to reconstruct attack chains, determine scope, and document containment-focused recommendations. Supporting work demonstrates Python automation, cross-platform troubleshooting, and clear technical documentation.
Technical skills
Security Operations & Incident Investigation
Alert triage, incident investigation, scope expansion, IOC enrichment, playbooks/runbooks, containment recommendations, incident reporting, MITRE ATT&CK, PICERL in labs and course simulations.
SIEM, Endpoint & Identity
Wazuh SIEM/XDR, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration; Microsoft Learn SC-200 labs covering Microsoft Sentinel/KQL and Defender XDR/Defender for Endpoint; Splunk/SPL in guided labs.
Network Analysis & Digital Forensics Labs
Wireshark, Zeek, RITA, PCAP analysis, TCP/IP, DNS, HTTP/S, C2 beacon analysis, Volatility 3, Procmon, Regshot, malware triage.
Systems & Infrastructure
Windows 11, Windows Server 2022, Ubuntu/Linux, Active Directory/DNS, VMware, network segmentation, static addressing, LVM, Netplan.
Cloud & Platforms
AWS security labs covering S3, IAM, IMDS/SSRF, AWS CLI, and ScoutSuite configuration assessment; GCP and Azure fundamentals.
Scripting & Automation
Python, PowerShell, SQL, Git/GitHub, triage automation, log parsing, evidence extraction.
AI-Assisted Development
ChatGPT/Codex, Claude Code, Google Antigravity.