Cybersecurity engineer focused on Python security automation, identity-centred defensive security and detection engineering.
A tested Python access-governance tool featuring:
- Strict IPv4 validation
- Atomic allow-list updates
- Recoverable audit transactions
- Structured JSONL audit records
- SHA-256 state verification
- Explicit failure and conflict handling
- Python 3.12/3.13 CI
- Ruff, mypy, pytest and CodeQL
A separate detection-engineering project now featuring:
- Sliding-window password-spray detection mapped to MITRE ATT&CK T1110.003
- Strict representative Windows Security parsing for events 4624, 4625, 4663 and 4740
- Employee, unknown-account, privileged-account and directory-status correlation
- Successful-logon detection for non-active identities with contextual T1078 mapping
- Successful-logon and account-lockout correlation after spray activity
- Trusted SHA-256 baselines for protected IPv4 allow lists
- Added, removed, replaced, missing and malformed allow-list detection
- Windows file-access evidence and cross-alert investigation timelines
- Versioned JSONL alerts and deterministic JSONL/Markdown timelines
- Static Sigma and Microsoft Sentinel KQL field-contract validation
- Evidence hashing and automated Markdown investigation reports
- Python 3.12/3.13 CI, Ruff, strict mypy, coverage enforcement and CodeQL
Next milestone: add further identity detections and validate the detection content in an environment-specific SIEM lab.
Python · Identity Security · ITDR · Detection Engineering · Access Control · File Integrity · Windows Security Events · Linux · PowerShell · MITRE ATT&CK · Sigma · KQL
- CompTIA Security+
- ISC2 Certified in Cybersecurity
- Google Cybersecurity Professional Certificate
- Blue Team Level 1 — in progress
