Five years across offensive security tooling and threat detection — building the scanners, rules and automation that carry security work at scale. Python, Java and TypeScript, on both sides of the line.
Years in security
SIEM platforms
Microsoft certs
Published paper
Most engineers pick one. I spent three years writing detections for what attackers do, and now I build the tooling that does it. Watch an attack chain run — and watch detection catch it.
At NetSPI — scanners, platform integrations and automated vulnerability verification for offensive security workflows.
SME for QRadar and Azure Sentinel at ReliaQuest — detection rules built through continuous R&D and shipped via CI/CD.
Automated re-testing service that independently re-checks every reported vulnerability and records a verdict against it — reaching internet-facing targets as well as assets inside restricted internal environments. Takes most of the manual false-positive review out of an engagement, and lets a customer confirm their own fix without waiting on a retest.
Hackathon build. Turns a raw infrastructure inventory into a live picture of known exposure — matching running services against public vulnerability data, scoring severity, and grouping findings by host so each owner sees only what is theirs. Exports for downstream reporting.
Centralises the reference data detection rules depend on — the allow-lists, watch-lists and lookup sets that decide what fires and what stays quiet. Analysts create, amend and retire entries from a single interface instead of working through the platform console.
End-to-end encrypted password manager built on AWS with Node.js, React and MySQL — AES-256 and Bcrypt behind an HTTPS REST API. Published in IJSREM, March 2023.
Microsoft · Jul 2024
Microsoft · Jan 2024
Microsoft
Open to security engineering and research conversations.
CriticalDeployed
HighHackathon
MediumIn use
HighPublished