Security professional with 8+ years of experience in IT and cybersecurity, with deep expertise in incident response, threat detection, and security assessments across hybrid and SaaS environments. Proven track record in leading enterprise-wide monitoring initiatives, designing and executing response plans, and driving remediation efforts in collaboration with legal, executive, and technical stakeholders. Skilled in applying threat intelligence, log analysis, and risk-based controls to strengthen organizational security posture.
Overview
10
10
years of professional experience
1
1
Certification
Work History
Application Security Specialist
KPMG JESS
09.2024 - Current
Lead over 20 security reviews for on-prem, SaaS, and PaaS applications using a NIST-CSF-adapted baseline.
Evaluated controls around access, logging, secure coding, patching, and vulnerability management.
Prioritized remediation based on PII/PHI sensitivity, exposure, and risk severity.
Coordinate with developers, architects and risk teams to ensure timely remediation of identified security gaps and alignment with business objectives.
Tracked risks using Archer and Microsoft Planner.
Influenced architectural changes after discovering missing TDE in high-criticality application.
IT Security Specialist
RJRGLEANER Communications Group
09.2021 - 08.2024
Conducted daily IOC sweeps (IPs/domains/hashes) tied to phishing and password spray attempts.
Used VirusTotal and Cisco Talos for IOC validation; escalated findings to CTO.
Analyzed payloads in malicious emails to extract hashes.
Reported IOC trends to support threat hunt prioritization.