Analyst
Cybersecurity Analyst: Threat Hunting & Detection Engineering
Contact
Open to threat hunting, detection engineering and DCO roles
Six years hunting adversaries on DoD and mission-partner networks: Hunt Forward Operations and Cyber Protection Team work in direct support of the Cyber National Mission Force.
Packet, flow and protocol analysis by hand. Suricata, Sigma and YARA content written from what the hunt turned up. Analysts trained and qualified behind me.
Mission data
Feb 2025toJul 2026
NIOC Pensacola, FL
CWT2
Oct 2023toFeb 2025
NIOC Hawaii / CNMF, Wahiawa, HI
CWT2
Oct 2019toOct 2023
NIOC Hawaii, Wahiawa, HI
CTN3
| Category | Used on mission |
|---|---|
| Network security monitoring | Suricata · Zeek · Security Onion sensor tuning · Arkime · Wireshark and tshark · tcpdump · NetworkMiner · full packet capture · NetFlow and flow analysis · protocol analysis |
| SIEM and detection engineering | Microsoft Sentinel (KQL) · Splunk (SPL) · Elastic and ELK (KQL, EQL, Lucene) · Sigma · YARA · use-case development · alert tuning and false-positive reduction · ATT&CK coverage mapping |
| Endpoint and forensics | Defender for Endpoint and XDR · Cisco Secure Endpoint · Elastic Agent · Sysmon · Windows and Linux triage · baselining · Volatility · FTK Imager · Autopsy · timeline and anti-forensic analysis |
| Malware analysis | Static and dynamic analysis · x64dbg and x32dbg · CFF Explorer · FLARE VM · REMnux · sandbox detonation with snapshot comparison · persistence and C2 identification · IOC extraction |
| Threat intelligence | MITRE ATT&CK mapping · Cyber Kill Chain · Diamond Model · IOC development and enrichment · pivoting · adversary infrastructure tracking · actor profiling |
| Vulnerability and architecture | ACAS (Nessus) · RedSeal exposure-path mapping · discovery and validation · firewall, router and switch configuration review · remediation prioritized by operational risk |
| Automation | Python · PowerShell · BASH · Terraform · Ansible · Docker · Kubernetes · Git and CI/CD |
| Frameworks and identity | NIST 800-53 · NIST CSF · RMF · CMMC · Zero Trust · Entra ID and on-premises Active Directory · AWS and Google Cloud · LAN, WAN, VPN, switching and routing |
A weekly cyber threat-intelligence briefing with a real subscriber list. Scheduled research jobs correlate primary sources into a vetted intel database, and a QA gate fails any draft carrying a CVE ID that database cannot verify. Reading the industry every week, in public.
Where detection ideas get tried before they meet a real network: build the telemetry, generate the activity, write the rule, then find out whether it fires on anything that matters.
A shipped macOS and iOS app that reads and writes a Fujifilm camera's custom setting banks over USB, with per-field read-back verification. Protocol work for fun instead of for evidence.
A Mac dictation tool that makes zero network calls by design; an iOS app that keeps credentials on the phone; a browser text adventure with fifty rooms and nine endings.