About

I'm a detection engineering and cloud security professional with ten years in IT and infrastructure engineering and more than six in SOC operations. My work sits where detection engineering, cloud security monitoring and FedRAMP meet: writing detections for AWS and Azure, tuning them until the alerts are worth an analyst's time, and keeping the evidence trail audit-ready.

Most recently I was the Information System Security Manager and primary detection engineering and continuous monitoring analyst for a FedRAMP cloud SOC. I helped take the program from FedRAMP Moderate to High and from an effectively single-analyst operation to a structured, multi-analyst team.

I'm a US citizen based in Michigan, and I'm looking for a remote Security Engineer, Detection Engineer, Security Analyst or SOC Analyst role. Get in touch.

Experience

CGC / Merlin Cyber

December 2024 – September 2026 · Remote

  • Information System Security Manager (ISSM)
  • SOC Analyst T2, Detection Engineering & FedRAMP Continuous Monitoring
  • SOC Analyst T1, Detection Engineering & FedRAMP Continuous Monitoring
  • Owned the FedRAMP continuous monitoring lifecycle end to end: creating, evaluating and submitting monthly packages, and deciding remediation status, risk categorization and POA&M disposition for vulnerability findings.
  • Owned the SIEM detection lifecycle, improving alert fidelity and reducing false positives as coverage grew.
  • Designed a cross-environment AWS and Azure detection strategy that standardized alerting across 8 customer cloud environments.
  • Built cloud log ingestion health checks to stabilize monitoring across tenants.
  • Drove the transition from the FedRAMP Moderate to High baseline, with the added controls and detection coverage that NIST SP 800-53 requires.
  • Automated vulnerability management and POA&M workflows, cutting review cycles from days to hours.
  • Interviewed, evaluated and onboarded SOC analysts, and turned solo institutional knowledge into documented, hand-off-ready workflows.

Blarney Castle Oil Co.

July 2024 – December 2024 · Bear Lake, MI

  • IT Analyst
  • Monitored SIEM, EDR and antivirus alerts and coordinated incident response with MSSPs.
  • Developed a transition plan to bring SOC operations in-house.
  • Automated operational workflows with PowerShell, Python and SQL.

Anitian

October 2020 – March 2024 · Remote

  • Security & Compliance Analyst
  • Security Operations Analyst
  • Junior Security Operations Analyst
  • Led detection optimization that cut team triage volume from 3,000 to under 400 hours per month, an 87% reduction, while maintaining coverage across cloud and hybrid environments.
  • Created 50+ MITRE ATT&CK-aligned detections, dashboards and alerting logic across Splunk, ELK and Azure Sentinel.
  • Led incident investigations and proactive threat hunting across 30+ customer environments.
  • Served as FedRAMP Moderate continuous monitoring SME, guiding multiple clients through 3PAO assessments, artifact collection and evidence reviews.
  • Automated FedRAMP artifact collection and compliance reporting, reducing preparation from 3+ days to under 4 hours.
  • Mentored junior and mid-level analysts and wrote standardized SOPs and IR playbooks.

Gordon Food Service

August 2017 – June 2020 · Wyoming, MI

  • Associate Security Analyst
  • Intermediate Client Administration Specialist
  • Primary SOC analyst for a 22,000-employee international environment, investigating and remediating threats with Elastic SIEM and CrowdStrike Falcon.
  • Delivered major findings during a ransomware incident, identifying malicious activity that had initially evaded IBM X-Force IRIS.
  • Led the enterprise-wide removal of local administrator rights across 20,000+ users.
  • Managed the enterprise Windows environment and evaluated EDR tooling from the endpoint administration side.

Earlier IT and infrastructure roles

2010 – 2017

  • IT Specialist at Kalamazoo County State Bank, IT Coordinator at St. Michael Lutheran Church & School, and IT Technical Assistant at Mid Michigan College.
  • Administered Windows and Linux systems, Active Directory and core network services, including in a regulated banking environment.

Skills

Detection and monitoring
Detection engineering, alert design and tuning, Splunk, Azure Sentinel, Elastic, MITRE ATT&CK mapping, threat hunting, incident response
Cloud security
AWS (CloudTrail, GuardDuty, Security Hub, IAM), Azure (Sentinel, Log Analytics, IAM)
Governance, risk and compliance
FedRAMP Moderate and High, continuous monitoring, NIST SP 800-53, POA&M management, vulnerability management, 3PAO audit support
Tooling and automation
CrowdStrike Falcon, Wiz, Tenable Nessus, Python, PowerShell, Bash, SQL, API integrations, LLM-assisted detection development

Certification and education