2026
University of Nevada, Reno
M.S. Cybersecurity
Dean’s List · 3.9+ GPA
Graduate work in threat modeling, secure architecture and defensive automation — the direct throughline to the DevSecOps practice I run today.
Cybersecurity‑focused DevOps engineer designing resilient infrastructure, automating secure deployments, and hardening systems from code to cloud.
01 — Education
Six years of formal grounding in systems, information and adversarial thinking — the theory that everything I ship in production is still built on.
2026
M.S. Cybersecurity
Dean’s List · 3.9+ GPA
Graduate work in threat modeling, secure architecture and defensive automation — the direct throughline to the DevSecOps practice I run today.
2023
B.A. Information Systems
Dean’s List · 3.8+ GPA
Where systems analysis met the business case for them — designing, integrating and documenting the platforms an organization actually depends on.
2020
A.S. Information Technology
Dean’s List · 3.7+ GPA
Systems administration, Linux fundamentals and the first scripting habits that eventually turned into an automation practice.
02 — Experience
Eight years moving from hands‑on integration work, through frontline security operations, into the platform engineering that keeps a multi‑tenant SOC running.
2024 — Present
SNC
Full‑time
Own the data and detection infrastructure behind a multi‑tenant Security Operations Center — ingestion pipelines, SIEM platform engineering, and the analyst‑facing tooling layered on top of both.
2023 — 2024
SNC
Full‑time
Frontline detection and response inside a Security Operations Center, triaging alerts across endpoint, network and identity telemetry and escalating confirmed incidents with documented scope, impact and containment guidance.
2018 — 2023
Magnolia AV
Full‑time
Delivered in‑home technical consultations and end‑to‑end integration of residential audio/video, networking and control systems — from requirements gathering through commissioning and client handoff.
03 — Stack
A read‑out of the tooling I work in, scored on how much I’d stake on it in production. The spread is deliberate — I’d rather be specific about where I’m deep and where I’m merely competent. The notes explain each number.
18
Tracked competencies
3yrs
In the field
3
Degrees earned
24/7
SOC coverage supported
80%
A year on the floor triaging alerts under response SLAs, then two more building the platform that feeds it. I’ve worked both sides of every ticket.
55%
I can turn observed tradecraft into detection logic and tune it against live telemetry, but authoring content is a smaller slice of my week than the pipelines feeding it.
50%
Working familiarity — feed curation, taxonomy hygiene, and pushing indicator context downstream. I know what it’s for and can operate it; I’m not deep in its internals.
85%
The deep end of my expertise. Ingest pipelines, index lifecycle and retention, query performance, cluster health and the tenant isolation boundaries underneath all of it.
70%
Batch and streaming transforms over large security datasets — normalization, enrichment joins and schema enforcement before anything reaches the SIEM.
60%
Working proficiency. I can model a schema, write the queries and run migrations for internal tooling, but deep relational tuning isn’t where my hours have gone.
45%
I build the dashboards I need — pipeline throughput, ingestion lag, tenant health — but I’d not call myself a Grafana specialist. Most of my visibility work lives in Kibana.
85%
Cluster setup, storage and networking, LXC and VM templating. I run my own multi‑node cluster, and CI for this site executes on a runner inside it.
75%
The through‑line of everything else here. If I do it twice by hand it becomes a pipeline, a role, or a script the next person can read.
70%
Deploy and operate containerized platform services — manifests, resource limits, rollout strategy, and the debugging that inevitably follows.
70%
I can reason about cloud topology — identity boundaries, network segmentation, tenant isolation — but most of my infrastructure hours are on hardware I own rather than rented.
60%
Idempotent roles for configuration management and fleet‑wide change, so environments converge on a known‑good state instead of quietly drifting apart.
60%
Infrastructure declared in code and reviewed like code, so environments are reproducible rather than hand‑built artifacts nobody dares rebuild.
65%
I design services that hold up, with attention to data contracts and tenant boundaries — but I come at it from the data and infrastructure side, not from microservice patterns.
55%
Functional, not fluent. I ship analyst‑facing views for the SOC tooling I build, but I’d defer to a dedicated front‑end engineer on anything more ambitious.
50%
An interest rather than a discipline. I care that tooling looks considered and I’ll put the hours in — this site is the evidence — but it’s the furthest thing here from my day job.
85%
Five years of in‑home consultations taught me to translate technical constraints into plain language and to set expectations I can actually meet.
75%
Queue and workflow management — intake, triage, SLA tracking, and the reporting that shows where a backlog is really accumulating.