Capabilities

Skills

Technical skills mapped to outcomes you can use in production.

I organize my skills around what helps your team most: secure access, resilient cloud operations, endpoint visibility, network hardening, and reliable delivery.

Technical Skills

01

Curated strengths

This view highlights the tools and workflows I use most often when building practical security outcomes.

AI Security Triage Engineering

I design AI-assisted SOC workflows that classify alerts, score risk, and produce auditable analyst guidance with deterministic fallback behavior.

  • Local LLM integration
  • SIEM alert normalization and triage
  • MITRE ATT&CK event mapping
  • Risk scoring and response recommendation generation

Identity and Access Security

I protect accounts and privileges so your users can work securely without unnecessary friction.

  • Microsoft Entra ID (Azure AD)
  • Conditional Access
  • MFA enforcement
  • RBAC and access reviews

Cloud Detection and Hardening

I combine cloud hardening with operational detections so your team can respond before issues escalate.

  • Azure NSG and VM hardening
  • Microsoft Sentinel
  • Log Analytics
  • GCP IAM and Cloud Security Command Center

Endpoint and Device Governance

I secure endpoints with policy, visibility, and follow-through that your support teams can sustain.

  • MaaS360 inventory and endpoint management
  • Defender for Endpoint
  • ESET response workflows
  • Patch and vulnerability coordination

Network and Infrastructure Security

I reduce attack surface while preserving availability across firewall, segmentation, and proxy layers.

  • Fortinet and Palo Alto firewalls
  • VLAN segmentation and VPN controls
  • Nginx reverse proxy hardening
  • Wireshark traffic validation

DevSecOps and Reliability

I embed security checks into delivery pipelines so your releases stay fast, controlled, and auditable.

  • Jenkins and GitHub Actions
  • Docker and Compose
  • Security gates and env validation
  • Health-check and rollback workflow design

Client Platform Engineering

I deliver production-ready web platforms with measurable quality, security-minded operations, and clear communication.

  • Next.js and React
  • TypeScript and API integration
  • DNS and SSL/TLS operations
  • Server management and client support

Full Capability Map

02

Detailed domain coverage

The full view includes additional infrastructure, automation, and operational depth from enterprise and client-platform work.

01

Domain

AI-Driven Security Triage and SOC Automation

I build practical AI-assisted triage workflows that reduce alert fatigue while keeping analyst decisions auditable and defensible.

  • SIEM alert triage and alert-fatigue reduction
  • Security event normalization from Wazuh and ELK-style alerts
  • True positive, false positive, and uncertain classification logic
  • MITRE ATT&CK mapping (including PowerShell execution T1059.001)
  • Threat analysis and plain-English incident summaries
  • Risk scoring and severity classification
  • Security audit logging and alert evidence preservation
  • Incident response recommendation generation
  • Suspicious PowerShell, brute-force, malware, phishing, and privilege-escalation detection logic
  • SOC workflow automation and analyst decision support
  • Suspicious outbound communication and possible C2 behavior triage
  • HTTP REST API integrations for Wazuh and Elasticsearch
  • Prompt engineering for structured JSON outputs and validator-backed parsing
  • Deterministic fallback classifiers for AI-service outages

02

Domain

Cloud Security

I secure cloud environments with identity-first guardrails, segmented networking, and actionable monitoring.

  • Microsoft Azure (VM, VNet, NSG, VPN Gateway, hardening)
  • Microsoft Sentinel and Log Analytics detections
  • Microsoft 365 Defender
  • Microsoft Defender for Endpoint
  • Google Cloud IAM
  • Google Cloud Security Command Center
  • Hybrid cloud connectivity controls
  • ESET endpoint protection
  • SolarWinds monitoring
  • Server patching and vulnerability remediation

03

Domain

Identity and Access Management

I design and operate identity controls that reduce risk without blocking productivity.

  • Microsoft Entra ID (Azure AD)
  • Conditional Access policy design
  • Multi-Factor Authentication enforcement
  • Role-based access control
  • Privileged Identity Management concepts
  • Active Directory
  • Access reviews
  • Onboarding and offboarding
  • Stale-account cleanup

04

Domain

Endpoint and UEM Operations

I protect user devices with policy enforcement, inventory visibility, and fast incident follow-through.

  • MaaS360 device inventory
  • MaaS360 endpoint policy management
  • Microsoft Defender for Endpoint triage
  • ESET malware response workflows
  • Patch and vulnerability coordination
  • Endpoint compliance and remediation tracking

05

Domain

Network Defense

I harden and validate network paths so you get stronger security with dependable uptime.

  • Fortinet and Palo Alto firewalls
  • IDS and IPS tuning
  • VPN (site-to-site and remote access)
  • Aerohive WAPs
  • WPA3 and guest/IoT isolation
  • VLAN segmentation
  • Packet analysis with Wireshark
  • Nginx reverse-proxy security controls
  • Firewall policy lifecycle and change discipline

06

Domain

DevSecOps and Automation

I use delivery automation to make secure releases repeatable, testable, and easier to support.

  • Jenkins CI/CD pipelines
  • GitHub Actions quality gates
  • Docker and Docker Compose operations
  • Buildx and container registry workflows
  • Environment validation and deployment guardrails
  • PowerShell scripting
  • Python security scripting
  • Bash and shell tooling
  • SQL log querying
  • Event-log collection
  • Git and GitHub workflows
  • Ticketing and SLA documentation

07

Domain

Software, Web, and Platform Delivery

I build and operate production web platforms with security, reliability, and client communication built in.

  • TypeScript
  • JavaScript
  • React and Next.js
  • FastAPI and Node.js service integration
  • Java
  • C#
  • Tailwind CSS
  • Backend integration
  • DNS, SSL/TLS, and hosting operations
  • Server management
  • Client support
  • Accessibility-aware UI

08

Domain

Frameworks and Standards

Working knowledge of frameworks used to align controls with risk.

  • NIST Cybersecurity Framework
  • CIS Benchmarks
  • Zero Trust principles
  • PIPEDA and privacy-aware handling
  • Audit-ready documentation

See these skills in real project decisions and measurable outcomes.