I develop locally first with Azurite, Functions Core Tools, and SQL Server
in Docker, which costs nothing. Then I deploy to Azure for real, capture the evidence, and run
terraform destroy.
Cybersecurity analyst working across cloud, detection, and AI.
I'm a security analyst at Sunflower Bank, focused on AI enablement, detection, and access governance. Most of that work stays internal, so I build the same kinds of systems on my own — real infrastructure, real controls — and document how each one went.
What I work on
Six areas. Some have finished work in them, some are still empty.
AWS and Azure infrastructure built with Terraform. Locking down IAM, networking, and storage, then tearing it back down.
Keeping data out of models that shouldn't see it, and stopping prompt injection in apps that call them.
Attacking systems I own so the detections I write aren't guesswork.
Control gap analysis and audit readiness against NIST 800-53, CSF 2.0, CMMC 2.0, and SOC 2.
Reading traffic at the packet level, mostly in Wireshark.
Detection rules, alert triage, and incident response playbooks.
Azure project series
Five builds. Each starts from a problem a small business actually has. I deploy them for real, save the evidence, then destroy them so the bill stays near zero.
Backups that only run when someone remembers eventually stop running. Versioning, lifecycle rules, immutability, and a daily message confirming it actually worked.
Blob Storage · Versioning · Lifecycle · Logic Apps
Owners can't tell what their cloud bill will be until it shows up. This one runs on the real spend from the other four Azure builds.
Cost Management · Monitor · Logic Apps · Workbooks
The site goes down and the owner hears about it from a customer. Three checks, alerts in seconds, and a dashboard showing the trend.
Timer Functions · Email/SMS · Workbooks
Sorting and routing incoming email with a model. That means untrusted text reaching something that can take actions, so it needs real injection defenses.
App Service · Azure OpenAI · SQL · Logic Apps
Stock decisions made on gut instead of data. Live stock levels plus restock predictions.
App Service · SQL · Azure OpenAI
Notes and write-ups
Framework breakdowns and what I learned building things.
What the framework actually gives you, and where it stops being useful.
Two AI attacks that get treated as the same thing. The difference decides where the fix goes.
How the DoD verifies its contractors, and the three things that stuck with me.
Where I've worked
- Lead secure AI enablement for 1,500+ users, building DLP controls for Microsoft Copilot so non-public information stays out of it.
- Wrote 55+ alert runbooks across SIEM and EDR, which cut mean time to resolution by 35%.
- Designed a 3-tier access exception process (manager → IT risk → CISO) handling 40+ tickets a week.
- Ran a gap analysis of 58 security controls against NIST 800-53.
- Built an ELK stack to centralize log data and automate monitoring.
- Worked alerts across 2,500+ endpoints in Splunk and CrowdStrike Falcon.
- Drafted 10+ incident response playbooks that cut investigation time by 20%.
- Helped migrate disaster recovery to AWS with automated failover.
I'm open to conversations
Cloud security, detection engineering, and AI security roles, or anyone building something interesting in those areas.