DLP · Security Automation · AI Agentics · InfoSec

Griffin Dutka

Security Engineer automating security operations with AI.

Scroll ↓

Profile

What I do

Security Operations Engineer with deep expertise in DLP, AI-driven security automation, SOC agentics, endpoint security, and incident response across large-scale enterprise environments. Experienced across on-prem and cloud/SaaS platforms, with a track record of designing security programs that reduce risk, improve response times, and scale across the organization.

Current work spans DLP investigation and escalation frameworks, AI-powered automation pipelines, SOC agentics, security policy creation and enforcement, and fleet-wide initiatives including device lifecycle management and enterprise data governance. Full-stack perspective from detection engineering and behavioral analysis to cross-functional work with HR, Legal, and executive leadership.

Prior critical-infrastructure experience includes on-prem deployment and administration of Splunk, CyberArk, Carbon Black, and Aruba ClearPass across Linux RHEL and Windows Server, with compliance alignment to NERC CIP, NIST, and other frameworks.

Impact

Measurable outcomes

The numbers behind the security programs, automation pipelines, and agentic tooling I run in production.

1,500+
Security Tool License/Seat Reclamation
Built Automated Security Tool Seat Cleanup Lifecycle · saving company cash
300+
AI-Generated Incident Reports
Drafted in <5 min each, down from 60–90 · more time for threat hunting :)
250h+
Analyst Hours Recovered
Per month via fully custom SOC/DLP AI agents · built with company context
80,000GB+
Sensitive Stale Data Surfaced
Across 4,500+ endpoints · implemented automated deletion scripts
<0.5%
Human Correction Rate
On AI agent reviews and automated report generation · post tuning cycle obvs
35+
Security Controls and Gaps Identified
Implemented to reduce company risk

Capabilities

How I work

  1. 01

    Detect what others miss

    Primary DLP analyst and incident commander across DLP, UAM, SIEM, EDR, PAM, email, and endpoint platforms — coordinating 25+ triage reviews a day and distilling every incident into risk-prioritized reporting for leadership. Built AI agents through rigorous prioritization based on risk/time KPIs to provide actionable results.

  2. 02

    Investigate at machine speed

    AI agents pull, correlate, and summarize investigations, provide real-time user-activity reviews, automated cross-referencing SIEM analysis, UAM footage timelines, and self-improving gemini “in-browser” skills. 300+ exec reports drafted in <5 min each.

  3. 03

    Contain before damage lands

    The Dead Man Switch, a firmware-level OS freeze, cached-credential clearing, and blocking controls across DLP, UAM, and SIEM targeted at terminated devices in cloud environments. Ensures that even if termination commands are not received by an offline device, it will remain secured. Zero unauthorized post-termination access across 1,500+ terminations and counting.

755025DLP EXFIL10.4.118.22INSIDER RISK10.7.33.9EMAIL DLP10.2.90.41
◍ THREAT SURFACE · SYNTHETIC

Agentic AI

DLP incident pipeline

An example of a DLP incident driven through my production agentic pipeline — alert ingest to exec-ready report. All data shown is synthetic.

  1. 01
    Alert Review
    DLP sensor agent
  2. 02
    Triage Agent
    provides risk scoring
  3. 03
    Agentic Activity Review
    sifts through 24h footage
  4. 04
    Log & Timeline Agent
    full timeline built
  5. 05
    Report Gen
    exec-ready draft for human review
LIVE · 1,240,512 events triaged
dlp-agent — incident DLP-2026-0609
$ dlp run --incident DLP-2026-0609 --agentic
alert.ingestDLP sensor · exfil pattern matchedOK
triage.agentrisk score 87/100 — HIGHCRIT
activity.review24h UAM window pulled · 3 flagsOK
log.timeline142 events correlatedOK
report.genexec-ready draft assembledOK
building report
REPORT READY9:47 min / 0 human corrections / 14 evidence artifacts
SCRIBEDeployed

End-to-end DLP report generation. Automatically drafts weekly & monthly executive reports from raw analyst findings.

300+ reports · 60–90 min → <5 min

OVERWATCHDeployed

Real-time automated user activity reviews — AI agent correlates and summarizes 24h windows of DLP activity and UAM footage on demand.

25+ analyst reviews coordinated daily

SIFTDeployed

Automated SIEM and Datastream log analysis — auth events, endpoint signals, and anomaly correlation without manual query spelunking. Specific AI agent to perform targeted user reviews with actionable outputs.

Minutes per query, not hours

REWINDDeployed

Feeds emails, UAM footage, and logs into a timeline agent that builds a full investigator-ready incident chronology.

Full timeline reports in one pass

SPECTERSelf-improving

Browser-based investigation skills that critique and refine their own outputs after every run.

Improves with every investigation

REVIEWLive monitor

Built DLP AI email review agents that pull email metadata, body, and attachments and correlates them against business context and strict severity/criticality matrices.

Ensures every email is reviewed resulting in 100% catch-rate and reducing analyst overhead by >300 hours monthly.

Experience

Where I've worked

Security Operations Engineer

Current
Beyond FinanceChicago, IL (Hybrid)July 2025 – Present
  • Leads daily DLP incident response as primary analyst and incident commander — coordinates 25+ analyst triage reviews across DLP, UAM, SIEM, EDR, PAM, email security, and endpoint resilience platforms.
  • Cut report drafting from 60–90 min to under 10 min by automating end-to-end DLP report generation with AI — 300+ reports, recovering an estimated 150–200+ analyst hours/month.
  • Engineered DLP-specific AI agentic agents and skill prompts for real-time user activity reviews, automated SIEM log analysis, UAM footage review timelines, and self-improving browser-based investigation skills.
  • Architected the Dead Man Switch (DMS) — a multi-layer offboarding lockdown that eliminated unauthorized post-termination device access across 1,500+ terminations: firmware-level OS freeze, cached-credential clearing via RMM/MDM heartbeats, and 20+ blocking controls across DLP/UAM/SIEM.
  • Created an Analyst Action Hub in an AI agent workspace — a daily dashboard for task check-offs, ticket pulls, and completion logging that serves as a live monitor of the entire DLP program for VPs and executives.
  • Owns High Risk User Monitoring (HRUM) — PIPs, suspected IP theft, disgruntled employees, and anomalous behavior; drafted entry/exit reviews spanning weeks to months.
  • Surfaced 80,000+ GB of stale data risk across 4,500+ devices via custom Mac/Windows discovery scripts; drove an automated tiered deletion pipeline.
  • Authored incident playbooks, escalation procedures, and the overall incident response plan; data custodian for Legal/HR e-discovery with compliance across NIST CSF, ISO 27001, GDPR, PCI-DSS, HIPAA, SOX, and SOC 2.

Cybersecurity Analyst

Exelon CorporationChicago, IL2023 – 2025
  • Investigated security incidents using Splunk, CyberArk, and Carbon Black for threat detection, log analysis, and incident response.
  • Assisted in deploying security tooling to 1,500+ endpoints across Linux RHEL 7/8, Windows Server 2016–22, and EMS environments.
  • Developed Splunk SPL queries and dashboards for real-time endpoint monitoring; optimized Carbon Black detection policies.
  • Managed privileged access via CyberArk and identity-based NAC via Aruba ClearPass; maintained NERC CIP compliance.
  • Authored SOPs, incident handling workflows, and troubleshooting guides for cross-team knowledge sharing.

Education

Credentials

B.S.

Cybersecurity

Bellevue University
GPA 4.0 · 2023 · NSA-Recognized

Network Security · Access Control & PKI · Risk Assessments · Database Security · OWASP · Digital Forensics · Penetration Testing · Incident Response · Python

A.S.

Cybersecurity

Joliet Junior College
2021

Networking · OSINT · Cryptography · Log Analysis · Network Traffic Analysis · Forensics · Web App Exploitation · CCNA

Cert

Certificate of Achievement

Joliet Junior College
35 Credit Hours · 2021

CCNA Security · Ethical Hacking · Computer & Network Security · Computer Forensics · Cryptography & Access Control

Compliance coverage
NIST CSFISO 27001NERC CIPGDPRPCI-DSSHIPAASOXSOC 2FISMAOWASP

// context switch

INCIDENT COMMANDER

The person behind the operations

About

Off the clock

Griffin Dutka

I grew up getting into so much trouble with my curiosity — but that same curiosity is what pulled me into computers, and then into security.

This site is part of that, too. I built it from scratch, mostly to find out whether I could. Turns out, yes. I've been sharpening my AI/LLM skillset in both my personal and work life.

AFK, you'll usually find me on ripping walks with my dog, deep in a new PC build or game, or surfing Facebook Marketplace. I'm an Acura fan through and through — that obsession with keeping them spotless became my auto-detailing company (@dondetails), going 6 years now. I live in Chicago's West Loop and love hanging out with friends, going to the lake, and trying new restaurants. If you made it this far — go to Rootstock in Humboldt Park for the BEST burger.

My two dogs on a trail
Trail crew
Custom PC build
Latest build
Acura at night
Late-night cruise
Freshly detailed Acura
Detail day

Contact

Let's talk

Open to security operations, DLP, and AI-automation roles — and always happy to trade notes.