Fifteen years across industry, national labs, and academia — securing cyber-physical systems, automating defense, and teaching the field.
Leading security automation: building Cortex XSOAR playbooks that streamline incident response, integrating with CrowdStrike NextGen SIEM and ServiceNow for automated enrichment and prioritization — on track to save $250K annually.
Designed and optimized anomaly detection algorithms in Splunk SIEM for real-time threat detection. Led DevSecOps adoption — a secure-coding program that cut detected security issues by 30% in six months. Helped build a CTF program with 75 challenges that engaged 130 mission engineers, and served on the Cybersecurity Review Board.
Teaching cybersecurity at CSU Long Beach, San Diego State, UNLV, and CU Boulder: digital forensics and incident response, threat hunting, Python, network security, and Linux security.
Research scientist with the Interdisciplinary Consortium for Improving Critical Infrastructure Cybersecurity. Built a scenario-based cyber incident response simulator to help non-expert operators make informed decisions during attacks on cyber-physical systems.
Postdoctoral researcher. Applied blockchain to build a distributed ledger for shared management of sensitive energy-system data, with a Bayesian framework reflecting the physical laws of the system, plus statistical anomaly detection on sensor data.
Cyber threat analysis for a campus-wide smart grid pilot, a real-time multicast authentication scheme for embedded systems, and an integer-programming approach to an NP-complete scheduling problem for embedded software patching.
Selected peer-reviewed work — 486+ citations, h-index 9. Full list on Google Scholar.
A hands-on training program for developers and security engineers: build a real AI agent, then red-team and patch it. Three tracks — AI foundations, agentic programming, and agentic security.
Visit the Academy ›This very website: a static site on S3 behind CloudFront, with a serverless visitor counter built on API Gateway, Lambda, and DynamoDB, deployed automatically from GitHub Actions.
Resources I used ›