Cybersecurity Engineer · Building SOCRoot

Practical SOC engineering with clear safety boundaries.

I maintain two independent cybersecurity tracks: Project Synapse, my open-source graduation project combining security engineering with data analytics and scalable architecture; and SOCRoot, a commercial innovation for automatable subscription services with measurable customer value.

Selected work

Evidence before claims

Public artifacts are separated by responsibility so architecture, runtime, control plane, and assessment evidence remain understandable.

Project Synapse

Hybrid SOC graduation project. The academic PSM experiment records 967 events/second sustained throughput, 15.96-second average latency, and 95.9% precision. These figures remain report-backed while the public reproduction package is completed.

Review architecture and evidence →

DVTA Security Assessment

Authorized grey-box lab assessment with 12 confirmed findings, evidence, and remediation guidance.

Open assessment →

Control Plane

Portals, RBAC, evidence workflows, client state, and observability.

Status: private during Git-history security review.

Project Synapse Runtime/POC

Alert ingestion, triage, HITL orchestration, and evidence capture for technical validation.

Status: private during Git-history security review.

SOCRoot Website

Product communication for automatable cybersecurity services intended to earn payment and renewal through clear customer value.

View source →
Engineering rules

Designed to fail safely

  • SOAR_DRY_RUN=true by default; sensitive actions require human approval.
  • CDN and RFC1918 addresses are never automatically blocked.
  • DNS events are NOTIFY_ONLY, never BLOCK_IP.
  • Raw client data is not sent to external AI providers.
  • Production claims require tests, operational evidence, and rollback paths.