HNWork

Work Experience

I was drawn to national security through my first job at CyberProtex, where they gave me hands-on experience with tooling used in the government, cybersecurity evaluations, and real-world experience with writing software.

CyberProtex logo
Huntsville, AL
CyberProtex logo

May 2024 – Present · Huntsville, AL

CyberProtex

Junior Security Software Engineer

My technical range is diverse from my experience utilizing Python, LAMP stacks, PostgreSQL, REST and OAuth 2.0, Microsoft Sentinel, and Fortify SAST during my time at CyberProtex.

Enterprise clients
8 → 19Enterprise clients
Users
200+Users
Cut per audit package
~720 hrsCut per audit package
Defender events triaged
200,000+Defender events triaged

This work is for a government client, so it's shown in text and diagrams only. No screenshots, client names, or addresses.

At CyberProtex

System diagram of the eMASS Simulator: client tenants feeding a shared PHP application layer over a MySQL database, with per-tenant data isolation.
Architecture only. No client data, names or addresses.

eMASS Simulator

LAMP · PHP · MySQL · RMF · CMMC

Grew a federal compliance platform from 8 to 19 enterprise clients and 200+ users, cutting ~720 hours per audit package by rebuilding NIST 800-53 control workflows into a full-stack LAMP application.

  • I managed and built out the eMASS Simulator on a LAMP stack using a SQL database with REST APIs and OAuth 2.0 for a Microsoft authenticator integration upon logins.
  • In the eMASS Simulator I constructed numerous automated reports based on mass quantities of data that would be filtered through a pipeline and shown on a dashboard for clients.
  • PHP
  • MySQL
  • RMF
  • CMMC
  • NIST 800-53
0/71on VirusTotallater confirmed by Microsoft

Ransomware alert triage

Microsoft Defender for Endpoint · VirusTotal · Sysinternals

Triaged 200,000+ Microsoft Defender for Endpoint (EDR) events to disprove a suspected ransomware incident, confirming a false positive mapped to MITRE ATT&CK T1562.001.

  • By utilizing the MD5 hash of the file, we swiftly searched VirusTotal's online database and found that it was not found positive for any threats (0/71).
  • This led us to suspect it was most likely a false alert on a non-whitelisted Datto RMM update, but to ensure that it actually was a false positive, we manually went in and checked defender logs, Sysinternals, and other virus detection systems on both the alerted files and the overall system.
  • Our suspicion was later confirmed by Microsoft in a public announcement.
  • Incident response
  • MITRE ATT&CK
  • KQL
  • Threat intel
sentinel // workbooklive
200k+events
19tenants
0incidents
04:12DCR · ubiquiti syslog forwardedok
04:17Ransom:Win32 flagged · datto rmmtriage
05:02md5 → virustotal 0/71 · sysinternals cleanfalse +
Illustration of a severity workbook — not client data.

Syslog into Microsoft Sentinel

Linux · Syslog · Sentinel · KQL

Architected a Syslog ingestion pipeline forwarding Ubiquiti firewall logs into Microsoft Sentinel with severity-based data collection rules, authoring custom KQL workbooks for real-time threat detection.

  • I built out a custom syslog server to intake Ubiquiti logs and forward them to a Microsoft Sentinel database and displayed it with KQL and Microsoft Workbooks.
  • Sentinel
  • KQL
  • Syslog
  • Ubiquiti
110NIST 800-171 practices

CMMC self-assessment engine

CMMC Level 1 & 2 · NIST SP 800-171

Built a CMMC Level 1 & 2 self-assessment engine scoring organizations against 110 NIST 800-171 practices with automated gap analysis, replacing manual audit review for 19 client organizations.

  • NIST 800-171
  • CMMC
  • Automation
340+live tickets and tasks

Zoho REST integration

OAuth 2.0 · REST · PHP

Integrated Zoho Desk and Zoho Projects REST APIs into an internal PHP timesheet application via OAuth 2.0, caching 340+ live tickets and tasks so staff bill hours against real work items instead of generic categories.

  • OAuth 2.0
  • REST
  • PHP
200+accounts across 19 client tenants

Account security

Microsoft Entra ID · SharePoint

Hardened account security across 200+ accounts and 19 client tenants by integrating SharePoint document libraries via REST API and OAuth 2.0, enforcing MFA through Microsoft Entra ID.

  • Entra ID
  • MFA
  • SharePoint
ShiftSplitPHP · MySQL

ShiftSplit

PHP · MySQL

Built ShiftSplit, a PHP and MySQL shift timer with client billing, Excel export, and an admin panel.

  • PHP
  • MySQL
HackUCF logo
Orlando, FL
HackUCF logo

August 2025 – Present · Orlando, FL

HackUCF

Network Specialist, CCDC C3 Team

I compete on the HackUCF competition team and am the network specialist for Lockdown competition, NCAE, etc.

At HackUCF

2hardening playbooks: pfSense/FreeBSD and MikroTik RouterOS

pfSense and MikroTik hardening playbooks

pfSense · FreeBSD · MikroTik RouterOS

Authored pfSense/FreeBSD and MikroTik RouterOS hardening playbooks used by the team for competition prep; also competed in ICEAGE and on the UCF CCDC C3 training roster team.

  • Through HackUCF I've gained substantial knowledge regarding terminology, procedures, OS, Docker, and other security features.
  • pfSense
  • FreeBSD
  • RouterOS
  • Docker