Detection Engineering
- Wazuh SIEM
- Log analysis
- Alert triage
- Custom detection
- Malware analysis
My work covers detection engineering, incident response and infrastructure hardening for environments where downtime has a real cost.
These cases show the problem I faced, what I changed and the result I was able to measure.
A 24/7 server environment had fragmented logging, which made security events slow to find and hard to prioritize.
I centralized the telemetry in Wazuh, tuned noisy detections and defined a consistent process for reviewing alerts.
I traced a staged PowerShell chain through Base64 decoding, RC4 decryption, in-memory execution, Assembly.Load and Reflection.
I recovered the embedded PE, recorded its SHA1 indicators, checked the file structure and reviewed strings associated with credential theft.
Security Operations Platform
I built Wild Boar to keep incidents, audits, risks, pentest findings and supporting evidence in one Django application.
I built this production backup path to store Proxmox VM backups on a Windows Server NFS repository and make restores easy to verify.
I use this lab to test Wazuh decoders and rules against simulated activity before considering them for production.
I developed a NIST-aligned incident response plan for mixed Windows and Linux environments, covering reporting, triage, containment, recovery and post-incident review.
I designed and carried out risk assessments, control reviews and remediation follow-up to turn technical exposure into clear priorities for the organization.
I carried out scoped security assessments across identity and wireless environments, validating exposure and turning the evidence into practical remediation work.
IT Security & Systems Specialist
Security operations · infrastructure · Wazuh SIEM · incident response · risk assessment · technical security reviews · security awareness.
Security Analyst
Risk assessment · NIST incident response planning · Ansible hardening · internal penetration testing.