SOC & Detection Engineering
Splunk, Sysmon, Snort, Windows Security Events, detections, dashboards, alerts, investigations, and security monitoring.
SYSTEMS ADMINISTRATION • NETWORKING • CYBERSECURITY
I design and build practical infrastructure and security projects involving Windows Server, Active Directory, Microsoft Entra ID, AWS, pfSense, Splunk, Sysmon, Snort, VPNs, endpoint security, automation, networking, and security operations.
I am developing practical experience across systems administration, networking, cybersecurity, cloud infrastructure, identity management, security operations, and enterprise troubleshooting.
My work focuses on building complete environments rather than studying technologies in isolation. I design systems, configure infrastructure, implement security controls, collect telemetry, create detections, test access, troubleshoot failures, and document the final result.
My current portfolio includes Active Directory and SOC engineering, AWS hybrid cloud infrastructure, Microsoft Entra hybrid identity, secure IKEv2 remote access VPNs, centralized monitoring with Splunk, endpoint telemetry with Sysmon, network detection with Snort, and controlled security testing.
I am expanding my hands-on work into endpoint detection and response and security automation.
Splunk, Sysmon, Snort, Windows Security Events, detections, dashboards, alerts, investigations, and security monitoring.
Active Directory, pfSense, network segmentation, firewall rules, DNS, access control, and enterprise troubleshooting.
AWS, VPC, EC2, IPsec, Microsoft Entra ID, Microsoft Entra Connect, and hybrid identity.
Endpoint telemetry, process behavior, alert triage, investigation, containment concepts, and response workflows.
PowerShell, Python, Bash, log processing, repeatable administrative tasks, alert enrichment, and response automation.
TCP/IP, subnetting, routing, VPNs, Wireshark analysis, VMware networking, and connectivity troubleshooting.
Hands-on infrastructure and cybersecurity projects demonstrating enterprise administration, networking, cloud, identity, security monitoring, access control, testing, and troubleshooting.
Built a segmented Windows enterprise environment using Active Directory, multiple domain controllers, Group Policy, pfSense, Splunk Enterprise, Sysmon, Snort IDS, and controlled security testing.
Designed an AWS VPC and securely connected it to an on-premises VMware infrastructure through pfSense using redundant IPsec Site-to-Site VPN tunnels.
Extended an on-premises Active Directory environment into Microsoft Entra ID and implemented hybrid identity using Microsoft Entra Connect Sync.
Designed, implemented, and validated secure remote access using pfSense, IKEv2/IPsec, Windows clients, network segmentation, least-privilege firewall rules, split tunneling, and Splunk authentication monitoring.
Upcoming endpoint security project focused on endpoint telemetry, process behavior, alert triage, investigation, detection logic, containment, and response workflows.
Upcoming security automation project focused on PowerShell, Python, Bash, log processing, alert enrichment, IOC handling, scheduled checks, repeatable workflows, and response automation.
Selected technical evidence from completed infrastructure and cybersecurity projects.
Multi-domain-controller Windows environment with Group Policy, centralized logging, Sysmon telemetry, Splunk detections, pfSense segmentation, and Snort IDS.
View Evidence →AWS VPC architecture, EC2 workloads, IAM controls, CloudTrail and CloudWatch, pfSense IPsec connectivity, private network testing, and redundant VPN validation.
View Evidence →Public-domain integration, UPN configuration, Microsoft Entra Connect Sync, synchronized identity validation, on-premises attribute verification, and cloud authentication.
View Evidence →Encrypted remote access, dedicated VPN addressing, split tunneling, DNS and SMB access controls, blocked-service testing, and Splunk authentication monitoring.
View Evidence →Windows Server 2016, 2019 & 2022, Active Directory Domain Services, domain controllers, AD replication, DNS, DHCP, Group Policy, users and groups, Organizational Units, file services, NTFS/share permissions, VMware, and Windows administration.
TCP/IP, IPv4, subnetting, LAN/WAN networking, routing, DHCP, NAT, network segmentation, pfSense, firewall rules, access control, IPsec, Site-to-Site VPN, Remote Access VPN, Wireshark, and VMware networking.
Splunk Enterprise, Universal Forwarder, SPL searches, dashboards, alerts, Sysmon, Snort IDS, Windows Security Events, centralized logging, detection engineering, threat investigation, vulnerability assessment, firewall validation, security hardening, and incident response.
Endpoint telemetry, process and network activity analysis, behavioral detection concepts, alert triage, investigation workflows, containment concepts, persistence analysis, authentication telemetry, and response workflows.
PowerShell, Python fundamentals, Bash scripting, log parsing, alert enrichment, IOC handling, scheduled checks, repetitive-task automation, workflow automation, and repeatable remediation.
AWS, EC2, VPC, IAM, S3, CloudTrail, CloudWatch, Microsoft Entra ID, Microsoft Entra Connect, hybrid identity, and identity and access management.
Technical training across networking, cybersecurity, cloud computing, SOC operations, and infrastructure.
Enterprise Networking, Security and Automation
Professional Certificate
Certificate
Cloud Technology Badge
Certificate
Cybersecurity Training
Network Projects Certificate
Routing, switching, subnetting, packet analysis, connectivity testing, and troubleshooting.