Profile
About
Signal over noise. Ownership over tickets.
I’m Scott — a security engineer who cares less about shiny dashboards and more about whether a team can find the real signal, close the right risk, and sleep after an incident.
By day I’m a Senior Security Engineer at Resultant, delivering managed cybersecurity for municipal government clients across Indiana. That means alert triage, account-takeover investigations, vulnerability ownership, and deciding whether a risky login is a real compromise or a salesperson on hotel Wi-Fi. Before that I ran the cybersecurity risk program for the City of Carmel — 25+ policy domains for a city of 100,000 residents, including water treatment, wastewater, police, fire, and emergency operations.
I got here the long way: a county sheriff’s office, cable installation, a hospital service desk, a NOC watching 25,000 route miles of fiber, network engineering, threat intelligence, DevOps in a HIPAA shop, a SOC, and municipal security. Fourteen years in IT, eight of them in security. The useful part of that route is that every layer I’m now responsible for defending, I’ve operated. When I ask an infrastructure team to change something, I know what I’m asking of them.
What I believe Link to heading
Noise is a security failure. An alert that fires 154 times without meaning trains people to ignore the next one that matters. Tuning, exceptions, and clear ownership are security work — not housekeeping.
Automation should shrink time-to-decision. The Python reporting framework I built didn’t exist to impress a demo; it cut monthly vulnerability analysis from hours to under 30 seconds so humans could act.
Programs outlast people. When I left Carmel, the runbook and handoff package covering 40+ segments mattered as much as the posture score. Security that depends on one brain isn’t security.
Write down the trade-offs. On Scott’s Lab I document specific problems in specific environments — what I chose, what it cost, and what I’d do differently. No listicles.
Outside the ticket queue Link to heading
The Lab is where that work gets published: home-lab SIEM with custom detections, forensics pipelines, Ansible/Ludus automation, open tools, and notes on AI in security ops. I also keep public security utilities on GitHub and experiment with AI coding agents and MCP-integrated automation in sandboxed, credential-scoped setups.
I’m working toward the ISC2 CISSP (exam booked for August 2026) and finishing a B.S. in Cybersecurity and Information Assurance at Western Governors University.