Mastercard β Cybersecurity
Security Awareness-focused simulation completed as a Security Analyst scenario, including phishing simulation design and interpretation of phishing-simulation results.
Enterprise IT professional with 12+ years of enterprise IT infrastructure experience, deliberately transitioning into cybersecurity. Hands-on cybersecurity capability is demonstrated through independent, authorized labs in Wazuh SIEM, detection engineering, incident investigation, DFIR, Windows/Sysmon telemetry, network security, cloud security, and automation. The portfolio clearly separates professional IT experience from independent security work.
12+ years supporting Windows/Linux environments, infrastructure, Active Directory, endpoint security, system hardening and business-critical IT operations β now applying that foundation to detection engineering, incident response, threat hunting, digital forensics and security automation.
Focused entry points for recruiters and technical reviewers. Each hub links directly to source evidence in the repository and preserves the portfolio's evidence-scope standard.
Wazuh, Windows telemetry, alert triage and investigation workflows.
Open evidence hub βDetection logic, attack simulation, validation and MITRE ATT&CK mapping.
Open evidence hub βForensics, evidence handling, timelines, IOC extraction and response.
Open evidence hub βNmap, Wireshark, PCAP analysis and network assessment evidence.
Open evidence hub βCaptured packet traffic using tshark to analyze automated web scans, SQL injection payloads, and command execution attempts. Engineered custom Python scripts for automated triage.
$ python3 pcap_triage.py --file capture.pcap
[+] Extracting HTTP POST payloads...
[!] ALERT: SQLi Payload Detected: ' OR 1=1 --
[!] Source IP: 192.168.1.105 -> Targeted Port: 8080
Executed deep forensic triage on compromised Linux system logs. Verified SHA-256 evidence hashes, mapped actor techniques to MITRE ATT&CK, and produced post-incident timelines.
# sha256sum /var/log/auth.log
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
[+] Root session established via SSH key from 10.0.4.12
Deployed Wazuh agents across lab nodes. Authored custom XML detection rules to flag privilege escalation and established File Integrity Monitoring (FIM) for system directories.
<rule id="100002" level="10">
<if_sid>5715</if_sid>
<match>sudo: privilege escalation</match>
<description>Possible privilege escalation alert</description>
</rule>
Completed a six-lab Splunk SOC track covering SSH authentication hunting, Windows/Sysmon process investigation, web-attack investigation, SPL detection engineering, SOC monitoring/dashboarding, and end-to-end incident investigation using controlled synthetic telemetry.
Automated parsing of Windows Security XML event logs (4624, 4625, 4728) using Python to highlight lateral movement, brute force attempts, and unauthorized group escalation.
$ python3 ad_triage.py --event 4728
[!] PRIVILEGE ESCALATION DETECTED
User 'jdoe' added target 'Domain Admins'
Caller User: 'bad_actor_admin'
Real Terraform for a GCP organization landing zone: org-level policy guardrails (no external IPs, no SA key files, domain-restricted IAM), an environment folder structure, a Shared VPC host project with deny-all-ingress firewall rules and Cloud NAT, and a centralized org-wide logging sink. Formatting-checked with terraform fmt; full validate/apply pending a real org (this build environment can't reach the Terraform registry).
3 real MITRE ATT&CK techniques (Execution T1059, Persistence T1053/T1547, Credential Access T1003), each written to run against 2 real, self-owned targets: the home-lab Linux host and the Azure Windows Server DC documented elsewhere in this portfolio. All 6 technique/platform combinations have preserved live-alert evidence from authorized tests against self-owned Linux and Windows lab targets. The evidence is lab validation, not client or production infrastructure.
Terraform-provisioned Windows Server 2022 VM in Azure with a default-deny NSG, no committed secrets, and daily auto-shutdown for cost control. Deployed, promoted to an AD Domain Controller (lab.local), hardened, and validated end-to-end: 409 real Security events exported and analyzed for 392 findings, plus a live Wazuh Agent connection generating real MITRE-mapped alerts.
CIS-benchmark-style Python audit engine (SSH config, sudoers NOPASSWD scope, SUID binaries, world-writable files, legacy services, firewall state), validated first against synthetic fixtures, then run for real against a live personal Linux host via a purpose-built collector script.
CIS Docker Benchmark / MITRE ATT&CK for Containers-style Python audit engine (root user, unpinned tags, hardcoded secrets, privileged mode, docker.sock mounts, host network mode), validated first against synthetic fixtures, then run for real against a home-lab Docker host via a docker inspect-based collector that redacts every env value before it touches disk.
Full TCP port range scan (-sV -sC -p-) against the analyst's own home-lab host, with raw output preserved in all three Nmap formats. An unrecognized service fingerprint on port 9443 was independently verified with curl/ss rather than assumed, revealing Portainer exposed on every network interface instead of scoped like the stack's other services.
Real tcpdump capture (52 packets) of the analyst's own Juice Shop container, including a genuine test of its known SQL-injection-vulnerable search endpoint. Analyzed with this portfolio's existing pcap_soc_analyzer.py, previously validated only against synthetic data - it correctly flagged the real SQLi request (HIGH) while correctly declining to flag a weaker scanner-UA signal alone.
Real bandit static analysis scan of this portfolio's own 1,278-line Python codebase - not a fictional target. Found and fixed one genuine High-severity issue (unnecessary shell=True command execution). Remaining findings triaged honestly: one confirmed scanner false positive, one documented defense-in-depth recommendation, and low-risk findings reviewed and accepted rather than blindly cleared.
Installed Sysmon (SwiftOnSecurity config) on a live, deployed Azure Domain Controller and captured real process-create (Event ID 1) and network-connect (Event ID 3) telemetry, validated against the same detection logic used on synthetic data.
<ProcessAccess onmatch="include">
<TargetImage condition="is">C:\Windows\System32\lsass.exe</TargetImage>
</ProcessAccess>
Practical cybersecurity simulations completed through Forage. These are virtual work experiences, not employment, and are presented as evidence of applied learning and professional skills.
Security Awareness-focused simulation completed as a Security Analyst scenario, including phishing simulation design and interpretation of phishing-simulation results.
Cybersecurity operations simulation covering cyberattack impact analysis and cybersecurity risk assessment, with emphasis on threat research, risk prioritization and actionable recommendations.
Certificates and original work products can be linked here once published. Only completed work and verifiable evidence should be presented.
Loading synchronized GitHub projectsβ¦
Core Security Standards
SOC & Defensive Tools
Systems & Networking
Undergraduate Degree
Targeting SOC Analyst, Security Operations Analyst, Cybersecurity Analyst, Detection Engineering, Threat Hunting, and Security Engineering opportunities.