INITIALIZING SECURE SESSION
OPS · SEC · AI

Griffin
Dutka

Security Operations Engineer
ANALYST STATUS: ONLINE
dlp_monitor.log
SCROLL TO INVESTIGATE
// PROFILE

Security Operations Engineer with deep expertise in DLP, AI-driven security automation, SOC agentics, endpoint security, and incident response across large-scale enterprise environments. Experienced operating across on-prem and cloud/SaaS platforms, with a track record of designing and implementing security programs that reduce risk, improve response times, and scale across the organization.

Current work spans DLP investigation and escalation frameworks, AI-powered automation pipelines, SOC agentics, security policy creation and enforcement, and fleet-wide security initiatives including device lifecycle management and enterprise data governance programs. Brings a full-stack perspective from detection engineering and behavioral analysis to cross-functional collaboration with HR, Legal, and executive leadership.

Prior experience in critical infrastructure security includes on-prem deployment and administration of Splunk, CyberArk, Carbon Black, and Aruba ClearPass across Linux RHEL and Windows Server environments, with compliance alignment to NERC CIP, NIST, and additional regulatory frameworks.

Combines technical depth with strong analytical thinking and clear communication to solve complex security challenges. Stays ahead by actively applying emerging AI technologies to security operations — not as an experiment, but as a standard part of how the work gets done.

// INCIDENT RECORD
CASE #001
ACTIVE
Security Operations Engineer
Beyond Finance · Chicago, IL (Hybrid) · July 2025 – Present
CASE #002
CLOSED
Cybersecurity Analyst
Exelon Corporation · Chicago, IL · 2023 – 2025
// LIVE TELEMETRY
0+
Terminations Secured
Zero unauthorized post-termination access
0+
AI-Generated Reports
Drafted in <10 min each, down from 60–90
0h+
Analyst Hours Recovered
Per month via AI automation pipelines & SOC/DLP agentics
0GB+
Stale Data Surfaced
Across 4,500+ endpoints · automated deletion via custom Mac/Windows scripts
<0%
Human Correction Rate
On AI-generated reports
0+
Security Controls
Implemented to reduce company risk factors
// AGENT OPERATIONS
Scroll to drive a simulated DLP incident through the agentic pipeline I built and run in production. All incident data below is synthetic.
ALERT INGEST
DLP sensor
TRIAGE AGENT
risk scoring
ACTIVITY REVIEW
24h footage review
LOG & TIMELINE
full timeline build
REPORT GEN
exec-ready draft
agent_pipeline.log — incident DLP-2026-0609
DLP INCIDENT REPORT
DLP-2026-0609 · SEVERITY: HIGH
DRAFT TIME9:47 min
HUMAN CORRECTIONS0
EVIDENCE ARTIFACTS14
STATUSREADY FOR ESCALATION
AGENT-DRAFTED
SCRIBEDEPLOYED
End-to-end DLP report generation. Drafts weekly & monthly executive reports from raw incident data.
TRIGGERincident closure · report cadence
STACKAI agent · DLP · SIEM
300+ reports · 60–90 min → <10 min
OVERWATCHDEPLOYED
Real-time user activity reviews — pulls, correlates, and summarizes 24h windows of DLP activity and UAM footage on demand.
TRIGGERDLP escalation · HRUM review
STACKAI /skills · DLP API
25+ analyst reviews coordinated daily
SIFTDEPLOYED
Automated SIEM log analysis — auth events, endpoint signals, and anomaly correlation without manual query spelunking.
TRIGGERincident investigation
STACKAI agent · SIEM · SOAR
Minutes per query, not hours
REWINDDEPLOYED
Feeds emails, UAM footage timelines, and log data into a timeline agent that builds a full incident timeline report — investigator-ready chronology.
TRIGGERactivity review escalation
STACKUAM · SIEM · AI timeline agent
Full timeline reports in one pass
SPECTERSELF-IMPROVING
Browser-based investigation skills that critique and refine their own outputs after every run.
TRIGGERnovel investigation patterns
STACKAI skills · browser automation
Improves with every investigation
ACTION HUBLIVE MONITOR
Daily analyst dashboard in an AI agent workspace — task check-offs, ticket pulls, completion logging, and program-wide visibility for VPs.
TRIGGERalways on
STACKAI agent workspace
One pane of glass for the DLP program
// CREDENTIALS
B.S.
Cybersecurity
Bellevue University
GPA: 4.0 · 2023 · NSA-Recognized
Network Security · Access Control & PKI · Risk Assessments & Audits · Database Security · Operational Security · Web App Security (OWASP) · Digital Forensics · Penetration Testing · Incident Response · Python
A.S.
Cybersecurity
Joliet Junior College
2021
Networking · OSINT · Cryptography · Password Cracking · Log Analysis · Network Traffic Analysis · Scanning & Reconnaissance · Forensics · Web App Exploitation · Enumeration · CCNA
CERT
Certificate of Achievement
Joliet Junior College
35 Credit Hours · 2021
CCNA Security · Ethical Hacking · Computer & Network Security · Computer Forensics · Cryptography & Access Control
COMPLIANCE COVERAGE
NIST CSFISO 27001NERC CIPGDPR PCI-DSSHIPAASOXSOC 2 FISMAOWASP
// OFF THE CLOCK
Griffin Dutka

I grew up getting into so much trouble with my curiosity, but that same curiosity is what pulled me into computers, and then into security.

This site is part of that, too. I built it from scratch, mostly to find out whether I could. Turns out, yes I can. I have been improving my AI/LLM skillset both in my personal and work life.

AFK, you'll usually find me out on ripping walks with my dog, deep in a new PC build or game, or surfing Facebook Marketplace. I'm an Acura fan through and through and that obsession with keeping them spotless molded into my own auto-detailing company (@dondetails) that has been going for 6 years now. I live downtown in Chicago's West Loop and love hanging out with friends and trying new restaurants. If you made it this far, let me put you on ball — go to Rootstock in Humboldt Park for the BEST burger.

// OPEN CHANNEL
LOCATION Chicago, IL
DOWNLOAD_RESUME.PDF PDF EMAIL_ME