MDR & SOC Maturation
Helped bring siloed SIEM and managed EDR together into a single MDR practice, moving the SOC from reactive alerting toward proactive detection and response.
Security Architect · CISSP · Tampa, FL
Building security that bends without breaking.
Cybersecurity team lead with 9+ years building and scaling managed security services. I help mature SOCs into proactive MDR practices, work on the design and economics of new services, and pair hands-on, AI-assisted development with secure-by-design practices to ship tooling fast.
I help turn security capabilities into services clients can actually use.
I'm a security architecture and engineering team lead at a managed security provider (MSSP), working as an individual contributor who leads projects. Our team brought siloed SIEM and managed EDR together into a unified MDR offering and moved the SOC from reactive toward proactive. Beyond the architecture, I help with service design, go-to-market, and the economics behind new offerings, like a Dark Web Monitoring service we launched at a 60% margin, working across sales, operations, and leadership to bring them to clients.
I'm also a builder. I ship full-stack internal tooling with Python (FastAPI), Next.js, and Docker, increasingly AI-assisted with LLMs and local models, applying secure-by-design practices like JWT auth, password hashing, and rate limiting. A self-hosting homelab keeps the fundamentals sharp.
If there's a thread through my work, it's a builder's curiosity: I like starting new projects and experimenting with new approaches so we can keep offering clients better services.
Helped bring siloed SIEM and managed EDR together into a single MDR practice, moving the SOC from reactive alerting toward proactive detection and response.
Help design, launch, and run the economics of managed services, like Dark Web Monitoring at a 60% margin, and the go-to-market behind them.
Cross-team SOAR and Python automation that cut manual analysis 50% and drive down operational cost.
Served as incident commander on partner breaches. Helped build playbooks and an AWS IR stack that cut downtime 50%, response time 35%, and ingestion 75%.
CTI tooling, proactive threat hunting, and IOC/TTP analysis, surfacing stolen credentials before they're exploited.
Full-stack internal tooling in FastAPI, Next.js, and Docker, built with LLMs and local models, shipped secure-by-design.
The strongest programs aren't the ones that never get hit; they're the ones built to absorb the hit, recover fast, and come back smarter.
From “Resilience Over Defense”, Cybersecurity Insiders
All Covered · Konica Minolta
All Covered · Konica Minolta
ConnectWise, LLC
ConnectWise, LLC
Sienna Group, LLC
CISSP, Certified Information Systems Security Professional
SentinelOne Sales Engineer Expert
SentinelOne Incident Responder
Why building to absorb and recover beats building only to block, and how to design for it.
Read the article → Open Source · GitHubPython tooling and automation for security operations and incident response.
View GitHub →Open to security architecture, advisory, and engineering conversations. The fastest way to reach me is email. I read every message.