Summary
IT professional specializing in information security, including hands-on network architecture, serverless application development, and infrastructure-as-code.
Experience
11/2022 - now
Cybersecurity Risk Analyst
NJCCIC
- Cloud & Network Architecture Review: Primary reviewer of cloud/SaaS network architecture like VPC/VNet segmentation, firewall rules, ports/protocols, and encryption-in-transit design for 28+ agencies; conduct NIST-based Security Architecture Reviews (103 YTD), closing 80% within SLA.
- Multi-Cloud CSPM Onboarding: Onboarded 51 AWS/Azure/GCP accounts into CrowdStrike Falcon CSPM, cutting unmanaged cloud attack surface 55% in 6 months, and built Looker/Tableau dashboards operationalizing findings for platform stakeholders.
- CI/CD-Integrated Automation: Engineered a CI/CD-integrated vulnerability notifier that cut agency awareness time for CISA KEV-listed vulnerabilities from 3 days to the same day.
- Application Security Testing: Run scheduled BurpSuite testing across 15 public-facing web applications and deliver remediation guidance to 9+ agencies, driving remediation of 11 critical/high vulnerabilities within 21 days.
02/2016 - 10/2022
Senior Technical Specialist
BSI America Professional Services Inc.
- Network & Infrastructure Administration: Designed, secured, and administered Windows server and network infrastructure for 50 users and 250+ distributed devices, establishing documentation and testing standards that improved audit readiness and operational continuity.
08/2012 – 12/2015
Security Engineer
Verizon Wireless
- Data Pipeline & Detection Automation: Directed case management and root-cause analysis across 200+ GB/day (1B+ daily records) on a high-volume network/identity dataset; engineered PL/SQL detection logic that cut case resolution time 33%.
Cloud & Network Infrastructure Lab (Personal)
Project
AWS Cloud Resume Challenge (Solutions Architect mod)
- Architected and built a full-stack serverless application end-to-end with S3/CloudFront/Route 53 static frontend, API Gateway + Lambda + DynamoDB visitor-counter backend, Python with unit tests, all infrastructure defined in Terraform and separate GitHub Actions CI/CD pipelines auto-deploying the frontend and backend on push; produced architecture diagrams and documented cost, performance, and reliability tradeoffs.
Project
Network Architecture & Security
- Designed and built a segmented, zero-trust network from bare metal, including an OPNSense firewall/router with 3 interfaces, Open vSwitch virtual switching, NAT/port-forwarding, and layered firewall ACLs enforcing least-privilege traffic flow between subnets; engineered a Wireguard VPN with peer-based routing and an internal PKI (Easy-RSA CA + Caddy ACME) issuing TLS certificates across the environment.
Project
Infrastructure-as-Code Automation
- Automated the full VM lifecycle with Packer (templating), Terraform (declarative provisioning), and Ansible (configuration management across mixed Linux/Windows fleets), cutting build time from 3 hours to 30 minutes; deployed Splunk with Zeek network traffic analysis via OVS port mirroring for full packet-level visibility.
Volunteer Service
Volunteer
U.S. Coast Guard Auxiliary
Vice Flotilla Commander & AUXCYBER Augmentation Specialist
- Augment USCG Cyber Protection Teams defending the Maritime Transportation System, leading threat modeling, vulnerability assessments, and remediation briefings for critical infrastructure stakeholders.
Education
M.S.
Computer Science
Stevens Institute of Technology
B.S.
Information Systems
Carnegie Mellon University
Minor in Professional Writing.
Certifications
GIAC Certifications
GIAC Cyber Threat Intelligence (GCTI)
GIAC Enterprise Vulnerability Assessor Certification (GEVA)
aws training and certification
AWS Certified Cloud Practitioner
AWS Certified Solutions Architect – Associate
AWS Certified Security – Specialty
CompTIA
Network+
Security+
CySA+
CompTIA Security Analytics Professional (Security+ / CySA+)
ISC2
Certified Information Systems Security Professional (CISSP)