From responding to alerts, to building what handles them.
I'm an Information Security Analyst with two years in a hands-on, high-tool-count environment: identity administration, DLP, email/endpoint security, SIEM triage, and compliance work. Along the way I started building small internal tools to close gaps I kept hitting manually: a lifecycle/lockout process that touched multiple systems by hand, and security alerts that lived in Jira but nowhere useful for spotting patterns.
I'm moving toward Security Engineering. Less "respond to the alert," more "build the thing that catches it, routes it, or removes the need for a human to touch it at all."
My interest in this space started early. Reverse engineering how games detect and prevent cheating pulled me toward how systems get bypassed and how attackers think, and reading about early threats like the Morris Worm pulled me toward the broader threat landscape. My dad's years as a digital forensic examiner reinforced it: watching him piece together evidence from footage and devices made investigation feel like the real work.
That instinct showed up directly on the job. When several employees reported a coworker soliciting money under false pretenses, I pulled the related Teams messages and email threads, built a timeline into a report, and handed it to leadership. The employee was terminated. It's the clearest example of what I actually do: I like thinking like a detective, turning scattered signals into a decision someone else can act on.
Outside of work, I stay hands-on through TryHackMe, Hack The Box, and Cato Networks' training platform.
Longer term, I want to keep growing into a senior security engineering role, building deep technical range across automation, insider risk, and cloud security. I also want to move into a leadership position, mentoring others the way I already do when onboarding new hires today.