Security Architect · CISSP · Tampa, FL

Mike Fuentes

Building security that bends without breaking.

Cybersecurity team lead with 9+ years building and scaling managed security services. I help mature SOCs into proactive MDR practices, work on the design and economics of new services, and pair hands-on, AI-assisted development with secure-by-design practices to ship tooling fast.

  • 0Years in security
  • 0Clients protected
  • 0New-service profit margin
  • 0Faster IR ingestion
m.fuentes@sec · zsh
visitor@mike:~$
Working across
  • SentinelOne
  • SOAR
  • AWS
  • Docker
  • Cloudflare
  • Python · FastAPI
  • NIST CSF
  • CIS Benchmarks
01

About

I help turn security capabilities into services clients can actually use.

I'm a security architecture and engineering team lead at a managed security provider (MSSP), working as an individual contributor who leads projects. Our team brought siloed SIEM and managed EDR together into a unified MDR offering and moved the SOC from reactive toward proactive. Beyond the architecture, I help with service design, go-to-market, and the economics behind new offerings, like a Dark Web Monitoring service we launched at a 60% margin, working across sales, operations, and leadership to bring them to clients.

I'm also a builder. I ship full-stack internal tooling with Python (FastAPI), Next.js, and Docker, increasingly AI-assisted with LLMs and local models, applying secure-by-design practices like JWT auth, password hashing, and rate limiting. A self-hosting homelab keeps the fundamentals sharp.

If there's a thread through my work, it's a builder's curiosity: I like starting new projects and experimenting with new approaches so we can keep offering clients better services.

  • Now Security Architecture & Engineering Team Lead · All Covered (Konica Minolta)
  • Cert CISSP · ISC2
  • Focus MDR · service design · new offerings
  • Builds Python · FastAPI · Next.js · Docker · AWS
  • Base Tampa, FL · Open to advisory & architecture work
02

What I Do

MDR & SOC Maturation

Helped bring siloed SIEM and managed EDR together into a single MDR practice, moving the SOC from reactive alerting toward proactive detection and response.

Security Service Design & GTM

Help design, launch, and run the economics of managed services, like Dark Web Monitoring at a 60% margin, and the go-to-market behind them.

SOAR & Automation

Cross-team SOAR and Python automation that cut manual analysis 50% and drive down operational cost.

Incident Response

Served as incident commander on partner breaches. Helped build playbooks and an AWS IR stack that cut downtime 50%, response time 35%, and ingestion 75%.

Threat Intelligence & Hunting

CTI tooling, proactive threat hunting, and IOC/TTP analysis, surfacing stolen credentials before they're exploited.

AI-Assisted Secure Development

Full-stack internal tooling in FastAPI, Next.js, and Docker, built with LLMs and local models, shipped secure-by-design.

The strongest programs aren't the ones that never get hit; they're the ones built to absorb the hit, recover fast, and come back smarter.

From “Resilience Over Defense”, Cybersecurity Insiders

03

Experience

  1. Security Architecture & Engineering Team Lead

    Oct 2024 - Present

    All Covered · Konica Minolta

    • Lead and manage security architecture and engineering projects as an individual contributor, including SOAR deployments and automations that helped lower operational cost.
    • Helped launch a new Dark Web Monitoring service (around a 60% margin) that flags stolen credentials before exploitation.
    • Worked to bring siloed SIEM and managed EDR together into a unified MDR offering, moving the SOC from reactive toward proactive.
    • Lead vendor evaluation and requirements gathering for new services and tools, balancing capability against cost and profitability.
    • Helped define the go-to-market for new services alongside sales, operations, development, marketing, and leadership.
    • Support and mentor SOC teammates on technical and career growth.
  2. Senior Cybersecurity Engineer

    Aug 2022 - Oct 2024

    All Covered · Konica Minolta

    • Supported deployment and maturation of managed endpoint security for 400+ clients, tailored to each client's risk profile.
    • Served as a senior escalation point for analysts on incident review and response.
    • Built SOAR and Python automation that cut manual data analysis 50%.
    • Served as the team's SentinelOne SME, using it for triage and helping improve true/false-positive accuracy.
    • Put together data-driven business cases that supported team growth.
  3. Incident Response Consultant

    Sep 2021 - Aug 2022

    ConnectWise, LLC

    • Served as Incident Commander for partner-facing incidents, coordinating SMEs and external partners for rapid recovery.
    • Cut partner downtime 50% through IR process improvements.
    • Led playbook development that shortened response times 35%.
    • Analyzed logs and artifacts with IOC tooling to determine root cause, TTPs, and threat intel.
    • Architected an AWS IR stack, cutting data ingestion/processing time 75%.
  4. Information Security Engineer

    May 2018 - Sep 2021

    ConnectWise, LLC

    • Built a Vendor Risk Management program, surfacing new revenue opportunities from risk data.
    • Created NIST CSF-compliant product assessments and remediation plans.
    • Automated vendor processes in Python; a separate tool cut manual workload 30%.
    • Architected multi-node, multi-cloud data discovery and classification in AWS for DLP.
    • Designed hardening guidelines on CIS Benchmarks and built CTFs for customer enablement.
  5. Managed Data Security Analyst

    Jan 2017 - May 2018

    Sienna Group, LLC

    • Maintained customer-managed data security infrastructure and software.
    • Remediated DLP configuration and installation issues for managed customers.
    • Validated data-classification effectiveness by testing data against the DLP engine.
04

Technical Proficiencies

Security Operations

  • MDR
  • SOAR
  • Threat Correlation
  • Incident Response
  • SOC Maturation

Endpoint & EDR

  • SentinelOne
  • Bitdefender

Cloud & Virtualization

  • AWS
  • Vultr
  • Cloudflare
  • Docker
  • Docker Compose
  • VMware

Development

  • Python
  • FastAPI
  • React / Next.js
  • TypeScript
  • REST APIs
  • PostgreSQL
  • Git

AI-Assisted Development

  • Claude / LLMs
  • Ollama (local models)
  • Secure-by-Design
  • JWT Auth
  • Rate Limiting

Infrastructure & Self-Hosting

  • Linux Admin
  • Caddy
  • Nginx
  • Tailscale
  • UniFi
  • Home Assistant

Data Protection

  • DLP
  • Data Classification
  • TITUS

Frameworks

  • NIST CSF
  • CIS Benchmarks

Operating Systems

  • Windows
  • Linux
  • macOS
05

Credentials

Certifications

  • CISSP, Certified Information Systems Security Professional

    ISC2 · Aug 2024

  • SentinelOne Sales Engineer Expert

    SentinelOne · Apr 2025

  • SentinelOne Incident Responder

    SentinelOne · Apr 2025

Verify on Credly →

Education

  • B.S. Computer Science

    University of South Florida · May 2018

Résumé

Download full résumé (PDF) →
06

Writing & Code

07

Let's build something resilient.

Open to security architecture, advisory, and engineering conversations. The fastest way to reach me is email. I read every message.