I own security incidents end to end — triage, containment, root-cause analysis, remediation, and post-incident review — across endpoint, identity, network, cloud, phishing, and account-compromise cases. Then I automate the parts that shouldn't need a human twice.
My open-source work turns SOC and IR toil into code: SOAR playbooks that ship through CI, detections managed like software, and tooling that shortens an analyst's day.
role: Senior SOC Analyst (L3) @ MSSP # escalation point for real intrusions
detect: ATT&CK threat hunts -> tuned rules in Cortex XSIAM, Splunk ES, Falcon, SentinelOne
automate: Python playbooks in Splunk SOAR & Cortex XSOAR (agentic + AI-assisted)
dfir: Volatility, Autopsy, FTK + reverse-engineering compiled code when needed| Project | What it does |
|---|---|
| 🧩 detection-as-code | Reusable CI/CD pipeline templates for building, testing, validating, and deploying security detections as code. |
| ⚡ splunk-soar-mcp | MCP server exposing 70 tools for Splunk SOAR — playbooks, containers, artifacts, administration, visual-editor blocks. |
| 🔍 soar-playbook-ci | CI for a SOAR playbook repo: structure validation plus a regex + LLM credential scan. |
| 🧬 pycinspect | Read, decompile, and patch CPython 3.13 .pyc files — every reconstruction verified against the bytecode. |
| SOAR playbooks | SLA compliance | MTTD / MTTR | Manual toil |
|---|---|---|---|
| 150+ | 82% → 95% | −40–45% | −60% |

