[ MODULE: ABOUT ]

Operator dossier

Security professional specializing in penetration testing, SOC operations, GRC frameworks, malware analysis, and smart contract security. Building tools that turn threat intel into action.

// FOCUS_AREAS

Offensive Security

Web, network, and AD-focused assessments with actionable remediations — not just findings dumps.

Detection & Response

SIEM tuning, hunt playbooks, and SOAR automation that shrink dwell time.

Chain Security

Solidity audits, invariant testing, and on-chain monitoring for protocol risk.

// EXPERIENCE_LOG

[2025.Q2] LEAD_RESEARCH

> Directed smart-contract audit program covering DeFi protocols; published remediations for critical reentrancy and oracle risks.

[2024.Q4] SOC_ESCALATION

> Built detection content for ransomware staging TTPs; reduced mean time to contain by 38%.

[2024.Q1] RED_TEAM_OP

> External + internal engagement for fintech client; achieved domain compromise via phishing + AD abuse chain.

[2023.Q3] MALWARE_LAB

> Stood up isolated analysis pipeline for PE/ELF samples; authored YARA packs for commodity RATs.

[2022.Q2] GRC_BASELINE

> Mapped controls to ISO 27001 / NIST CSF; guided first SOC 2 Type I evidence collection.

// CERTIFICATIONS

CEH

CEH

EC-Council · 2024

Verify
OSCP

OSCP

Offensive Security · 2025

Verify
Comp

CompTIA Security+

CompTIA · 2023

Verify
AWS

AWS Security Specialty

Amazon Web Services · 2024

Verify