Lab foundation
Segmented blue-team environment
A Proxmox-based lab with a pfSense gateway, an Active Directory forest, domain-joined endpoints, realistic organisational structure, and rollback snapshots at meaningful checkpoints.
Privacy-first security portfolio
A capability-led portfolio documenting hands-on security operations, incident investigation, vulnerability assessment, remediation ownership, and the systems built to practise them.
Built around verifiable work
Security operations Incident investigation Vulnerability remediation Cloud and identitySelected evidence
Completed work leads. In-progress work is labelled plainly. Roadmap ideas do not masquerade as shipped projects.
Lab foundation
A Proxmox-based lab with a pfSense gateway, an Active Directory forest, domain-joined endpoints, realistic organisational structure, and rollback snapshots at meaningful checkpoints.
Detection visibility
A working SIEM stack ingesting endpoint and network telemetry, with Sysmon, file-integrity monitoring, pfSense events, and vulnerability-detection coverage.
Detection engineering
A controlled workflow for firing ATT&CK-aligned techniques, validating telemetry, authoring detections, and tracking what the environment can and cannot see.
Professional practice
The public portfolio deliberately avoids unverifiable volume claims and sensitive employment details. It focuses instead on the working method used across assigned security tickets and third-party vulnerability assessments.
Establish context, validate the signal, preserve useful evidence, and separate real risk from noise.
Evaluate exposure, likely impact, control gaps, and the evidence needed to support a defensible decision.
Own assigned work through resolution, coordinate corrective action, and confirm that the fix addresses the risk.
Capture lessons, strengthen repeatability, and turn operational findings into better detection and prevention.
Working toolkit
Technology is grouped by the work it supports, not presented as an unqualified keyword wall.
Microsoft Sentinel, Defender XDR, KQL, incident triage, phishing investigation, and evidence-led escalation.
Tenable Nessus, assessment scoping, remediation tracking, validation, and third-party vulnerability reviews.
Microsoft Azure, Entra ID, Conditional Access, Intune, and identity-aware security controls.
Proxmox, pfSense, Wazuh, Sysmon, PowerShell, Git, Docker, Terraform, and repeatable technical documentation.
Verified foundation
Certification identifiers, personal records, dates, and document scans are intentionally excluded from the public site.
Privacy-respecting contact
This public portfolio does not embed a personal phone number, email address, precise location, tracking form, or social profile. If it was shared with an application or professional introduction, use the contact channel supplied there.
Open the capability brief