Skip to main content

CAPABILITIES

Turning security problems into systems people can trust.

Security engineering, systems architecture, cloud platforms, automation, governance, and secure software capabilities demonstrated through practical responsibility and continued building.

  1. 01

    Security Engineering

    My security work has included identity and privileged access, endpoint protection, email and collaboration security, data protection, detection, investigation, and incident response. I start with the risk and the operating environment before choosing a control.

    Selected practice

    • Identity and access security
    • Endpoint, workforce, and collaboration security
    • Data protection and security operations
    • Detection, response, and exposure management
  2. 02

    Architecture and Systems Thinking

    I look for the relationships a product view misses: trust boundaries, identity, data flow, failure recovery, support burden, and long-term ownership. Certificate-backed EAP-TLS work, for example, required device management, certificates, network policy, and user experience to function as one system.

    Selected practice

    • Trust boundaries and data flows
    • Dependencies, failure modes, and resilience
    • Operational ownership and technical debt
    • Build-versus-buy and maintainability decisions
  3. 03

    Cloud and Platform Engineering

    I have worked across Microsoft Azure, Microsoft 365, Google Workspace, SaaS platforms, endpoint management, and security telemetry in distributed environments. A platform control has to reduce risk without becoming too fragile or burdensome to operate.

    Selected practice

    • Microsoft Azure, Microsoft 365, and Google Workspace
    • Enterprise identity and SaaS integration
    • Endpoint-management and security platforms
    • Telemetry, configuration baselines, and governance
  4. 04

    Automation and Engineering Efficiency

    I use PowerShell, Python, APIs, and Microsoft Graph for administration, validation, evidence collection, reporting, and security operations. I automate work when repetition is creating inconsistency or hiding useful information, and I account for permissions, failure handling, and who will maintain it.

    Selected practice

    • PowerShell and Python
    • REST APIs and Microsoft Graph
    • Configuration validation and evidence collection
    • Security operations, data processing, and reporting
  5. 05

    Risk, Governance, and Executive Communication

    I have explained identity, data-protection, third-party, incident, and AI risks to executives and partners in legal, compliance, IT, and business operations. The goal is to give people enough technical context to decide, including uncertainty and tradeoffs, without using fear as leverage.

    Selected practice

    • Technical risk and security control design
    • Regulatory interpretation and third-party risk
    • Policies, standards, and AI governance
    • Incident communication and executive decision support
  6. 06

    Secure Software Engineering

    This is a developing part of my work. Graduate computer-science study and continued building have given me hands-on practice with APIs, authorization, data models, validation, dependencies, containers, and testing, while also showing me where I need more depth.

    Selected practice

    • Application architecture and secure design
    • Authentication, authorization, APIs, and data integrity
    • Validation, dependencies, logging, and testing
    • Threat modeling and containerized development
  7. 07

    Research and Communication

    I use technical writing, diagrams, literature review, and small experiments to work through questions and explain what I find. I distinguish graduate study and applied investigation from formal research, and I try to state limitations as clearly as conclusions.

    Selected practice

    • Research questions and literature review
    • Applied investigation and experiment design
    • Technical writing, diagrams, and architecture documentation
    • Speaking, teaching, and responsible publication

Technologies applied in practice

Platforms, frameworks, and tools used across security engineering, cloud infrastructure, automation, and software development.

Microsoft Azure

Cloud infrastructure, identity integration, security architecture, and platform operations

Microsoft Entra ID

Authentication, conditional access, privileged access, identity governance, and passkeys

Microsoft Defender

Endpoint protection, threat investigation, vulnerability management, and security operations

Microsoft Sentinel

Detection engineering, investigation, analytics, and incident response

Microsoft Purview

Data classification, information protection, retention, and data loss prevention

PowerShell

Security automation, administration, reporting, and operational workflows

Jamf

Apple device management, configuration enforcement, and endpoint security

Kali Linux

Security labs, assessment workflows, systems administration, and platform engineering

Docker

Application packaging, security labs, and repeatable deployment

Cloudflare

DNS, web application protection, traffic control, and edge security

Python

Security automation, data processing, integrations, and application development

FastAPI

Secure API development, backend services, and application prototyping

PostgreSQL

Relational data modeling, application persistence, and secure data workflows

TypeScript

Type-safe software development, frontend engineering, and application architecture

React

Component-driven user interfaces and interactive application development

Next.js

Static web architecture, application routing, content-driven development, and frontend engineering

Git

Version control, change management, and collaborative software development

GitHub

Source control, project collaboration, code review, and repository governance

Current direction

Still building.

My deepest experience is in enterprise security: identity, endpoints, cloud platforms, data protection, operations, automation, and the decisions around them. I am still developing as a software engineer and researcher through graduate computer-science study, secure application work, cloud-native and AI security study, and continued building. I do not consider those areas finished expertise.