Privacy-first security portfolio

Security operations.
Cloud defence.
Practical proof.

A capability-led portfolio documenting hands-on security operations, incident investigation, vulnerability assessment, remediation ownership, and the systems built to practise them.

  • Investigate
  • Assess
  • Remediate
  • Improve

Built around verifiable work

Security operations Incident investigation Vulnerability remediation Cloud and identity

Selected evidence

Proof, not posture.

Completed work leads. In-progress work is labelled plainly. Roadmap ideas do not masquerade as shipped projects.

02
Completed

Detection visibility

Wazuh SIEM deployment

A working SIEM stack ingesting endpoint and network telemetry, with Sysmon, file-integrity monitoring, pfSense events, and vulnerability-detection coverage.

  • Wazuh
  • Sysmon
  • FIM
  • Network telemetry
Evidence Telemetry validation, coverage notes, documented feed limitations
03
In progress

Detection engineering

Attack-to-detection workflow

A controlled workflow for firing ATT&CK-aligned techniques, validating telemetry, authoring detections, and tracking what the environment can and cannot see.

  • MITRE ATT&CK
  • Atomic Red Team
  • Sigma
  • Git
Current focus Technique execution, rule authoring, validation, coverage mapping

Professional practice

A disciplined path from signal to resolution.

The public portfolio deliberately avoids unverifiable volume claims and sensitive employment details. It focuses instead on the working method used across assigned security tickets and third-party vulnerability assessments.

  1. 01

    Investigate

    Establish context, validate the signal, preserve useful evidence, and separate real risk from noise.

  2. 02

    Assess

    Evaluate exposure, likely impact, control gaps, and the evidence needed to support a defensible decision.

  3. 03

    Remediate

    Own assigned work through resolution, coordinate corrective action, and confirm that the fix addresses the risk.

  4. 04

    Improve

    Capture lessons, strengthen repeatability, and turn operational findings into better detection and prevention.

Working toolkit

Tools in context.

Technology is grouped by the work it supports, not presented as an unqualified keyword wall.

A

Security operations

Microsoft Sentinel, Defender XDR, KQL, incident triage, phishing investigation, and evidence-led escalation.

B

Vulnerability management

Tenable Nessus, assessment scoping, remediation tracking, validation, and third-party vulnerability reviews.

C

Cloud and identity

Microsoft Azure, Entra ID, Conditional Access, Intune, and identity-aware security controls.

D

Lab and automation

Proxmox, pfSense, Wazuh, Sysmon, PowerShell, Git, Docker, Terraform, and repeatable technical documentation.

Verified foundation

Credentials without oversharing.

Certification identifiers, personal records, dates, and document scans are intentionally excluded from the public site.

  • CEH v12EC-Council
  • Certified in CybersecurityISC2
  • SC-900Microsoft
  • AWS Cloud PractitionerAWS
  • Network+CompTIA
  • ITIL 4 FoundationPeopleCert

Privacy-respecting contact

Continue through the trusted channel.

This public portfolio does not embed a personal phone number, email address, precise location, tracking form, or social profile. If it was shared with an application or professional introduction, use the contact channel supplied there.

Open the capability brief