Experience

Core competencies, certifications, and the programs I have designed and delivered.

Core competencies

Cloud
AWS
Microsoft Azure
Google Cloud Platform
Security Architecture
Infrastructure & Cloud Security
Hybrid Security
Threat Modeling
Architecture Reviews
Risk Assessment
Security Operations
Google SecOps / Chronicle
Palo Alto XSOAR
SIEM
SOAR
Detection Engineering
Parser Development
Threat Hunting
CTI
Purple Team
Identity
OAuth
Workforce Identity Federation
SSO
Authentication
Authorization
Security Engineering
Automation
Security Controls
Vulnerability Management
DAST
Network Security
Encryption & Key Management
Configuration Management
Compliance
NIST 800-53
PCI-DSS
ISO 27001
FedRAMP
SOC 2
SOX
Cloud & Data Security Posture
Attack Surface Management
CSPM
DSPM
Insider Threat Detection
Leadership
Vendor Management
Client Advisory
Executive Communication
Cross-Functional Program Leadership
Mentoring & Hiring

Certifications

CISM

ISACA

CDPSE

ISACA

CCSK v3.0

Cloud Security Alliance

CEH

EC-Council

Qualys Certified Vulnerability Specialist

Qualys

Qualys Certified Web Application Specialist

Qualys

AWS Cloud Practitioner

Amazon Web Services

Microsoft Azure Fundamentals

Microsoft

Microsoft Azure Implementation (70-533)

Microsoft

ITIL v3 Foundation

AXELOS

Selected programs

Enterprise SIEM on Google SecOps

Architected and engineered Google Security Operations (Chronicle) as the enterprise SIEM — ingestion pipelines, parsers, detection logic, and automated response built from scratch.

SIEM
Detection Engineering
Data Pipelines

SOAR Automation Program

Built Palo Alto XSOAR playbooks and integrations with Google SecOps that reduced MTTR and eliminated manual SOC triage activities.

XSOAR
Automation
SOC

Multi-Cloud Security Integration

Designed security integrations across AWS, Azure, GCP, Okta, secure web gateway, and endpoint platforms for centralized visibility and detection coverage.

AWS
Azure
GCP
Okta

CTI & Threat Hunt Function

Hired and built the cyber threat intelligence and threat hunt team; converted adversary TTP research into detection requirements and hunt hypotheses.

CTI
Threat Hunting
Purple Team

Cloud & Data Posture Program

Deployed Attack Surface Management, CSPM, and DSPM capabilities to close cloud and data visibility gaps, plus enterprise insider threat detection.

ASM
CSPM
DSPM

Audit & Compliance Engineering

Represented security engineering in FedRAMP, NIST, ISO 27001, SOC 2, and PCI-DSS audits with architecture documentation and control evidence.

FedRAMP
ISO 27001
SOC 2
PCI-DSS