Experience
Sep 2025 - Present
3 months
- Analyzed malware families targeting AI/edge workloads; summarized TTPs and persistence techniques.
- Drafted concise intel briefs with IoCs, MITRE ATT&CK mapping, and host/network detection notes.
- Prototyped Python scripts to normalize telemetry and surface behavior-based indicators.
Jun 2025 - Aug 2025
3 months
- Created small reverse-engineering labs using Ghidra/x64dbg to practice unpacking and API tracing.
- Wrote short guidance notes translating technical behaviors into practical detection tips for learners.
Apr 2025 - May 2025
2 months
- Analyzed malware families targeting AI/edge workloads; summarized TTPs and persistence techniques.
- Drafted concise intel briefs with IoCs, MITRE ATT&CK mapping, and host/network detection notes.
- Prototyped Python scripts to normalize telemetry and surface behavior-based indicators.
Mar 2024 - Jun 2025
1 year 4 months
- Tuned IDS/IPS and WAF rulesets; authored Sigma/YARA where suitable for targeted detections.
- Supported incident investigations by correlating EDR, NetFlow, and proxy logs to identify activity.
- Helped roll out SSO/2FA and documented playbooks for common response actions.
Mar 2024 - Jul 2024
5 months
- Led hands-on sessions on traffic analysis and basic reversing; reviewed reports for clarity and impact.
Jul 2023 - Present
2 years 5 months
- Investigated intrusion vectors and documented findings with reproducible PoCs and clear mitigations.
- Performed malware triage on samples from engagements (static/dynamic), extracting IoCs and behavior.
- Built Python helpers for log parsing and YARA-based hunting to speed up follow-up analysis.
May 2023 - Feb 2024
10 months
- Ran controlled attack simulations; captured host/network traces to refine detections and alerts.
- Authored concise after-action reports with mitigation steps prioritized by effort vs. impact.
- Assisted Tier-1/2 triage with artifact extraction and rapid IoC enrichment.
Nov 2022 - May 2023
7 months
- Assessed security controls and documented gaps; proposed practical hardening measures.
- Helped establish a lightweight vulnerability management routine with clear ownership.
Mar 2022 - Dec 2022
10 months
- Assisted with security reviews and produced short notes for engineers on observed misconfigurations.