$ whoami

Cybersecurity professional building practical security solutions that reduce risk, improve visibility, and streamline security operations — across application and product security, IAM/PAM, cloud security, detection engineering, and automation.

Experience spanning application and product security, IAM/PAM, cloud security, detection engineering, vulnerability management, infrastructure as code, container security, and security automation. Hands-on with CyberArk, CrowdStrike, Splunk, Azure, Palo Alto, F5 BIG-IP, Active Directory, Docker, CI/CD pipelines, Linux, Windows, REST APIs, Python, PowerShell, and Bash. I integrate security into cloud infrastructure, IaC deployments, containerized environments, and DevSecOps workflows — identifying configuration risks, securing containers and pipelines, managing secrets, and promoting secure development practices throughout the software lifecycle. Especially interested in AI security and using automation to improve phishing analysis, incident response, compliance reporting, vendor risk monitoring, and security control validation. I enjoy solving complex security challenges, collaborating across technical and business teams, and helping organizations build secure, scalable, and resilient systems.

// selected_work/
[01 · llm-pipeline]
COMPASS — Configuration Assessment Agent
Multi-agent LLM enrichment of CrowdStrike CIS findings against the official benchmark PDF, with human-in-loop approval and automated ServiceNow change tickets.
[02 · erm-platform]
Risk Register
Enterprise risk management with LangGraph agents — intake, scoring, monitoring, mitigation tracking.
[03 · soc-tooling]
Mail IOC Scanner
Microsoft Graph harvesting + VirusTotal / urlscan.io / AbuseIPDB enrichment for shared mailbox triage.
[04 · agent-framework]
Event Planner — CrewAI
Multi-agent event-planning web app on CrewAI, demonstrating agent collaboration patterns outside the COMPASS pipeline.
[05 · identity-sdk]
CyberArk Python SDK
REST API wrapper for CyberArk privileged-access workflows, authored from scratch.
[06 · cloud-security]
Azure Web App Secure Design
Defense-in-depth secure architecture and remediation plan for six critical risk domains on Azure App Service.
[07 · endpoint-automation]
CrowdStrike Falcon Tag Sync
Active Directory ↔ Falcon device-tag reconciliation that drives patching cadence and DLP policy assignment.

Smaller tools and one-off scripts live in /lab.