About

I lead detection and investigation quality for a global security operations center at Dow, in Michigan. Most of my attention goes upstream of the alert queue — to which detections we trust, which controls hold, and what can be automated safely enough to run unattended.

That emphasis came from the response side of the job. Enough incidents in, the interesting question stops being what happened and becomes what the incident says about the system: which detection missed it, which control was incomplete, which procedure was ambiguous enough that two analysts read it differently. Answering that during the incident resolves one incident. Writing the answer down — as a rule with review criteria, a playbook, an exception anyone can apply without asking — is the version that helps the next one.

Where the habits came from

Before security, I spent a decade in Dow’s legal department — legal holds, eDiscovery, chain of custody, access reviews, and the migrations that move sensitive litigation data from one system to another without losing any of it. The question in that work was rarely whether something functioned. It was whether it could be defended afterwards: who had access, when it was last reviewed, how the data moved, and what evidence exists that it moved correctly.

That is the standard I brought with me in 2021, and it is still the one I work to. It is why I would rather a detection rule have documented review criteria than a good reputation, why an automation exception should be a written condition instead of something the team simply knows, and why I try to keep what has been verified separate from what is still inference. I came to security in the middle of a career rather than at the start of one. The way I build things shows it.

Contact

Email is the surest way to reach me; LinkedIn also works. I am glad to hear from people hiring, people working on the same problems, and anyone with a question about something written here.