Indianapolis, IN · Eastern Time

Summary Link to heading

Security engineer with eight years in cybersecurity, currently the incident response lead and vulnerability management owner for municipal government clients as an MSSP subject matter expert. Builds the tooling a security program actually runs on: a Python vulnerability-reporting framework that cut monthly analysis from hours to under 30 seconds, a Rapid7 detection exception that ended a 154-ticket false-positive flood without losing coverage, and a public GitHub of self-built security tooling. Owned a 25+ domain cybersecurity risk program end to end for a city of 100,000 residents, raising its posture score 6.7% in six months. Works across detection engineering, vulnerability management, incident response, IAM, and GRC — with current hands-on experience running AI-agent and MCP-based automation platforms and a certification track (CISSP, Databricks, Google Cloud) aimed at AI security.

Core Competencies Link to heading

Detection Engineering & SIEM — Rapid7 InsightIDR · Microsoft Sentinel · Microsoft Defender XDR · Wazuh · MITRE ATT&CK mapping · alert tuning · detection rule authoring

Vulnerability Management — Rapid7 InsightVM · Tenable Nessus · ConnectSecure · prioritization and remediation at 11,000+ finding scale

Security Automation — Python reporting frameworks · scripted ingestion across 40+ segments · dual-format reporting · infrastructure automation

AI Agent & LLM Tooling — AI coding agents · MCP-integrated automation · sandboxed execution · credential-scoped workflows

Incident Response — IR lead for confirmed intrusions, ATO, BEC, and vendor email compromise · forensic triage · executive and insurer coordination

Identity & Access — Microsoft Entra ID · Conditional Access · Active Directory · Duo MFA · Varonis · RBAC / least privilege

Compliance & Risk (GRC) — NIST CSF 2.0 · CIS Controls · HIPAA · PCI DSS · ISO 27001 · CJIS · Cynomi risk register · policy authoring

Experience Link to heading

Resultant (MSSP) · Mar 2026 – Present · Remote Link to heading

Senior Security Engineer

Subject matter expert delivering managed cybersecurity services to municipal government clients across Indiana, including a city and county serving 300,000+ residents. Owns security assessments, incident response, vulnerability management, and detection engineering across multi-agency environments spanning public safety, public utilities, and critical infrastructure.

  • Authored a Rapid7 detection exception that eliminated a fleet-wide false-positive class generating 154 tickets in a single burst — ending a recurring alert flood without reducing coverage.
  • Serve as incident response lead for a confirmed cryptominer intrusion (XMRig via IIS deserialization) at a major Indiana municipality, running forensic triage, containment scoping, and executive briefing for the CIO and cyber insurance stakeholders.
  • Lead 20–30 documented investigations per month across identity, endpoint, email, and network telemetry, including account takeover, BEC, and a third-party vendor email compromise identified through header analysis where the sender passed SPF, DKIM, and DMARC.
  • Conduct baseline security assessments across municipal clients using ConnectSecure and Rapid7; manage identity security (Entra ID, Conditional Access, Duo, Varonis), endpoint protection (CrowdStrike Falcon, JAMF), and awareness (KnowBe4).
  • Deliver threat intelligence aligned to NIST CSF 2.0 and CIS Controls; author the company-wide security SOP library for the firm’s runbook system of record.

City of Carmel, Indiana · Sep 2025 – Mar 2026 · Carmel, IN

System Administrator, Cybersecurity

Owned the cybersecurity risk program for municipal government infrastructure serving 100,000+ residents across 25+ security policy domains.

  • Built a Python reporting framework ingesting exports from 40+ network segments, cutting monthly vulnerability analysis from hours to under 30 seconds with MITRE ATT&CK mappings and dual-format output.
  • Triaged 11,777+ vulnerability findings (3 critical, 112 high-severity) mapped to 39 organizational risks, reducing high-severity hosts 33% (281 to 187) in three months while advancing CJIS compliance to 59% and NIST CSF 2.0 alignment to 55%.
  • Improved cybersecurity posture score 6.7% (5.28 to 6.0) in six months, driving 284 of 553 security tasks to completion and closing 86% of critical-priority items.
  • Assessed critical infrastructure vulnerabilities across water treatment, wastewater, police, fire, and emergency operations networks; authored a 9-section operational runbook and handoff package covering 40+ segments.
  • Reduced phish-prone rate from 25% to 1.8% (93% improvement) across 861 users — ten times better than the 18.6% government sector benchmark — and led an Abnormal AI deployment across 1,051 mailboxes that reduced social-engineering BEC from 13 incidents to 0.

Quadrant Information Security · Jan 2024 – Sep 2025 · Remote

Cyber Threat Analyst

  • Monitored and analyzed security alerts across client environments using SIEM platforms; performed real-time threat detection, triage, and escalation for managed security operations.
  • Investigated malware, phishing, unauthorized access, and anomalous network activity; refined detection rules and correlation logic to reduce false positives and improve alert fidelity.

Medical Informatics Engineering · Apr 2023 – Aug 2023 · Fort Wayne, IN

DevOps Technician

  • Managed infrastructure automation, deployment pipelines, and system configuration for an EHR provider in a HIPAA-regulated environment.
  • Automated deployment and configuration management; monitored system health and security events across production healthcare infrastructure.

Network Engineer

  • Engineered enterprise SD-WAN, MPLS, and cloud connectivity with security as a design requirement.
  • Configured firewalls, VPNs, and network segmentation; collaborated with security teams on network-layer incident response.

Team Cymru · Apr 2022 – Aug 2022 · Remote Link to heading

Client Support Specialist

  • Supported enterprise threat intelligence customers on the Pure Signal platform — IP reputation and network flow analysis — helping Fortune 500 security teams operationalize threat intel feeds into detection and response workflows.

NetGain Technologies · Oct 2021 – Apr 2022 · Lexington, KY

Field Engineer

  • Delivered on-site infrastructure and security support for managed services clients across healthcare, manufacturing, and professional services.
  • Performed network security hardening and firewall rule optimization; managed EDR, patching, and vulnerability remediation under HIPAA and PCI requirements.

Everstream · Nov 2020 – Oct 2021 · Remote

NOC Engineer

  • Monitored enterprise fiber infrastructure spanning 25,000+ route miles; performed real-time triage via SNMP, syslog, and proprietary platforms; escalated security-relevant events and documented incident timelines.

Rook Security · 2018 – 2019 · Indianapolis, IN Link to heading

Security Operations Center Analyst

  • First dedicated security operations role at a regional MSSP: monitored and triaged security events, performed vulnerability scanning with Tenable Nessus, and escalated confirmed threats with written analysis. Position ended when the company ceased operations.

Earlier experience Link to heading

IT Contractor — Napa Balkamp (2018); Kinney Group (2018, Splunk environment). Subject Matter Expert, Radiology — IU Health (2014–2017). Utility Locator — USIC (2017). Technician — Comcast (2012–2014). Deputy Sheriff — Marion County Sheriff’s Office (2009–2012), working under CJIS with daily incident documentation and evidence handling.

Projects & Public Work Link to heading

Hands-on orchestration of AI coding agents and MCP-integrated automation platforms, including scheduled jobs, sandboxed execution, and credential-scoped automation. Public writing, tools, and repositories are linked in the sidebar.

Certifications Link to heading

In progress: CISSP — ISC2 (exam scheduled August 24, 2026) · ISC2 Candidate (through May 2027)

Security: CompTIA CySA+ ce · CompTIA Security+ ce · CompTIA Security Analytics Professional (CSAP) · Blue Team Level 1 (BTL1) · Certified CyberDefender Level 2 (CCDL2) · Wazuh for Security Engineers · Ransomware Negotiation and Threat Intelligence · Microsoft Certified: Security, Compliance and Identity Fundamentals

Cloud & Infrastructure: CompTIA Cloud+ ce · CompTIA Secure Cloud Professional (CSCP) · CompTIA Cloud Admin Professional (CCAP) · AWS Certified Cloud Practitioner · Microsoft Certified: Azure Fundamentals · CompTIA Network+ ce

Platform & Program: ConnectSecure Certified Administrator (CCA) · CompTIA Project+ ce

Roadmap: Microsoft AZ-500 and SC-200 following CISSP; Databricks Certified Generative AI Engineer and Google Cloud AI/ML track through 2027.

Education Link to heading

Western Governors University — B.S. Cybersecurity and Information Assurance (in progress)