Capabilities

Scoped security engineering, not inflated service claims.

I am open to technical roles, collaborations, and carefully scoped pilot work where the environment, authorization, deliverables, and success criteria are explicit.

SOC & SIEM Engineering

Wazuh-centered monitoring architecture, ingestion, tuning, detection workflows, and evidence-oriented reporting.

SOAR Workflow Design

Controlled triage, enrichment, case handling, and human-approved response with safe defaults.

Security Automation

Python, FastAPI, Docker, queues, data stores, and observability for repeatable security operations.

Security Assessment

Authorized lab and application assessment with reproducible evidence, risk explanation, and mitigations.

Security Architecture

Bounded designs for SMB environments, including assumptions, failure modes, privacy, and operational constraints.

Documentation & Handover

Architecture maps, runbooks, maturity statements, evidence packages, and implementation-ready handoffs.

Engagement gate

Required before work starts

  1. Explicit authorization and target ownership.
  2. Defined scope and excluded systems.
  3. Agreed deliverables and acceptance criteria.
  4. Safe test environment and rollback plan.
  5. No unsupported production, SLA, or compliance claims.