Open to remote security engineering, detection and SOC roles
Ryan Williams
Detection Engineering & Cloud Security
I build detections that analysts can trust and keep cloud environments audit-ready. Six-plus years in SOC operations across AWS and Azure, most recently as the primary detection engineer and continuous monitoring lead for a FedRAMP cloud SOC.
Email me LinkedIn GitHub Experience
Looking for: Security Engineer, Detection Engineer, Security Analyst or SOC Analyst roles · Remote · US citizen
- 87%
- reduction in SOC triage volume, from 3,000 to under 400 hours a month, through detection tuning
- 50+
- MITRE ATT&CK-aligned detections built across Splunk, Elastic and Azure Sentinel
- 8
- customer AWS and Azure environments standardized under one detection strategy
- Under 4 hours
- to prepare FedRAMP audit evidence, down from 3+ days, after automating artifact collection
Projects
VulnAnalyzer
A web tool that turns a raw vulnerability scan export into a ranked answer to "what do we fix first, and what is overdue?" I built it to speed up POA&M management for FedRAMP continuous monitoring.
- Reads exports from six scanners (Nessus, Qualys, Rapid7, OpenVAS, Wiz, Defender) into one format
- Adds exploit intelligence: CISA Known Exploited Vulnerabilities, EPSS and NVD
- Ranks findings by threat, severity, exposure and deadline, and shows the reason for each rank
- Applies FedRAMP's 2026 rules: likely exploitable, internet-reachable, agency impact and class-based deadlines
- Compares scans and exports PDF, JSON and OSCAL reports
How the 2026 evaluation works Source on GitHub Earlier desktop version
Detections
Detection logic for Splunk, Microsoft Sentinel and Elastic, one file per detection: what it looks for and why, the query for each platform, expected false positives, blind spots, and how to trigger it safely in a lab.
- Windows and Active Directory: recovery tampering, ransomware behavior, lateral movement, account abuse
- AWS CloudTrail: disabled logging, root use, missing MFA, credential persistence, exposure
- Linux: shells spawned by web servers
Writing
-
FedRAMP 2026 vulnerability deadlines, worked through a real scan
Severity-based deadlines are gone. How the new exploitability, reachability and impact evaluation changes what is due when, and how I built a first pass of it into VulnAnalyzer.
-
Five CloudTrail detections to deploy first
Logging tampering, root use, console logins without MFA, credentials created for someone else, and resources opened to the internet. Splunk and Sentinel queries with tuning notes.
-
Catching shadow copy deletion before the encryption starts
One detection for vssadmin, wmic, wbadmin, bcdedit and PowerShell recovery tampering (T1490), written for Splunk, Sentinel and Elastic.
-
Detecting ransomware encryption by behavior, not file extension
Why extension watchlists fail, and two behavioral detections that hold up: mass renames that collapse many file types into one, and the same note dropped in every folder.
-
AD account deletion: turning event 4726 into a useful alert
Alerting on every deletion is noise. Three variants that carry signal: who deleted what, bulk deletion, and accounts created and deleted within a day.
-
FedRAMP's 2026 rules: what changes for continuous monitoring
POA&Ms are gone, ConMon is now Ongoing Certification, and impact levels became classes. A summary of the Consolidated Rules for 2026 and the dates that matter.
-
One-liners for triage
Short Python, Bash and PowerShell snippets for hashing, pulling URLs, checking listeners, startup items and AD password expiry.
-
What makes a SOC analyst stand out
Six habits that separate analysts who close alerts from analysts who improve the SOC.