Thoughtful. Secure Architecture.

Cybersecurity‑focused DevOps engineer designing resilient infrastructure, automating secure deployments, and hardening systems from code to cloud.

Currently open to engagements
Scroll

01 — Education

Where the foundation
was poured.

Six years of formal grounding in systems, information and adversarial thinking — the theory that everything I ship in production is still built on.

  1. 2026

    University of Nevada, Reno

    M.S. Cybersecurity

    Dean’s List · 3.9+ GPA

    Graduate work in threat modeling, secure architecture and defensive automation — the direct throughline to the DevSecOps practice I run today.

    • Threat Modeling
    • Cryptography
    • Incident Response
  2. 2023

    University of Nevada, Reno

    B.A. Information Systems

    Dean’s List · 3.8+ GPA

    Where systems analysis met the business case for them — designing, integrating and documenting the platforms an organization actually depends on.

    • Systems Analysis
    • Databases
    • Cloud Infrastructure
  3. 2020

    Truckee Meadows Community College

    A.S. Information Technology

    Dean’s List · 3.7+ GPA

    Systems administration, Linux fundamentals and the first scripting habits that eventually turned into an automation practice.

    • Linux
    • Networking
    • Scripting

02 — Experience

From the field
to the pipeline.

Eight years moving from hands‑on integration work, through frontline security operations, into the platform engineering that keeps a multi‑tenant SOC running.

  1. 2024 — Present

    SNC

    Full‑time

    Cybersecurity DevOps Engineer

    Own the data and detection infrastructure behind a multi‑tenant Security Operations Center — ingestion pipelines, SIEM platform engineering, and the analyst‑facing tooling layered on top of both.

    • Design, deploy and maintain log‑ingestion pipelines feeding a multi‑tenant SIEM, covering collection, parsing, normalization, enrichment and schema consistency across heterogeneous tenant data sources.
    • Engineer and operate SIEM platform infrastructure — cluster health and capacity, index lifecycle and retention policy, role‑based access control, and the isolation boundaries that keep tenant data segregated.
    • Automate build, deployment and configuration management for detection content and platform services, keeping every environment reproducible, version‑controlled and auditable.
    • Develop React front‑end tooling that surfaces pipeline health, detection coverage and tenant‑scoped investigation workflows for SOC analysts.
    • Partner with analysts to convert operational gaps into engineered capability: new data sources onboarded, noisy detections tuned, and coverage tracked as a measurable metric.
    • Data Pipelines
    • SIEM Engineering
    • Multi‑Tenant
    • CI/CD
    • React
    • Infrastructure as Code
  2. 2023 — 2024

    SNC

    Full‑time

    Cybersecurity Analyst

    Frontline detection and response inside a Security Operations Center, triaging alerts across endpoint, network and identity telemetry and escalating confirmed incidents with documented scope, impact and containment guidance.

    • Monitored and triaged SIEM alert queues against established playbooks, performing initial scoping, enrichment and false‑positive reduction under defined response SLAs.
    • Conducted host‑ and network‑level investigations, correlating EDR, firewall, proxy, DNS and authentication telemetry to reconstruct activity timelines and determine true impact.
    • Authored incident reports and after‑action documentation, and fed recurring false positives back to engineering as concrete detection‑tuning requests.
    • Maintained indicator and threat‑intelligence enrichment, mapping observed tradecraft to MITRE ATT&CK techniques to keep coverage gaps visible.
    • SOC Operations
    • SIEM
    • EDR
    • Incident Triage
    • MITRE ATT&CK
  3. 2018 — 2023

    Magnolia AV

    Full‑time

    A/V Integration & Automation Specialist

    Delivered in‑home technical consultations and end‑to‑end integration of residential audio/video, networking and control systems — from requirements gathering through commissioning and client handoff.

    • Conducted on‑site consultations that translated client requirements into documented system designs, signal‑flow diagrams and itemized bills of material.
    • Integrated distributed audio, video distribution, lighting and network subsystems, including structured cabling, rack build‑out and segmented networks provisioned for latency‑sensitive AV traffic.
    • Programmed and commissioned home‑automation controllers — device driver configuration, scene and event logic, scheduling, and custom touch‑panel interface layouts.
    • Performed post‑installation validation and calibration, led client operational training, and owned ongoing warranty support and remote troubleshooting.
    • AV Integration
    • Control Programming
    • Home Automation
    • Structured Cabling
    • Client Consultation

03 — Stack

What I reach for,
and how far.

A read‑out of the tooling I work in, scored on how much I’d stake on it in production. The spread is deliberate — I’d rather be specific about where I’m deep and where I’m merely competent. The notes explain each number.

18

Tracked competencies

3yrs

In the field

3

Degrees earned

24/7

SOC coverage supported

Detection & Response

avg 62

  • SOC Operations

    80%

    A year on the floor triaging alerts under response SLAs, then two more building the platform that feeds it. I’ve worked both sides of every ticket.

  • Detection Engineering

    55%

    I can turn observed tradecraft into detection logic and tune it against live telemetry, but authoring content is a smaller slice of my week than the pipelines feeding it.

  • MISP

    50%

    Working familiarity — feed curation, taxonomy hygiene, and pushing indicator context downstream. I know what it’s for and can operate it; I’m not deep in its internals.

Data & Observability

avg 65

  • Elastic Stack

    85%

    The deep end of my expertise. Ingest pipelines, index lifecycle and retention, query performance, cluster health and the tenant isolation boundaries underneath all of it.

  • PySpark

    70%

    Batch and streaming transforms over large security datasets — normalization, enrichment joins and schema enforcement before anything reaches the SIEM.

  • PostgreSQL

    60%

    Working proficiency. I can model a schema, write the queries and run migrations for internal tooling, but deep relational tuning isn’t where my hours have gone.

  • Grafana

    45%

    I build the dashboards I need — pipeline throughput, ingestion lag, tenant health — but I’d not call myself a Grafana specialist. Most of my visibility work lives in Kibana.

Platform & Infrastructure

avg 70

  • Proxmox

    85%

    Cluster setup, storage and networking, LXC and VM templating. I run my own multi‑node cluster, and CI for this site executes on a runner inside it.

  • Automation

    75%

    The through‑line of everything else here. If I do it twice by hand it becomes a pipeline, a role, or a script the next person can read.

  • Kubernetes

    70%

    Deploy and operate containerized platform services — manifests, resource limits, rollout strategy, and the debugging that inevitably follows.

  • Azure Architecture

    70%

    I can reason about cloud topology — identity boundaries, network segmentation, tenant isolation — but most of my infrastructure hours are on hardware I own rather than rented.

  • Ansible

    60%

    Idempotent roles for configuration management and fleet‑wide change, so environments converge on a known‑good state instead of quietly drifting apart.

  • Terraform

    60%

    Infrastructure declared in code and reviewed like code, so environments are reproducible rather than hand‑built artifacts nobody dares rebuild.

Application

avg 57

  • Backend Architecture

    65%

    I design services that hold up, with attention to data contracts and tenant boundaries — but I come at it from the data and infrastructure side, not from microservice patterns.

  • React

    55%

    Functional, not fluent. I ship analyst‑facing views for the SOC tooling I build, but I’d defer to a dedicated front‑end engineer on anything more ambitious.

  • Web Design

    50%

    An interest rather than a discipline. I care that tooling looks considered and I’ll put the hours in — this site is the evidence — but it’s the furthest thing here from my day job.

Service Delivery

avg 80

  • Customer Relations

    85%

    Five years of in‑home consultations taught me to translate technical constraints into plain language and to set expectations I can actually meet.

  • osTicket

    75%

    Queue and workflow management — intake, triage, SLA tracking, and the reporting that shows where a backlog is really accumulating.