Cybersecurity leader, advisor, author, and open-source creator focused on security operations, cyber defense, incident response, detection engineering, SIEM/XDR, GRC, and AI governance.
Website · LinkedIn · Insights and research · Microsoft Security author profile
I turn complex security-operations and governance problems into practical operating models, decision frameworks, playbooks, and testable tools. My public work is designed for CISOs, SOC and MSSP leaders, incident commanders, detection engineers, security architects, GRC teams, and AI-governance practitioners.
- Enterprise Security Operations and SOC/MSSP operating models
- Incident response, incident command, operational resilience, and cyber-risk decisions
- Vendor-neutral SIEM/XDR strategy, detection engineering, threat hunting, and security automation
- AI-agent security, non-human identity, Responsible AI, and Artificial Intelligence Management Systems (AIMS)
- Governance, risk, and compliance aligned with ISO/IEC 27001, ISO/IEC 42001, NIST CSF, and NIST AI RMF
- 18+ years spanning MSSP operations, enterprise SOC leadership, threat intelligence, cloud security, security-product development, GRC, and AI governance
- Led a 15-person MSSP analyst team and built, trained, and mentored a 10-person Microsoft SOC analyst team with operational oversight
- Founding-team experience with the Microsoft Threat Intelligence Center (MSTIC), early Microsoft Sentinel detection development, Linux threat detection for Azure Security Center, and detection-engineering leadership in Microsoft Defender XDR
- Led or supported 25+ high-severity, APT, and complex breach investigations; developed 75+ SIEM/XDR/cloud correlations and 40+ playbooks or runbooks
- Worked across eight SIEM and two XDR platforms and influenced a $2 million security investment through evidence-based capability assessment
| Project | What it helps security leaders do |
|---|---|
| AI Agent Security & Governance Toolkit | Assess whether an AI agent is ready for controlled operational authority across identity, tools, telemetry, detection, containment, evidence, and governance. |
| The 72-Minute Defense | Define, attest, rehearse, and measure pre-authorized ransomware-containment decisions before an attacker reaches exfiltration. |
| Cyber Incident Commander Toolkit | Coordinate high-severity cyber incidents through decision rights, executive communication, DFIR evidence, playbooks, and risk governance. |
Each repository is a reference implementation for research, evaluation, and organizational adaptation. Scope, limitations, safety boundaries, and licensing are documented in the individual projects.
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- ISO/IEC 42001 Lead Implementer
I advise organizations on cyber defense, security operations, SIEM/XDR strategy, detection engineering, incident response, cyber risk, AI-agent security, and AIMS. I also consider senior in-house cybersecurity leadership opportunities and speaking or educational engagements.
