// security & development
Security practitioner,
analyst, and builder.
Working across security operations, detection engineering, compliance, and independent software development. I build the tools, run the investigations, and write about what I find.
About Me
I work across security operations, detection engineering, and compliance, building tools, running investigations, and thinking seriously about the gaps between what detection programs claim to cover and what they actually do.
My background spans SOC operations with hands-on experience in Sentinel, Splunk, and Falcon, GRC and compliance work across SOC 2 and NIST CSF, and independent software development. I write in-depth technical analysis on this site and build everything I can from scratch.
Featured Work
SOC Analyst Lab
Home lab on Debian 13 / KVM with Elastic Stack and a Windows 11 endpoint. Five structured investigations, brute force, LotL reconnaissance, phishing analysis, IOC automation, and detection engineering with full ATT&CK coverage mapping.
View projectCivic Nexus
Independent political insight platform built end-to-end, FastAPI backend, PostgreSQL, Cloudflare edge, privacy-by-design architecture. Live in production.
View project