About

About

Professional Summary

Security operations-focused analyst with hands-on lab and project experience in incident response, network threat detection, Windows/Linux infrastructure, and telemetry integration. In controlled labs and course simulations, I correlate endpoint, network, memory, and Windows event evidence to reconstruct attack chains, determine incident scope, and document containment-focused recommendations. Supporting work demonstrates Python automation, cross-platform troubleshooting, and clear technical documentation.

Certifications

  • GIAC Certified Incident Handler (GCIH) — 92%
  • GIAC Security Essentials (GSEC) — 98%
  • GIAC Foundational Cybersecurity Technologies (GFACT)

Applied Cybersecurity Certificate (ACS) — Expected November 2026

SANS Technology Institute

SOC Level 1 Path — Expected September 2026

TryHackMe

Google Cybersecurity Professional Certificate — 2024

Google / Coursera

Bachelor of Management (Honours), Minor in Psychology — 2023

University of British Columbia (UBC)

National Cyber League — Spring 2025

Ranked 521st individually (Top 6%) and 63rd as a team (Top 1.3%).

Technical Skills

  • Security Operations & Incident Response: Alert triage, incident investigation, scope expansion, IOC enrichment, playbooks/runbooks, containment recommendations, incident reporting, MITRE ATT&CK, PICERL
  • SIEM, Endpoint & Identity: Wazuh SIEM/XDR, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration; Microsoft Learn SC-200 labs covering Microsoft Sentinel/KQL and Defender XDR/Defender for Endpoint; Splunk/SPL in guided labs
  • Network Detection & DFIR: Wireshark, Zeek, RITA, PCAP analysis, TCP/IP, DNS, HTTP/S, C2 beacon analysis, Volatility 3, Procmon, Regshot, malware triage
  • Systems & Infrastructure: Windows 11, Windows Server 2022, Ubuntu/Linux, Active Directory/DNS, VMware, network segmentation, static addressing, LVM, Netplan
  • Cloud & Platforms: AWS security labs covering S3, IAM, IMDS/SSRF, AWS CLI, and ScoutSuite configuration assessment; GCP and Azure fundamentals
  • Scripting & Automation: Python, PowerShell, SQL, Git/GitHub, triage automation, log parsing, evidence extraction
  • AI-Assisted Development: Codex, Claude Code

Analyzed a TryHackMe packet capture containing covert HTTP-cookie exfiltration, preserved and reduced the evidence set, extracted encoded values in packet order, and reversed the XOR/Base64 transformation to reconstruct the stolen data.

Enterprise Incident Response & Threat Hunting Simulation

Investigated simulated ransomware and destructive malware during SANS SEC504 using PowerShell live triage, PCAP and proxy analysis, Volatility 3, Procmon, Regshot, Hayabusa/Sigma, Zeek, and RITA. Reconstructed the execution chain, identified persistence and 60-second C2 beaconing, and expanded incident scope from one endpoint to four.

SOC Architecture & Telemetry Integration

Configured an isolated dual-homed VMware lab with Windows Server 2022 Active Directory/DNS, Windows 11, Ubuntu Server, Kali Linux, Wazuh, Zeek, and Sysmon. Validated endpoint and network telemetry ingestion while troubleshooting storage, dependency, networking, and parsing issues.

SOC Investigation: TA505 MirrorBlast Campaign

Triaged a high-priority IDS alert in a TryHackMe lab, analyzed the supplied packet capture, identified staging infrastructure and host artifacts, mapped the observed behavior to MITRE ATT&CK, and documented containment and detection recommendations.

Additional Work

Browse my Security Operations posts and all categories for full technical write-ups, investigation notes, playbooks, implementation decisions, validation evidence, and repeatable project documentation.