Cybersecurity Analyst — SOC monitoring, threat detection & endpoint defense
I watch the signals across SIEM, EDR and DLP so incidents get contained before they become headlines. Currently securing infrastructure at Wonder Home Finance; building tooling on the side.
Day-to-day SOC responsibilities at Wonder Home Finance — monitoring, hardening, and closing the gap between "alert fired" and "threat contained."
Watching correlation rules and alert queues, separating noise from real signal, escalating what matters.
Deploying and tuning endpoint detection policy, chasing down encryption and licensing edge cases across the fleet.
Configuring exfiltration rules and reviewing DLP incidents to keep sensitive data where it belongs.
Running scans, triaging findings by real risk, and tracking remediation through to close.
Mapping detections to ATT&CK tactics and benchmarking hardening against CIS and OWASP guidance.
Writing tools on the side to close gaps the off-the-shelf platforms don't — see below.
Two projects built outside the day job, both public on GitHub.
A parallelized antivirus scanning pipeline built as a desktop app — designed to run entirely offline rather than depending on cloud signature lookups, with a Rust core doing the heavy lifting behind a React front end.
An NLP notebook for surfacing investigatively relevant terms from large text corpora — built to speed up the first pass through evidence in a digital forensics workflow.
Click a tactic to see what that looks like day-to-day, given the tools I actually work with.
Click any tactic above.