I build and ship real security tools — live OSINT platforms, threat-intel maps, and RAG assistants — at the intersection of security engineering and software. Eight years in technology operations, an M.S. in Cybersecurity at NYU, and a habit of turning ideas into deployed products.
Real tools — deployed, live, and reachable. Not mockups.
Full-stack OSINT intelligence aggregation platform. 17 files, 1,434 lines, 5 serverless API routes in production. Integrates HIBP, Shodan, Hunter.io, AbuseIPDB, VirusTotal, crt.sh, WhoisJSON, IPQualityScore, and GitHub into a single analyst interface with an executive design system and PDF case-file export.
React habit tracker built from scratch — hooks, derived state, and localStorage persistence. Add and delete habits, track daily streaks with live best-streak and total-day stats computed on every render. Deployed to its own subdomain via Vite.
React + Vite IP-intelligence tool with Mapbox GL JS geolocation, AbuseIPDB threat scoring, and real-time visitor-IP detection.
Full PHP/MySQL helpdesk — 11 tables, stored procedures, triggers, role-based access, knowledge base, and reporting. Complete CRUD with agents, tickets, tags, and a KB module.
Enterprise SIEM walkthrough — live Sentinel workspace, custom KQL detection rules mapped to MITRE ATT&CK Initial Access, and triaged real triggered incidents.
LangChain + FAISS + HuggingFace all-MiniLM-L6-v2 + GPT-4o-mini. Six curated SOC knowledge packs — answers pulled from curated documents, not general training data. Deployed on Streamlit Cloud.
A live AWS environment using GuardDuty, CloudTrail, and SNS alerting to simulate real attack scenarios — credential stuffing, S3 exposure, IAM abuse — each mapped to MITRE ATT&CK with a triage runbook. Currently building.
Not demos for a slide deck — a RAG pipeline I built and deployed for SOC analyst workflows.
Ask about phishing triage, Splunk SPL hunting queries, MITRE ATT&CK mapping, AWS CloudTrail events, or IAM fundamentals. Answers are pulled from curated SOC knowledge packs — not general training data — so they're auditable and source-grounded.
▶ Launch Live AppOpens in a new tab · Selectable knowledge packs · Evidence sources · Conversation history
How the assistant turns a plain-English question into source-grounded analyst guidance:
Key idea: instead of relying on the model's general knowledge, it answers only from curated documents — making responses accurate, auditable, and domain-specific.
A simplified, offline taste of the assistant's tone. Try “DNS tunneling”, “phishing”, or “ransomware” — for the real retrieval-backed answers, launch the live app.
8+ years across IT operations, enterprise security, and operations leadership in regulated, high-volume environments.
Depth across software, applied AI, security operations, and the infrastructure that ties them together.
Active certifications and completed training programs.
A strong academic record across three institutions.
Open to roles, collaboration, and conversations at the intersection of security engineering, software, and applied AI. Reach me through any of the channels here, or send a message directly.