GitHub Actions · Shuffle SOAR · Semgrep, Trivy, Gitleaks, OWASP ZAP
Built and gated a four-scanner CI/CD pipeline wired into a Shuffle SOAR platform for automated triage. Diagnosed and fixed two structural Shuffle bugs (an unintended branch connection and a startnode routing defect), a severity-gate logic bug in DAST, and verified all four scanners end to end with real Slack, Shuffle, and email evidence.
MedCore Logistics · Wazuh, Action1, Suricata, Tailscale, Atomic Red Team
Built a centralized threat detection and monitoring environment for a fintech client running hybrid on-premise and AWS/Azure infrastructure. My role covered Suricata deployment across all endpoints, hosting the Wazuh manager and the attack-simulation host, cloud account setup for AWS and Azure log ingestion, and running all three Atomic Red Team validation scenarios.
CyberNetwork Healthcare Logistics · Wazuh, Action1, Tailscale, Python
Built as part of a 14-day team sprint to take a healthcare logistics client from zero endpoint visibility to a measurable, evidence-backed defense program. My role covered the asset inventory, tagging convention, security architecture, and the Tailscale network bridge connecting endpoints across three office locations.
Wazuh custom correlation rule · Hydra · MITRE ATT&CK · Sigma / Elastic
Built and validated a custom Wazuh rule detecting RDP brute-force attacks end to end against a live Hydra attack and a simulated credential-reuse pivot. Root-caused a real detection bug where a built-in rule was silently pre-empting the custom one, fixed it, and re-validated against the same live attack. Also authored the same logic as a Sigma rule and documented its Elastic equivalent.
Wazuh · Sysmon · Suricata · Zeek · Action1 · Tailscale
Built and independently verified a self-hosted, four-endpoint SIEM environment across two physical hosts as the foundation the other eight labs in this pack run on. Every sensor, Wazuh agents, Sysmon, Suricata, and Zeek, was confirmed with real, evidenced detections rather than a service status check, including a genuine Zeek scan detection and a live Suricata attack simulation traced end to end into the dashboard.
Forage · View certificate
Four tasks made up this simulation for Commonwealth Bank's Cybersecurity team, spanning data analysis, incident response, security awareness, and penetration testing. I installed and used Splunk to build dashboards visualizing fraud-related data, then worked through a full incident response cycle: identifying the attack type, containing it, and outlining recovery and prevention steps. I designed an infographic on secure password practices based on Australian Cyber Security Centre guidance, and completed eleven beginner labs on PortSwigger's Web Security Academy, writing up a penetration testing report with findings and remediation recommendations. It was the broadest single simulation I've done, touching data analysis, incident response, security awareness, and offensive testing in one exercise.
Forage · View certificate
Supporting a client through an active data breach was the scenario in this Deloitte simulation. I read through web activity logs to help determine the source of the breach and answered a series of questions to identify suspicious user activity. It's a compact exercise, but it built a skill I'll lean on constantly in SOC work: reading raw log data and pulling out what actually matters.
Forage · View certificate
Identity and access management was the core focus here, worked through end to end. I learned IAM fundamentals and how it mitigates security risk through case study analysis, then assessed hypothetical enterprise scenarios for IAM readiness and built a checklist to evaluate that readiness. From there I designed custom IAM solutions tailored to specific enterprise requirements and worked through platform integration challenges to keep access to enterprise resources secure. I closed it out with documentation and a presentation communicating the technical design to a non-technical audience.
Forage · View certificate
This simulation put me in the shoes of a cybersecurity consultant investigating a simulated cyber-attack on a mid-sized company. I analyzed the attack vector, the data compromised, and the operational impact, then wrote a report summarizing the breach, the vulnerabilities exploited, the business ramifications, and recommendations to improve the client's security posture. A second task had me run a structured risk assessment of an organization's assets to identify and prioritize potential threats. It strengthened how I think through breach impact and communicate mitigation strategies clearly.
Forage · View certificate
Working on AIG's Cyber Defense Unit meant handling two very different problems. First, reviewing CISA publications, researching a reported zero-day vulnerability, and drafting a clear email guiding affected teams through remediation for a staging environment. Second, writing a Python script to bruteforce the decryption key on a ransomware-encrypted file, an ethical alternative to paying the ransom. It sharpened both my ability to communicate a technical risk to non-technical teams and basic scripting for security problems.
Forage · View certificate
Phishing was the core threat explored in this simulation, stepping into Mastercard's Security Awareness Team. I examined a phishing email and reworked it to be more convincing, then built a phishing simulation to raise awareness of the threat internally. I analyzed the results to identify which teams needed more security training and outlined the training and procedures for those teams. This gave me hands on exposure to how organizations detect, report, and reduce phishing risk at scale.