Detection and response engineer at Meta. Before that I built detection content for Splunk Enterprise Security at Cisco.
Most of my work sits in the detection lifecycle: getting telemetry from cloud, endpoint, DNS, and identity sources into something usable, writing detections that map to ATT&CK, and building the automation that gets an analyst from alert to answer faster. Lately that includes figuring out how to detect AI agents attacking infrastructure at machine speed, which turns out to be a genuinely new problem, not just a faster version of the old one.
A few things worth knowing:
- I own 90+ production detections at Meta across cloud, DNS, endpoint, and AI agent surfaces, with full ATT&CK TTP coverage.
- Before Meta, I wrote 100+ detections for Splunk Enterprise Security, published to the Security Content library and running in production at thousands of companies.
- DEF CON speaker three years running: Cloud Village 2025 on cross cloud detection and response, Cloud Village 2026 on detecting AI autonomous cloud compromise at non human identity scale, and Red Team Village 2026 running "Zero Signal: Operating Where Defenders Can't See," a hands on tactic table on cloud intrusions that leave zero endpoint telemetry.
- Also spoke at fwd:cloudsec NA 2023 on Sigma based detection engineering.
- 5 published CVEs, and hall of fame credits from Walmart, the UN, and American Express.
- MS in Information Security, Carnegie Mellon University.
- OSCE3, OSEP, OSWE, OSED, OSCP, OSWA, SSCP, CCNA.
Links: LinkedIn | Blog | Google Scholar (200+ citations)
| Project | What it is |
|---|---|
| OSINT-Explorer | Modernized OSINT framework with a hierarchical, YAML configured tool catalog and interactive visualization |
| MultiBurst | Distributed scanning infrastructure that orchestrates large scale content discovery across ephemeral droplets via Ansible/Terraform |
| zoom-scraper | Forensic artifact collection tool for video conferencing software |
| CodeWhisper | Pulls developer comments and notes left behind in deployed web content |
| shodan-autobot | Shodan API automation for attack surface enumeration |


