Open to remote security engineering, detection and SOC roles

Ryan Williams

Detection Engineering & Cloud Security

I build detections that analysts can trust and keep cloud environments audit-ready. Six-plus years in SOC operations across AWS and Azure, most recently as the primary detection engineer and continuous monitoring lead for a FedRAMP cloud SOC.

Email me LinkedIn GitHub Experience

Looking for: Security Engineer, Detection Engineer, Security Analyst or SOC Analyst roles · Remote · US citizen

87%
reduction in SOC triage volume, from 3,000 to under 400 hours a month, through detection tuning
50+
MITRE ATT&CK-aligned detections built across Splunk, Elastic and Azure Sentinel
8
customer AWS and Azure environments standardized under one detection strategy
Under 4 hours
to prepare FedRAMP audit evidence, down from 3+ days, after automating artifact collection

Projects

VulnAnalyzer

A web tool that turns a raw vulnerability scan export into a ranked answer to "what do we fix first, and what is overdue?" I built it to speed up POA&M management for FedRAMP continuous monitoring.

  • Reads exports from six scanners (Nessus, Qualys, Rapid7, OpenVAS, Wiz, Defender) into one format
  • Adds exploit intelligence: CISA Known Exploited Vulnerabilities, EPSS and NVD
  • Ranks findings by threat, severity, exposure and deadline, and shows the reason for each rank
  • Applies FedRAMP's 2026 rules: likely exploitable, internet-reachable, agency impact and class-based deadlines
  • Compares scans and exports PDF, JSON and OSCAL reports

PythonFastAPIpandasReact

Detections

Detection logic for Splunk, Microsoft Sentinel and Elastic, one file per detection: what it looks for and why, the query for each platform, expected false positives, blind spots, and how to trigger it safely in a lab.

  • Windows and Active Directory: recovery tampering, ransomware behavior, lateral movement, account abuse
  • AWS CloudTrail: disabled logging, root use, missing MFA, credential persistence, exposure
  • Linux: shells spawned by web servers

SPLKQLEQLMITRE ATT&CK

Writing