Security leadership
Develop the team
Lead SOC and incident-response work, develop analysts through technical coaching and investigation review, and coordinate offensive assessment delivery. Explore how I connect technical decisions with service ownership.
All cards in this section are viewed.
SOC leadership and incident response across client environments
MSSP Security Operations & Incident ResponseLed SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.
Read the storyCNI SOC leadership and investigation standards
Security Operations LeadershipOnboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.
Read the storyKeeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storyFollow a skill into the work