Open to remote security engineering, detection and SOC roles
Ryan Williams
Detection Engineering & Cloud Security
I build detections that analysts can trust and keep cloud environments audit-ready. Six-plus years in SOC operations across AWS and Azure, most recently as the primary detection engineer and continuous monitoring lead for a FedRAMP High cloud SOC. US citizen, eligible for Public Trust and security clearance.
- 87%
- reduction in SOC triage volume, from 3,000 to under 400 hours a month, through detection tuning
- 50+
- MITRE ATT&CK-aligned detections built across Splunk, Elastic and Microsoft Sentinel
- 8
- customer AWS and Azure environments standardized under one detection strategy
- Under 4 hours
- to prepare FedRAMP audit evidence, down from 3+ days, after automating artifact collection
Projects
VulnAnalyzer
A web tool that turns a raw vulnerability scan export into a ranked answer to "what do we fix first, and what is overdue?" I built it to speed up POA&M management for FedRAMP continuous monitoring.
- Reads exports from six scanners (Nessus, Qualys, Rapid7, OpenVAS, Wiz, Defender) into one format
- Adds exploit intelligence: CISA Known Exploited Vulnerabilities, EPSS and NVD
- Ranks findings by threat, severity, exposure and deadline, and shows the reason for each rank
- Applies FedRAMP's 2026 rules: likely exploitable, internet-reachable, agency impact and class-based deadlines
- Compares scans and exports PDF, JSON and OSCAL reports
How the 2026 evaluation works Source on GitHub Earlier desktop version
Detections
Detection logic for Splunk, Microsoft Sentinel and Elastic, one file per detection: what it looks for and why, the query for each platform, expected false positives, blind spots, and how to trigger it safely in a lab.
- Windows and Active Directory: recovery tampering, ransomware behavior, lateral movement, account abuse
- AWS CloudTrail: disabled logging, root use, missing MFA, credential persistence, exposure
- Linux: shells spawned by web servers
Writing
-
Cutting SOC triage from 3,000 hours a month to under 400
Measuring analyst time instead of alert count, asking one question of every noisy rule, and keeping ATT&CK coverage intact while cutting 87% of triage hours.
-
Every 17 minutes: finding the foothold a ransomware investigation missed
An REvil incident where the outside responders confirmed ransomware but not the way in. A beacon on a fixed interval led to the scheduled tasks and the stale domain admin account behind it.
-
FedRAMP 2026 vulnerability deadlines, worked through an example scan
Severity-based deadlines are gone. How the new exploitability, reachability and impact evaluation changes what is due when, and how I built a first pass of it into VulnAnalyzer.
-
Five Entra ID detections to deploy first
Privileged role assignments, MFA methods registered from unfamiliar addresses, risky app consent, Conditional Access changes and credentials added to applications. Sentinel and Splunk queries with tuning notes.
-
Five CloudTrail detections to deploy first
Logging tampering, root use, console logins without MFA, credentials created for someone else, and resources opened to the internet. Splunk queries with tuning notes, plus Sentinel for the logging alert.
-
Catching shadow copy deletion before the encryption starts
One detection for vssadmin, wmic, wbadmin, bcdedit and PowerShell recovery tampering (T1490), written for Splunk, Sentinel and Elastic.
-
Detecting ransomware encryption by behavior, not file extension
Why extension watchlists fail, and three detections that hold up: mass renames that collapse many file types into one, the same note dropped in every folder, and a canary file.
-
AD account deletion: turning event 4726 into a useful alert
Alerting on every deletion is noise. Three variants that carry signal: deletions by an unexpected admin, bulk deletion, and accounts created and deleted within a day.
-
FedRAMP's 2026 rules: what changes for continuous monitoring
POA&Ms are gone, ConMon is now Ongoing Certification, and impact levels became classes. A summary of the Consolidated Rules for 2026 and the dates that matter.
-
One-liners for triage
Short Python, Bash and PowerShell snippets for hashing, pulling URLs, checking listeners, startup items and AD password expiry.
-
What makes a SOC analyst stand out
Six habits that separate analysts who close alerts from analysts who improve the SOC.