// PROFILE
Security Operations Engineer with deep expertise in DLP, AI-driven security automation, SOC agentics, endpoint security, and incident response across large-scale enterprise environments. Experienced operating across on-prem and cloud/SaaS platforms, with a track record of designing and implementing security programs that reduce risk, improve response times, and scale across the organization.
Current work spans DLP investigation and escalation frameworks, AI-powered automation pipelines, SOC agentics, security policy creation and enforcement, and fleet-wide security initiatives including device lifecycle management and enterprise data governance programs. Brings a full-stack perspective from detection engineering and behavioral analysis to cross-functional collaboration with HR, Legal, and executive leadership.
Prior experience in critical infrastructure security includes on-prem deployment and administration of Splunk, CyberArk, Carbon Black, and Aruba ClearPass across Linux RHEL and Windows Server environments, with compliance alignment to NERC CIP, NIST, and additional regulatory frameworks.
Combines technical depth with strong analytical thinking and clear communication to solve complex security challenges. Stays ahead by actively applying emerging AI technologies to security operations — not as an experiment, but as a standard part of how the work gets done.
// INCIDENT RECORD
Security Operations Engineer
Beyond Finance
·
Chicago, IL (Hybrid)
·
July 2025 – Present
- FINDING: Leads daily DLP incident response as primary analyst and incident commander — coordinates 25+ analyst triage reviews across DLP, UAM, SIEM, EDR, PAM, email security, and endpoint resilience platforms
- FINDING: Produces weekly and monthly DLP executive reports for leadership — distilling every incident into clear, risk-prioritized summaries
- FINDING: Cut report drafting from 60–90 min to <10 min by automating end-to-end DLP report generation with AI — 300+ reports, recovering an estimated 150–200+ analyst hours/month
- FINDING: Engineered DLP-specific AI agentic agents and /skill prompts for real-time DLP user activity reviews, automated SIEM log analysis, automated UAM footage review timelines, and several browser-based investigation skills that self-improve upon each output
- FINDING: Created an Analyst Action Hub in an AI agent workspace — a daily dashboard analysts work from to check off daily review tasks, pull ticket requests, and log completions; serves as a live monitor for the entire DLP program, providing visibility to VPs and executives
-
CRITICAL: Eliminated unauthorized post-termination device access in a cloud-based environment across 1,500+ terminations and counting by architecting the Dead Man Switch (DMS) — a multi-layer offboarding lockdown system built following a P0-Critical incident
Layer 1 — Firmware-Level OS Freeze: auto-bricks offline devices after 30 days via embedded offline timer. Automated 7-day and 24-hour device warning emails so users are never caught off guard.
Layer 2 — Cached credential clearing via RMM + MDM heartbeat scripts (3–5 day inactivity, by job title). Seamless login resumes after the heartbeat syncs with the directory.
Layer 3 — 20+ additional blocking controls and monitors across DLP, UAM, and SIEM platforms to detect any post-termination activity across high-turnover users.
- FINDING: Owns High Risk User Monitoring (HRUM) — PIPs, suspected IP theft, disgruntled employees, anomalous behavior; drafted and implemented entry/exit reviews spanning weeks to months to monitor risky users
- FINDING: Surfaced 80,000+ GB of stale data risk across 4,500+ devices via custom Mac/Windows discovery scripts; drove automated deletion pipeline with tiered rules per department — measurably reducing attack surface from large local file depositories
- FINDING: Authored official incident playbooks, escalation procedures, incident report structure, and overall incident response plan covering a full range of security incident types
- FINDING: Data custodian for legal/HR — e-discovery across enterprise vault, BI, UAM, DLP, and legal review platforms; compliance with NIST CSF, ISO 27001, GDPR, PCI-DSS, HIPAA, SOX, SOC 2
Cybersecurity Analyst
Exelon Corporation
·
Chicago, IL
·
2023 – 2025
- FINDING: Investigated security incidents using Splunk, CyberArk, and Carbon Black for threat detection, log analysis, and incident response
- FINDING: Assisted in deploying security tooling to 1,500+ endpoints across Linux RHEL 7/8, Windows Server 2016–22, and EMS environments
- FINDING: Developed Splunk SPL queries and dashboards for real-time endpoint activity monitoring; optimized Carbon Black detection policies
- FINDING: Managed privileged access via CyberArk; identity-based NAC via Aruba ClearPass; NERC CIP compliance
- FINDING: Authored SOPs, incident handling workflows, and troubleshooting guides for cross-team knowledge sharing
// AGENT OPERATIONS
Scroll to drive a simulated DLP incident through the agentic pipeline I built and run in production.
All incident data below is synthetic.
TRIAGE AGENT
risk scoring
ACTIVITY REVIEW
24h footage review
LOG & TIMELINE
full timeline build
REPORT GEN
exec-ready draft
DLP INCIDENT REPORT
DLP-2026-0609 · SEVERITY: HIGH
DRAFT TIME9:47 min
HUMAN CORRECTIONS0
EVIDENCE ARTIFACTS14
STATUSREADY FOR ESCALATION
AGENT-DRAFTED
SCRIBEDEPLOYED
End-to-end DLP report generation. Drafts weekly & monthly executive reports from raw incident data.
TRIGGERincident closure · report cadence
STACKAI agent · DLP · SIEM
300+ reports · 60–90 min → <10 min
OVERWATCHDEPLOYED
Real-time user activity reviews — pulls, correlates, and summarizes 24h windows of DLP activity and UAM footage on demand.
TRIGGERDLP escalation · HRUM review
STACKAI /skills · DLP API
25+ analyst reviews coordinated daily
SIFTDEPLOYED
Automated SIEM log analysis — auth events, endpoint signals, and anomaly correlation without manual query spelunking.
TRIGGERincident investigation
STACKAI agent · SIEM · SOAR
Minutes per query, not hours
REWINDDEPLOYED
Feeds emails, UAM footage timelines, and log data into a timeline agent that builds a full incident timeline report — investigator-ready chronology.
TRIGGERactivity review escalation
STACKUAM · SIEM · AI timeline agent
Full timeline reports in one pass
SPECTERSELF-IMPROVING
Browser-based investigation skills that critique and refine their own outputs after every run.
TRIGGERnovel investigation patterns
STACKAI skills · browser automation
Improves with every investigation
ACTION HUBLIVE MONITOR
Daily analyst dashboard in an AI agent workspace — task check-offs, ticket pulls, completion logging, and program-wide visibility for VPs.
TRIGGERalways on
STACKAI agent workspace
One pane of glass for the DLP program
// CREDENTIALS
B.S.
Cybersecurity
Bellevue University
GPA: 4.0 · 2023 · NSA-Recognized
Network Security · Access Control & PKI · Risk Assessments & Audits · Database Security · Operational Security · Web App Security (OWASP) · Digital Forensics · Penetration Testing · Incident Response · Python
A.S.
Cybersecurity
Joliet Junior College
2021
Networking · OSINT · Cryptography · Password Cracking · Log Analysis · Network Traffic Analysis · Scanning & Reconnaissance · Forensics · Web App Exploitation · Enumeration · CCNA
CERT
Certificate of Achievement
Joliet Junior College
35 Credit Hours · 2021
CCNA Security · Ethical Hacking · Computer & Network Security · Computer Forensics · Cryptography & Access Control
COMPLIANCE COVERAGE
NIST CSFISO 27001NERC CIPGDPR
PCI-DSSHIPAASOXSOC 2
FISMAOWASP