Professional Experience
My journey through cybersecurity, from foundational IT support to leading enterprise incident response teams.
โกExperience Timeline
Deloitte
Jan 2023 โ Present
CurrentSophos
Nov 2020 โ Jan 2023
eClinicalWorks
Jul 2018 โ Nov 2020
Deputy Manager โ CSIRT
Deloitte
๐Key Metrics
๐Key Achievements
Enterprise Incident Response Leadership
Operated in a high-pressure CSIRT environment, managing enterprise-scale incident response for ransomware outbreaks, cobalt strike intrusions, command-and-control (C2) callbacks, and suspicious persistence mechanisms.
Advanced Forensic Analysis
Performed end-to-end forensic investigations, acquiring memory dumps, analyzing Master File Table (MFT), parsing shell artifacts, and extracting volatile indicators to determine root cause and threat actor behavior.
Detection Engineering Excellence
Led reverse engineering of malware payloads (obfuscated DLLs, PE files, and encrypted scripts) using disassemblers and emulation tools, enabling early-stage detection of custom malware and LOLBins abuse.
Threat Detection & Containment
Built and refined detection rules (EDR + SIEM), optimizing telemetry logic to detect rare behaviors like token impersonation, parent-child process anomalies, and native API misuse.
SOAR & Automation
Automated containment and recovery workflows using SOAR (XSOAR Cortex), reducing time-to-response (MTTR) for critical alerts across the enterprise.
Playbook Development
Drafted enterprise-wide SOPs and playbooks for incidents involving web shell exploitation, lateral movement, credential theft, and cloud-native attacks (Azure/AWS).
Team Development & Mentorship
Mentored L1 analysts and junior responders through ransomware simulations, real-time triage exercises, and forensic case studies, driving a 92% improvement in detection precision.
AI & ML Integration
Integrated OpenAI APIs to develop early-stage threat narrative classification models, automating contextual alert analysis and tagging within SOC workflows.
Decryption Research
Actively contributed to ransomware decryption research, integrating YARA-based scanning logic for novel strains and deploying resilient backup validation methods.
Advanced Detection Engineering
Helped in tuning the detection logic for ransomware and other threats and created a custom detection logic on Splunk and MDE using KQL
Threat Hunting & Detection
Worked closely with iBoss, Zscaler, and Cisco Stealthwatch telemetry for east-west traffic inspection, DLP monitoring, and anomaly detection.
Total Achievements
11 major accomplishments with significant business impact