AI Security Engineer · Chicago, IL

Catches leaks.
Keeps receipts.

Security Operations Engineer building AI systems and agents that triage, review, and report, with every finding backed by evidence receipts and a human review.

scroll
about my work

Security work, with receipts.

I run DLP incident response and build AI agents that review 6,000+ emails and attachments a day, and show their work.

SummarySecurity Operations Engineer

I build AI agents that securely connect log and data sources for automated reviews with severity context, and I prove they work with a measurement strategy: catch rate against a noise ceiling, evals, and human-in-the-loop review.

DLP Insider risk Incident response E-discovery AI agents Agent orchestration AI governance Evals Human-in-the-loop MCP SIEM Python
Current work2025 → now

Incident commander for daily DLP response at Beyond Finance. I build the escalation frameworks, AI pipelines, playbooks and the fleet-wide initiatives, and I work alongside HR, Legal and exec leadership.

Before2023 → 2025

Critical-infrastructure security at Exelon: deployed Splunk, CyberArk, Carbon Black and Aruba ClearPass to 1,500+ RHEL and Windows Server endpoints, and owned the on-prem servers behind Splunk and CyberArk, under NERC CIP and NIST.

StackDaily drivers
  • DetectionDLP · UAM · SIEM · EDR
  • AccessPAM · NAC · RMM / MDM
  • AutomationAI agents · MCP · evals
  • FrameworksNIST · ISO 27001 · SOC 2
  • CodePython · PowerShell · Bash
(02) receiptsimpact · 2025 → now
6,000+Emails reviewed daily by AI agents, up 12x from 500
15 minDaily triage run, down from roughly 5 hours
300+AI-drafted incident reports, each under 10 minutes
150h+Analyst hours handed back every month
0Company data access after termination
Numbers from the day jobChicago · 2025 → now
ai email review

Trust, but verify. Then securely automate the verifying.

Follow one day of email through the review crew: a code pass, an orchestrator, six specialist reviewers, and a tuning loop that can't change its own rules.

Synthetic run · invented data
01 / 06
01 · Intake

An export lands at 4:52 PM Friday.

50,214 emails sent outside the company today. Every one of them gets read.

02 · Code first

Code goes first. The model goes second.

Plain code parses, filters and redacts first. Duplicates, automated mail, internal business traffic and excluded teams drop out, so the model only sees what it needs.

03 · Fan-out

One orchestrator, six specialists.

Each packet goes to the reviewer that owns its kind of risk: customer data, financial, credentials, HR data, free-mail and quarantined mail.

04 · Review

No silent agents.

All six run in parallel and log every step as it happens, so a stalled or wrong run is visible right away. Every agent reads the same context and severity playbooks from the orchestrator agent at runtime, that way severity calls stay consistent across reviewers.

05 · Report

Three escalations, each with receipts.

Every finding links to its evidence, and an analyst confirms before anything goes out. About 15 minutes, down from roughly 5 hours of daily manual review.

06 · Tuning

Agents propose, people approve.

A tuning agent learns from analyst decisions and call transcripts, then automatically drafts playbook changes. Nothing goes live until an engineer approves it.

RUN-1004 · synthetic data● Running
Hover any step to see what it owns.
    Emails0outbound · 1 day
    Escalated0human sign-off
    Run time0:00Manual: ~5 hours
    the rules it runs on
    01

    Every finding links to its evidence.

    No claim without a link a person can click to verify.

    02

    Agents propose, people approve.

    Tuning changes go through human review before they go live.

    03

    Code first, model second.

    Parsing, filtering and redaction run as plain code, so the model only sees what it needs.

    04

    Least privilege, always.

    Agents read through scoped connectors, and secrets never sit in a prompt.

    05

    No silent agents.

    Every step is logged as it happens, so a stalled or wrong run is visible right away.

    06

    One source of truth.

    Every agent reads the same playbook at runtime, never answering from memory.

    07

    One orchestrator, specialist sub-agents.

    A single run fans out to reviewers that each own one kind of risk.

    08

    Shipped like production code.

    Agent changes go through branches, PRs and review, never straight to main.

    Demo data is synthetic. Every email, name, count and finding above is invented, and the design is generalized from a production system. The scale is real: 6,000+ emails a day, reviewed in about 15 minutes.

    Things I've built

    0123456/06
    agent

    Email Review

    Specialized agents sort outbound mail (personal, free-mail, bounced, quarantined) and add severity context. 500 → 6,000+ a day.

    Live
    agent

    Report Gen

    Drafts the whole DLP incident report. 300+ written, 60–90 minutes down to under 10.

    Deployed
    agents

    Daily Reviews

    A crew of review agents, one per risk group. Each one triages open alerts, then sweeps the activity that never set one off.

    Live
    program

    Offboarding Lockdown

    A multi-layer offboarding system. Every device is locked down, zero company data access after termination.

    Live
    agent

    Risk Profile

    Give it a name and a time window. It checks every signal source, reviews emails, and hands back a risk report with a receipt behind every claim.

    Automated + on demand
    framework

    AI Measurement Framework

    Measure AI review success using catch rate to noise level thresholds from metric outputs written to a shared runlog.

    Live
    Scroll to spinAll agent data shown is synthetic
    Synthetic data
    “The agent reads every alert. The analyst reads the ones that matter.”
    On building the email review agents
    experience

    Where I've done it.

    Beyond Finance
    Security Operations Engineer
    Promoted from Information Security Analyst in nine months.
    2025 → present · Chicago
    • Scaled AI email review 12x, from 500 to 6,000+ emails a day; roughly 5 hours of daily triage became 15-minute runs.
    • Made AI triage safe to act on: catch rate against a noise ceiling, evals on every agent, human-in-the-loop review, and least-privilege API connectors and MCP servers.
    • Run a crew of review agents like production software: evals, evidence links on every finding, logged steps, and changes shipped through reviewed PRs.
    • Built an agentic DLP pipeline: 300+ exec-ready reports, 60–90 minutes down to under 10, and 150–200+ analyst hours back every month.
    • Incident commander for daily DLP response, coordinating 25+ triage reviews across DLP, UAM, SIEM and EDR with HR, Legal and leadership.
    • Drive high-risk user monitoring and e-discovery for Legal and HR.
    Multi-layer offboarding lockdown · zero post-exit access
    Exelon Corporation
    Cybersecurity Analyst
    2023 → 2025 · Chicago
    • Investigated incidents with Splunk, CyberArk and Carbon Black: detection, log analysis and response.
    • Deployed security tooling to 1,500+ endpoints across RHEL and Windows Server.
    • Ran the security applications on-prem and owned the servers behind Splunk and CyberArk.
    • Wrote SPL dashboards for real-time endpoint monitoring and tuned Carbon Black policies.
    • Managed privileged access in CyberArk and NAC in Aruba ClearPass under NERC CIP.
    1,500+ endpoints
    SplunkCyberArkCarbon BlackClearPassNERC CIPNIST
    Bellevue University
    B.S. Cybersecurity · NSA-recognized
    2023
    • Network security, access control and PKI, risk and audits, OWASP web app security.
    • Digital forensics, pen testing, incident response, Python.
    • Before that: A.S. Cybersecurity, Joliet Junior College, 2021.
    4.0GPA
    NIST CSFISO 27001SOC 2PCI-DSSHIPAA
    off the clock

    Curiosity got me into trouble, then into security.

    Away from the keyboard I'm out walking my dog, headbanging at music festivals, deep in a YouTube documentary, or using FB Marketplace as social media. Then I end up right back at the keyboard, gaming.

    I'm a car guy, Acura ride or die. Keeping them spotless turned into my own detailing company, @dondetails, now six years running.

    I live in Chicago's West Loop and I'm always trying new restaurants. Send me your recs, but let me put you on first: Rootstock in Humboldt Park has the best burger in the city.

    Griffin's two dogstrail crew
    An Acura at nightlate cruise
    A custom PC buildlatest build
    Detailing an Acuradetail day
    6 yrs
    detailing
    contact

    If you made it this far, hit me up.

    Always open to a chat about AI security, agents, or whatever you're building.