Curriculum vitae

Resume

Security Analyst and DevSecOps Engineer

North Bay, Ontario - Remote, hybrid, or on-site

ngenzipack@gmail.com

Resume for cybersecurity, IAM, cloud, DevSecOps, and network security roles.

A web-friendly summary of my hiring profile. Download the Word resume or review role-aligned highlights below.

Download

Get a copy of the resume for your hiring process.

The downloadable Word file is the current resume used for hiring conversations.

Profile

I design and operate practical security controls across IAM, cloud, endpoints, and networks. My work includes Entra ID and Active Directory governance, RBAC, MFA, Conditional Access, Azure VM and NSG hardening, Microsoft Sentinel detections, Defender and ESET response workflows, SolarWinds monitoring, firewall cleanup, wireless segmentation, vulnerability remediation, automation, and secure web/server operations.

  • Security Analyst
  • IAM Analyst
  • Cloud Security Analyst
  • DevSecOps Engineer
  • SOC/NOC Analyst
  • Network Security Administrator

Credentials

01

Education and certifications.

Education

Computer Engineering Technology

Mohawk College - Graduate

Certifications

  • Credential badge for CompTIA Security+

    CompTIA Security+

    CompTIA

    Last updated: May 2026

    Certified
    • Threat, attack, and vulnerability identification
    • Risk management and risk mitigation techniques
    • Threat management operations
    • Intrusion detection practices
    • Core cybersecurity function readiness
    View credential
  • Google Cybersecurity Certificate

    Google / Coursera

    Last updated: May 2026

    Certified
  • Microsoft SC-300: Identity and Access Administrator

    Microsoft

    Last updated: May 2026

    In Progress

Experience

02

Roles and impact.

01

Nov 2023 - Present

North Bay, Ontario

Intermediate IT System Support

Near North District School Board

  • Support 1,000+ endpoints while triaging endpoint-security, access, connectivity, and availability issues for teachers, administrators, and students.
  • Operate SolarWinds and ESET monitoring; mitigate 150+ malware/security incidents monthly with remediation follow-through and clear escalation notes.
  • Harden Azure virtual machines and NSG security rules while reviewing access exposure and Conditional Access alignment.
  • Delivered phishing, password hygiene, MFA, and secure-browsing guidance for 12+ users/groups, reducing reported suspicious incidents by 30%.

02

Jan 2022 - Dec 2023

Hamilton, Ontario

Network Specialist

Bell

  • Configured Fortinet and Palo Alto firewall rules and tightened policy exposure, reducing attack surface by 25% while preserving approved access paths.
  • Implemented Entra ID RBAC and least-privilege controls, cutting excessive permissions by 19%; automated onboarding/offboarding with PowerShell.
  • Secured Aerohive WAPs with WPA3 encryption and VLAN segmentation to isolate guest and IoT traffic.
  • Configured Microsoft Defender for Endpoint workflows to detect, investigate, and isolate compromised devices.

03

Feb 2020 - Jan 2022

Hamilton, Ontario

Technical Support Analyst I

SP Data Digital

  • Resolved 95% of Tier I/II tickets within 20 minutes, including account lockouts, access requests, endpoint issues, and security escalations.
  • Patched 50+ servers for critical vulnerabilities, including Log4j, helping reduce exploit exposure and improve resilience.
  • Reduced critical outages by 70% through proactive maintenance, documentation, escalation discipline, and repeatable troubleshooting protocols.
  • Maintained secure access and customer-service discipline in a high-volume privacy-sensitive support environment.

04

Jan 2022 - Feb 2025

North Bay, Ontario

Property Manager

Independent Property Management

  • Assessed 10+ third-party vendors for PIPEDA-aligned data privacy practices.
  • Protected sensitive tenant financial data and PII through access-control and confidentiality practices.
  • Managed keycard, CCTV, and facilities access workflows using least-privilege and auditability principles.
  • Coordinated vendor and stakeholder communication for security-critical maintenance windows.

Capabilities

03

Skills snapshot.

AI-Driven Security Triage and SOC Automation

  • SIEM alert triage and alert-fatigue reduction
  • Security event normalization from Wazuh and ELK-style alerts
  • True positive, false positive, and uncertain classification logic
  • MITRE ATT&CK mapping (including PowerShell execution T1059.001)
  • Threat analysis and plain-English incident summaries
  • Risk scoring and severity classification
  • Security audit logging and alert evidence preservation
  • Incident response recommendation generation
  • Suspicious PowerShell, brute-force, malware, phishing, and privilege-escalation detection logic
  • SOC workflow automation and analyst decision support
  • Suspicious outbound communication and possible C2 behavior triage
  • HTTP REST API integrations for Wazuh and Elasticsearch
  • Prompt engineering for structured JSON outputs and validator-backed parsing
  • Deterministic fallback classifiers for AI-service outages

Cloud Security

  • Microsoft Azure (VM, VNet, NSG, VPN Gateway, hardening)
  • Microsoft Sentinel and Log Analytics detections
  • Microsoft 365 Defender
  • Microsoft Defender for Endpoint
  • Google Cloud IAM
  • Google Cloud Security Command Center
  • Hybrid cloud connectivity controls
  • ESET endpoint protection
  • SolarWinds monitoring
  • Server patching and vulnerability remediation

Identity and Access Management

  • Microsoft Entra ID (Azure AD)
  • Conditional Access policy design
  • Multi-Factor Authentication enforcement
  • Role-based access control
  • Privileged Identity Management concepts
  • Active Directory
  • Access reviews
  • Onboarding and offboarding
  • Stale-account cleanup

Endpoint and UEM Operations

  • MaaS360 device inventory
  • MaaS360 endpoint policy management
  • Microsoft Defender for Endpoint triage
  • ESET malware response workflows
  • Patch and vulnerability coordination
  • Endpoint compliance and remediation tracking

Network Defense

  • Fortinet and Palo Alto firewalls
  • IDS and IPS tuning
  • VPN (site-to-site and remote access)
  • Aerohive WAPs
  • WPA3 and guest/IoT isolation
  • VLAN segmentation
  • Packet analysis with Wireshark
  • Nginx reverse-proxy security controls
  • Firewall policy lifecycle and change discipline

DevSecOps and Automation

  • Jenkins CI/CD pipelines
  • GitHub Actions quality gates
  • Docker and Docker Compose operations
  • Buildx and container registry workflows
  • Environment validation and deployment guardrails
  • PowerShell scripting
  • Python security scripting
  • Bash and shell tooling
  • SQL log querying
  • Event-log collection
  • Git and GitHub workflows
  • Ticketing and SLA documentation

Software, Web, and Platform Delivery

  • TypeScript
  • JavaScript
  • React and Next.js
  • FastAPI and Node.js service integration
  • Java
  • C#
  • Tailwind CSS
  • Backend integration
  • DNS, SSL/TLS, and hosting operations
  • Server management
  • Client support
  • Accessibility-aware UI

Frameworks and Standards

  • NIST Cybersecurity Framework
  • CIS Benchmarks
  • Zero Trust principles
  • PIPEDA and privacy-aware handling
  • Audit-ready documentation

Ready to talk about a role or engagement?