Navigation
AboutExperienceBlogResourcesMerchContact

inquiries@ctijen.com

Experience

Real-world CTI impact

Senior Threat Intelligence Analyst with 8+ years in cybersecurity and 6+ years focused on CTI, specializing in full-lifecycle intelligence programs, AI-assisted automation, and translating threat intelligence into measurable defensive outcomes.

Threat Actor Tracking

Who I actually track

A few of the actors and campaigns I follow closely, in enough detail to actually talk through:

Public writeups of the same kind of work: Scattered Spider / MGM, mapped to the Diamond Model and Why I Wouldn't Mess With Iran.

Impact Highlights

What I deliver

Designed and built an end-to-end AI-assisted threat intel pipeline (LLM triage, staged MCP-server escalation, hallucination-checking judge model) that routes validated intel to 6 stakeholder teams through a self-serve, tunable intelligence requirements system, cutting low-signal OSINT analysis by 3-5 hours per week.
Track and profile threat actors including Scattered Spider/The Com, DPRK fraudulent IT worker operations, and ClickFix-style malware delivery campaigns.
Delivered intelligence reports and threat briefings to director and C-staff audiences with business impact framing.
Professional Timeline

Roles and responsibilities

Senior Threat Intelligence Analyst - Zendesk (Remote)

2019 - Present
  • Own full CTI lifecycle: stakeholder planning, collection, analysis, dissemination, and iterative feedback loops.
  • Partner across Detection Engineering, Incident Response, Red Team, Compliance, and Vulnerability Management to operationalize intelligence.
  • Built and maintained TIP workflows to evaluate feeds, automate triage, and route high-fidelity findings into defensive actions.
  • Translate intelligence into ATT&CK-aligned guidance for detection, hunting, and simulation teams.
  • Track high-risk actor landscape with recurring reporting and leadership-ready impact summaries.

Security Operations Engineer - Zendesk

2018 - 2019
  • Monitored and triaged security alerts across the environment, escalating confirmed incidents to the appropriate response teams.
  • Built the foundational security operations experience that led directly into a newly created CTI function the following year.

IT Global Service Desk Specialist - Zendesk

March 2017 - 2018
  • Resolved enterprise endpoint, SaaS, telephony, and collaboration platform issues in high-volume environments.
  • Partnered with IAM to support identity provisioning and access control workflows across Okta and OneLogin.

Genius (Hardware and Software Technician) - Apple - Madison, WI

January 2014 - March 2017
  • Performed certified hardware diagnostics and repair for macOS and iOS devices.
  • Built strong customer communication habits that now inform clear executive and stakeholder security reporting.
Flagship Project

An AI-assisted threat intel pipeline

Designed and built an end-to-end pipeline that takes a raw threat report from ingestion all the way to a validated, stakeholder-ready alert, with no manual triage in the middle unless something actually needs a human.

  • A playbook in our TIP triggers on every ingested report, which an LLM triages against our tech stack, industry, and architecture before anything moves forward.
  • Relevant reports are written to GitHub and kick off a GitHub Actions workflow that checks them against a running history to avoid duplicate alerts, with exceptions for evolving threats (a PoC that becomes a KEV) or anything independently corroborated elsewhere.
  • Findings cascade through staged internal MCP servers, documentation first, then infrastructure, then exploitability, deliberately escalating only as evidence accumulates to keep token usage sane.
  • Exploitability assessment accounts for compensating controls (a vulnerable service sitting behind SSO, for example) and cross-references live vulnerability management data, including SLA and ownership.
  • A judge LLM reviews every assessment for hallucinated CVEs or fabricated evidence before it reaches a human; anything flagged comes to me for review over our messaging platform.
  • Built and maintain a self-serve intelligence requirements app (vibe-coded) so stakeholder teams can see exactly which keywords and filters drive their feed and tune it themselves, with lightweight thumbs up/down feedback and satisfaction tracking built in.
  • Track pipeline health end-to-end: story volume, false positive rate, automation failures, and stakeholder satisfaction, with an on-demand reporting tool so any team can pull a threat-landscape summary for a given date range.

That pipeline runs inside Zendesk and its code isn't mine to share. On my own time, I built a separate, standalone project from scratch that mimics its first stage, ingestion and triage, so I'd have something real to open source:

Open Source Work

A personal project, built outside of work

AI-Assisted CTI OSINT Pipeline

A personal project, independent of Zendesk, that mimics the ingestion, triage, and deduplication approach from the pipeline above: point it at your own RSS feeds and threat actor watchlist and get analyst-ready outputs (Markdown, HTML, JSON, and STIX 2.1).

  • AI-powered validation against a configurable list of threat actors and feeds, with confidence scoring to cut noise.
  • Concurrent processing with intelligent caching and exponential backoff, built to run on a schedule via cron or GitHub Actions.
  • Fully configurable through a single file, feeds, actors, and lookback windows, no code changes required to retarget it.
View project on GitHub ↗
Tools and Credentials

Execution stack

Tools and Frameworks

  • ThreatConnect, Recorded Future, TruSTAR, Pulsedive, ZeroFox, MISP
  • Splunk, DataDog, Anvilogic
  • CrowdStrike, Carbon Black, Umbrella, Netskope, Mimecast, AWS
  • Python, Terraform, Atlantis, GitHub, XSOAR, Torq, Cursor, MCPs, Anthropic/OpenAI models
  • VirusTotal, DomainTools, Shodan, Talos, URLScan, Jira, Zendesk
  • MITRE ATT&CK, MITRE DeTT&CT, MITRE INFORM, Diamond Model, Cyber Kill Chain, NIST, CIS, OWASP

Certifications and Trainings

  • GIAC GSEC
  • Recorded Future Certified Analyst
  • Mandiant Cyber Intelligence Production
  • SANS FOR578 Cyber Threat Intelligence Class Challenge Coin Recipient
  • Splunk User Certified
  • AWS Cloud Practitioner
  • Zendesk Support Administrator
  • Python3 - Codecademy
  • CS50: Introduction to Computer Science (Harvard, in progress)
Education: B.S. Rehabilitation Psychology - University of Wisconsin-Madison (December 2013)
View speaking and community work