Resume
In enterprise cyber defense since 2021, after a decade in legal and compliance operations — both at Dow, in Michigan. My focus now is upstream of response: detection lifecycle governance, control design, and automation, so that fewer incidents need an incident commander.
Experience
Cyber Defense Specialist — Monitoring & Detection Lead
- Detection and investigation quality lead for a global security operations center supporting a large manufacturing enterprise.
- Designed and now run a phased lifecycle-review program for an enterprise detection library of several hundred KQL rules — review criteria, alignment tagging, deployment-suitability outcomes, remediation-effort sizing, documentation standards, scheduling, and remediation handoffs. Phase-level metrics feed backlog planning and rule trust; recommendations to retire a rule go to leadership for decision rather than being actioned unilaterally.
- Develop and tune detections in Microsoft Sentinel and Defender XDR across identity, endpoint, and cloud telemetry, retuning analytics rules with sharper exception criteria to reduce false positives without giving up meaningful coverage.
- Worked with the SOC team to implement automated device isolation on high-severity detections, with an exemption mechanism that keeps critical manufacturing and business systems out of scope and monitor-only rule variants that preserve high-severity alerting where automatic containment is not acceptable.
- Serve as incident commander for high-severity events — scoping, containment decisions, coordination across endpoint, identity, cloud, business, and security teams, and leadership-ready updates while the incident is still moving. Contained an identity compromise within the hour through credential reset and token revocation.
- Conduct advanced investigations across endpoint, identity, email, and cloud telemetry in Sentinel, Defender XDR, and Entra ID — including business email compromise and email-based vendor fraud — to scope and remediate complex threats.
- Co-authored and maintain the SOC’s incident response playbooks, mapped to MITRE ATT&CK tactics, and its analyst knowledge base — the standards that keep a distributed team consistent.
- Designed a standardized incident record format to improve data consistency and support stronger reporting, process maturity, and later analytics.
- Led a small investigations-quality team, using ticket auditing, trend analysis, and quality metrics reported to leadership to raise investigation standards.
- Mentor junior analysts and apprentices in investigative method, KQL, and threat analysis, and upskilled analysts in other time zones to take top-severity incidents — widening after-hours coverage and measurably reducing reliance on the on-call responder.
- Co-lead a recurring cyber briefing for IT leadership, translating incidents, threat trends, and operational findings into guidance that can be acted on.
- Built a lab environment to reproduce attack techniques, examine hostile infrastructure safely, and validate investigative tooling.
Internal Audit Rotation
- Reviewed Microsoft 365 Copilot access and security configuration against NIST 800-53 AC-3 and AC-6 expectations, through configuration review, evidence analysis, and stakeholder interviews.
- Documented an access-scope risk found during that review, which fed a formal COSO-aligned management comment and corrective action planning.
- Analyzed a governance gap in decentralized software procurement and proposed mandatory security and data privacy review for higher-risk purchases.
- Independently validated the remediation of a user access management control in a finance-critical application during an ICFR audit cycle, using evidence review, walkthroughs, and stakeholder interviews.
- Assessed a third-party SOC 1 Type II report for a key service provider, evaluating the relevance and effectiveness of vendor controls against internal control expectations tied to financial reporting.
Cyber Defense Analyst
- Managed cybersecurity investigations end to end and joined the rotating on-call schedule within six months, supporting high-severity escalations and major incidents.
- Carried a steady alert and consultation load spanning identity, endpoint, cloud, phishing, and user activity, including regular escalation-level events.
- Standardized KQL investigation and hunting workflows for phishing and identity activity, measurably reducing phishing response time and making triage more repeatable.
- Conducted investigations into phishing, malware, and identity incidents using Defender XDR, Sentinel, Cisco Secure Malware Analytics, and Recorded Future threat intelligence.
- Analyzed emerging QR-code phishing activity, identifying indicators of compromise and adversary techniques that informed improved detection logic and mitigation guidance.
Operations Analyst, Legal Department
- Designed and implemented an automated data preservation workflow integrating Relativity Legal Hold with Microsoft 365 Compliance (now Purview), removing a substantial amount of recurring manual effort while improving defensibility and compliance.
- Co-led a multi-terabyte eDiscovery vendor migration of sensitive litigation data, with chain-of-custody validation, no downtime, and no data loss.
- Led technical onboarding and integration for new eDiscovery and litigation service providers, acting as primary liaison across legal, IT, and vendor teams for secure deployment and operational readiness.
- Mentored legal operations staff on eDiscovery technologies, workflows, and data-handling practices.
Technologist, Legal Department
- Led implementation of a SaaS legal hold platform (RelativityOne), migrating the active legal-hold portfolio through a structured extract, transform, and load strategy.
- Implemented role-based access control and onboarding/offboarding processes for Relativity Legal Hold, supporting eDiscovery and legal-hold operations at enterprise scale.
- Designed and launched a custom Relativity application to centralize the historical eDiscovery collection record, cutting research time from hours to minutes.
- Built and secured a centralized repository for legacy legal hold information, improving accessibility and continuity while maintaining appropriate access controls.
Senior Technician, Legal Department
- Primary technical administrator for the Exterro Fusion legal hold application, owning its full lifecycle: security patching, hotfix deployment, vendor coordination for upgrades, and end-user support.
- Managed the secure migration of the legal-hold portfolio into Exterro Fusion, verifying data integrity and implementing access controls throughout the transition.
- Began leading access reviews for restricted legal file shares in 2015 and continued them through 2021, documenting findings and coordinating least-privilege updates with stakeholders.
- Developed custom reporting for legal hold managers using SQL and Crystal Reports, giving visibility into hold data, custodian status, and compliance metrics.
- Received an internal award for collaborative project excellence, recognizing work on the secure implementation, migration, and maintenance of the Exterro Fusion platform.
Technician, Legal Department
- Supported implementation and configuration of the Exterro Fusion legal hold platform, acting as liaison between the vendor and internal legal stakeholders during rollout.
- Administered the Symantec Clearwell eDiscovery platform — case setup, secure data loading and processing, and user access administration for internal investigations.
- Managed digital evidence and chain-of-custody processes, and developed the supporting workflows.
Education
Bachelor of Applied Science, Cyber Operations
Certifications
- Certified Information Systems Security Professional (CISSP), ISC2
- Prosci Certified Change Practitioner
- Global Industrial Cyber Security Professional (GICSP), GIAC
- Certified Cloud Security Professional (CCSP), ISC2
Capabilities
- Incident response
- Incident command for high-severity events, end to end: scoping, containment decisions, cross-team coordination, and leadership communication while the incident is still moving. Identity compromise response — account takeover, token and session abuse, Entra ID investigation, containment through credential reset, token revocation, and session invalidation. Investigation across endpoint, identity, email, and cloud telemetry, including phishing, malware, QR-code phishing, business email compromise, and email-based vendor fraud.
- Detection engineering
- KQL analytics in Microsoft Sentinel and custom detections in Defender XDR; reusable hunting and investigation queries for phishing and identity activity; tuning and exception design that cuts false positives without narrowing coverage.
- Detection lifecycle governance
- A repeatable review methodology for an enterprise rule library — alignment tagging, deployment-suitability outcomes, remediation-effort sizing, documentation standards, phased scheduling, and phase-level metrics that make backlog planning an argument from evidence rather than instinct.
- Security engineering and automation
- Response automation with the exception logic that makes it safe to run on a manufacturing floor; role-based access control design and implementation; least-privilege remediation; platform integrations that replace manual, error-prone process.
- Governance and audit
- COSO-aligned observations, ICFR control validation, third-party SOC 1 Type II review, evidence analysis, walkthroughs, and stakeholder interviews. Recurring access reviews for restricted file shares, 2015 through 2021, and vendor-risk process improvement.
- Security platforms
- Microsoft Sentinel · Defender XDR · Entra ID · Microsoft 365 and Azure telemetry · Defender for Cloud Apps · Microsoft Purview · Zscaler · ServiceNow · Cisco Secure Malware Analytics · Recorded Future
- Frameworks
- MITRE ATT&CK · NIST SP 800-53 access control · COSO · Prosci change management
- Legal technology and data
- Relativity and RelativityOne · Exterro Fusion · Symantec Clearwell · SQL · Crystal Reports