Open to remote security engineering, detection and SOC roles

Ryan Williams

Detection Engineering & Cloud Security

I build detections that analysts can trust and keep cloud environments audit-ready. Six-plus years in SOC operations across AWS and Azure, most recently as the primary detection engineer and continuous monitoring lead for a FedRAMP High cloud SOC. US citizen, eligible for Public Trust and security clearance.

Email me LinkedIn GitHub Experience

87%
reduction in SOC triage volume, from 3,000 to under 400 hours a month, through detection tuning
50+
MITRE ATT&CK-aligned detections built across Splunk, Elastic and Microsoft Sentinel
8
customer AWS and Azure environments standardized under one detection strategy
Under 4 hours
to prepare FedRAMP audit evidence, down from 3+ days, after automating artifact collection

Projects

Detections

Detection logic for Splunk, Microsoft Sentinel and Elastic, one file per detection: what it looks for and why, the query for each platform, expected false positives, blind spots, and how to trigger it safely in a lab.

  • Windows and Active Directory: recovery tampering, ransomware behavior, lateral movement, account abuse
  • AWS CloudTrail: disabled logging, root use, missing MFA, credential persistence, exposure
  • Linux: shells spawned by web servers

SPLKQLEQLMITRE ATT&CK

Writing