Security Operations Engineer
Current- Leads daily DLP incident response as primary analyst and incident commander — coordinates 25+ analyst triage reviews across DLP, UAM, SIEM, EDR, PAM, email security, and endpoint resilience platforms.
- Cut report drafting from 60–90 min to under 10 min by automating end-to-end DLP report generation with AI — 300+ reports, recovering an estimated 150–200+ analyst hours/month.
- Engineered DLP-specific AI agentic agents and skill prompts for real-time user activity reviews, automated SIEM log analysis, UAM footage review timelines, and self-improving browser-based investigation skills.
- Architected the Dead Man Switch (DMS) — a multi-layer offboarding lockdown that eliminated unauthorized post-termination device access across 1,500+ terminations: firmware-level OS freeze, cached-credential clearing via RMM/MDM heartbeats, and 20+ blocking controls across DLP/UAM/SIEM.
- Created an Analyst Action Hub in an AI agent workspace — a daily dashboard for task check-offs, ticket pulls, and completion logging that serves as a live monitor of the entire DLP program for VPs and executives.
- Owns High Risk User Monitoring (HRUM) — PIPs, suspected IP theft, disgruntled employees, and anomalous behavior; drafted entry/exit reviews spanning weeks to months.
- Surfaced 80,000+ GB of stale data risk across 4,500+ devices via custom Mac/Windows discovery scripts; drove an automated tiered deletion pipeline.
- Authored incident playbooks, escalation procedures, and the overall incident response plan; data custodian for Legal/HR e-discovery with compliance across NIST CSF, ISO 27001, GDPR, PCI-DSS, HIPAA, SOX, and SOC 2.




