
About me
Software Engineer graduated from UIA, passionate about technology for as long as he can remember.
More than 5 years of experience in cybersecurity, protecting real infrastructure.
In his free time he builds home labs, studies AI, and develops his own systems.
He's worked remotely from more than 10 countries doing what he loves.
- role:
- Senior Cybersecurity Engineer
- education:
- UIA graduate
- experience:
- +5 years in cybersecurity
- remote from:
- 10+ countries, working remote
- off hours:
- home labs, applied AI, building my own systems
Experience
Security Architect
- +Owns day-to-day onboarding and operation of SIEM and EDR platforms for enterprise accounts.
- +Leads customer onboarding for Microsoft Sentinel and Splunk — log ingestion, indexes, forwarders, and detection rules.
- +Works daily across EDR platforms (Carbon Black, SentinelOne, Microsoft Defender for Endpoint, CrowdStrike) on migrations and detection tuning.
- +Supported 50+ security platform migrations and serves as the Microsoft Subject Matter Expert (SME) for the account.
Cybersecurity Engineer
- +Secured Azure deployments with CLI, PowerShell, and Runbooks to automate security controls.
- +Designed and deployed hybrid cloud security with Sentinel, AIP, Defender, and ATP.
- +Deployed Microsoft Sentinel and Defender for Endpoint to centralize threat monitoring and response.
- +Automated cloud deployments with IaC (Bicep, ARM templates) and extended governance with Azure Arc.
Infrastructure Security Technician
- +Resolved hardware and performance issues across Windows and Linux environments.
- +Analyzed security and performance logs using Dell SupportAssist tooling.
- +Hardened systems — applied patches, disabled unused services, configured RAID for data reliability.
- +Managed cloud-based Linux server deployments and administration on Azure.
Security Engineer
- +Designed and implemented Microsoft Sentinel solutions to enhance threat detection.
- +Fine-tuned Microsoft Defender settings, improving endpoint security and response.
- +Managed email security tools (Proofpoint, KnowBe4) against phishing and other threats.
- +Optimized Cisco Umbrella deployments, strengthening network security and traffic filtering.
SOC Analyst Intern
- +Monitored and investigated security incidents across client environments.
- +Analyzed security events with QRadar to identify potential threats.
- +Managed alerts across multiple vendors (IBM, Cisco, Juniper) for prompt incident response.
- +Led and coordinated a team of analysts, covering 24/7 on-call incident response.
Network Security Engineer
- +Monitored network traffic and analyzed logs to detect potential threats.
- +Configured and maintained firewalls, VPNs, and IDS/IPS to strengthen network security.
- +Conducted vulnerability assessments and proposed mitigation strategies.
- +Contributed to disaster recovery and business continuity planning.
Projects
Endpoint Health Dashboard

Customer names and report links cropped out of view for client privacy.
Built a dashboard that pulls every endpoint and site from a company's SentinelOne tenant via API, then checks each agent's version and OS against SentinelOne's officially published support baseline — flagging what's current, aging, or legacy. Generates per-customer reports that help IT and security teams keep agents up to date and stay within support standards.
- SentinelOne API
- Python
- Dashboards
- Reporting
AI Research Agent

Live 'quick' depth run — 28 sources, QC score 85/100.

Every citation traces to a real, retrievable source — nothing invented.

The actual pipeline: trigger & validation → planning & web research → synthesis & QC → finalize & respond.
An agentic n8n pipeline that turns a one-line topic into a citation-backed, quality-checked research report. It plans research questions, searches the live web, ranks sources by credibility, extracts individually-sourced facts, catches contradictions between sources, and writes a polished report — running it through an automated QC gate that sends it back for correction, up to twice, before returning it. Every claim traces back to a real, retrievable URL, and the pipeline runs identically on OpenAI or a fully local Ollama model. The example below is a live 'quick' depth run on "AI in Cybersecurity: Current Applications and Emerging Risks in 2026" — 28 real sources, QC score 85/100.
- n8n
- OpenAI
- Ollama
- Tavily
- LangChain
- JavaScript
NovaTech Sales Intelligence RAG Chatbot

The full agent graph — 7 tools wired in, live chat test on the left, real execution log (~1543 tokens, 22.4s) on the right.
An internal B2B sales chatbot built entirely as n8n workflows — no separate app or frontend — combining RAG over a 125-document knowledge base with real-time structured queries against Postgres. Runs entirely on local Ollama models (qwen3:8b + qwen3-embedding): zero cloud API dependency, zero per-token cost. The agent combines 7 tools: semantic search (pgvector) for judgment calls — positioning, objection handling, competitive comparisons — and real-time SQL queries via PostgREST for exact facts like pricing, accounts, and deals, never inventing a number and citing its sources on every answer. Validated with real live testing, not just code review — that process found and fixed 12 real bugs (n8n/local-agent framework incompatibilities, data-flow semantics, and an architecture mismatch between real Supabase and self-hosted PostgREST), each documented with root cause and fix. Verified against the live agent with an end-to-end battery of 20 questions, backed by full synthetic data: 484 chunks across 125 documents.
- n8n
- Supabase
- Postgres
- pgvector
- Ollama
- PostgREST
Technologies & tools
EDR
- S1SentinelOne
- CSCrowdStrike
- MDEMicrosoft Defender for Endpoint
Network / Traffic analysis
- Wireshark
- SUSuricata
- Snort
- NMNmap
SIEM
- SENMicrosoft Sentinel
- Splunk
- Elastic SIEM
Languages & dev tools
- JavaScript
- Python
- Bash
- PSPowerShell
- HTML5
- CSS
- Claude Code
- CXCodex
- Git
- GitHub
- Postman
- Node.js
- React
- YAML
- JSON
- SQLSQL
- Supabase
AI & Automation
- Ollama
- OLMOpenLLM
- n8n
- Make
- Hugging Face
- LangChain
- AOAIAzure OpenAI
- FDYMicrosoft Foundry
- LOVLovable
Cloud & Infrastructure
- AZAzure
- AWSAWS
- Google Cloud
- Docker
- Kubernetes
- Terraform
Vulnerability Scanners
- NENessus
- OVOpenVAS
Achievements

Certifications
Free Cybersecurity Starter Roadmap
A short, no-fluff PDF covering the four main ways into cybersecurity, a basic starter path, and which entry-level certifications actually matter. It's the 10,000-foot view — enough to get oriented. If you want a roadmap built around your own background and timeline instead, that's what career coaching is for.
Services
Pick one to start the conversation.
Contact
Got an automation idea, a cloud environment that needs hardening, or want a roadmap into the field? Reach out.