Security Engineer · Detection & Agentic Automation

I build security systems, and the AI agents that run inside them.

Not dashboards and tickets. Pipelines, playbooks, and agents that do the work, documented so you can see how.

Security system agent online
An agent at the centre of a system, reaching into the nodes around it. agent

Selected Work

Systems I built end to end.

Each one is a writeup: the gap, the design, what it actually does.

How I work.

I work the way detection engineering should: start from the adversary behavior, not the alert. I map what I'm defending against to MITRE ATT&CK, write the detection or the automation to close that specific gap, then prove it fires on the thing it was built for and stays quiet otherwise.

Lately that means handing the repetitive parts to agents. An LLM wired into the SOC's real tools, through MCP, can pull the context an analyst would gather by hand and attach it to the alert before a human ever opens it. The interesting engineering is the plumbing and the guardrails, not the model.

The toolkit.

What I reach for, grouped by where it lives.

Domains 16
Detection EngineeringThreat HuntingSIEMSOAREDRIAMDLPPAMDFIRGRCEmail SecurityCloud SecurityZero TrustAI Agent DesignMCPVulnerability Mgmt
Frameworks 07
MITRE ATT&CKNIST CSF 2.0Zero TrustOWASP Top 10CIS ControlsPCI-DSSCISA SCuBA
Platforms 12
Microsoft SentinelMicrosoft DefenderCrowdStrike FalconEntra IDIntuneMicrosoft PurviewBeyondTrust PRARapid7 InsightIDRCopilot StudioAWSAzureKnowBe4
Languages 06
PythonPowerShellTypeScriptJavaScriptGoGit