Experience
Real-world CTI impact
Senior Threat Intelligence Analyst with 8+ years in cybersecurity and 6+ years focused on CTI, specializing in full-lifecycle intelligence programs, AI-assisted automation, and translating threat intelligence into measurable defensive outcomes.
Threat Actor Tracking
Who I actually track
A few of the actors and campaigns I follow closely, in enough detail to actually talk through:
- Scattered Spider / The Com: track evolving domain infrastructure, pivoting from known indicators to related registrations and hosting patterns using urlscan.io.
- DPRK fraudulent IT worker operations: analyze the Contagious Interview and Wagemole campaigns, distinguishing financially-motivated infiltration (working roles while remitting income to evade sanctions, alongside opportunistic reconnaissance) from dedicated reconnaissance operations with shorter dwell times.
- ClickFix-style campaigns: track fake OS-cleaning lure pages pushed through SEO-poisoned sponsored search ads, abusing infrastructure like pages.dev, AI-platform artifact hosting, and Craft.do, including encoded curl payloads that deploy AMOS and Mac Sync stealers on macOS.
Public writeups of the same kind of work: Scattered Spider / MGM, mapped to the Diamond Model and Why I Wouldn't Mess With Iran.
Impact Highlights
What I deliver
Designed and built an end-to-end AI-assisted threat intel pipeline (LLM triage, staged MCP-server escalation, hallucination-checking judge model) that routes validated intel to 6 stakeholder teams through a self-serve, tunable intelligence requirements system, cutting low-signal OSINT analysis by 3-5 hours per week.
Track and profile threat actors including Scattered Spider/The Com, DPRK fraudulent IT worker operations, and ClickFix-style malware delivery campaigns.
Delivered intelligence reports and threat briefings to director and C-staff audiences with business impact framing.
Professional Timeline
Roles and responsibilities
Senior Threat Intelligence Analyst - Zendesk (Remote)
2019 - Present
- Own full CTI lifecycle: stakeholder planning, collection, analysis, dissemination, and iterative feedback loops.
- Partner across Detection Engineering, Incident Response, Red Team, Compliance, and Vulnerability Management to operationalize intelligence.
- Built and maintained TIP workflows to evaluate feeds, automate triage, and route high-fidelity findings into defensive actions.
- Translate intelligence into ATT&CK-aligned guidance for detection, hunting, and simulation teams.
- Track high-risk actor landscape with recurring reporting and leadership-ready impact summaries.
Security Operations Engineer - Zendesk
2018 - 2019
- Monitored and triaged security alerts across the environment, escalating confirmed incidents to the appropriate response teams.
- Built the foundational security operations experience that led directly into a newly created CTI function the following year.
IT Global Service Desk Specialist - Zendesk
March 2017 - 2018
- Resolved enterprise endpoint, SaaS, telephony, and collaboration platform issues in high-volume environments.
- Partnered with IAM to support identity provisioning and access control workflows across Okta and OneLogin.
Genius (Hardware and Software Technician) - Apple - Madison, WI
January 2014 - March 2017
- Performed certified hardware diagnostics and repair for macOS and iOS devices.
- Built strong customer communication habits that now inform clear executive and stakeholder security reporting.
Flagship Project
An AI-assisted threat intel pipeline
Designed and built an end-to-end pipeline that takes a raw threat report from ingestion all the way to a validated, stakeholder-ready alert, with no manual triage in the middle unless something actually needs a human.
- A playbook in our TIP triggers on every ingested report, which an LLM triages against our tech stack, industry, and architecture before anything moves forward.
- Relevant reports are written to GitHub and kick off a GitHub Actions workflow that checks them against a running history to avoid duplicate alerts, with exceptions for evolving threats (a PoC that becomes a KEV) or anything independently corroborated elsewhere.
- Findings cascade through staged internal MCP servers, documentation first, then infrastructure, then exploitability, deliberately escalating only as evidence accumulates to keep token usage sane.
- Exploitability assessment accounts for compensating controls (a vulnerable service sitting behind SSO, for example) and cross-references live vulnerability management data, including SLA and ownership.
- A judge LLM reviews every assessment for hallucinated CVEs or fabricated evidence before it reaches a human; anything flagged comes to me for review over our messaging platform.
- Built and maintain a self-serve intelligence requirements app (vibe-coded) so stakeholder teams can see exactly which keywords and filters drive their feed and tune it themselves, with lightweight thumbs up/down feedback and satisfaction tracking built in.
- Track pipeline health end-to-end: story volume, false positive rate, automation failures, and stakeholder satisfaction, with an on-demand reporting tool so any team can pull a threat-landscape summary for a given date range.
That pipeline runs inside Zendesk and its code isn't mine to share. On my own time, I built a separate, standalone project from scratch that mimics its first stage, ingestion and triage, so I'd have something real to open source:
Open Source Work
A personal project, built outside of work
AI-Assisted CTI OSINT Pipeline
A personal project, independent of Zendesk, that mimics the ingestion, triage, and deduplication approach from the pipeline above: point it at your own RSS feeds and threat actor watchlist and get analyst-ready outputs (Markdown, HTML, JSON, and STIX 2.1).
- AI-powered validation against a configurable list of threat actors and feeds, with confidence scoring to cut noise.
- Concurrent processing with intelligent caching and exponential backoff, built to run on a schedule via cron or GitHub Actions.
- Fully configurable through a single file, feeds, actors, and lookback windows, no code changes required to retarget it.
View project on GitHub ↗Tools and Credentials
Execution stack
Tools and Frameworks
- ThreatConnect, Recorded Future, TruSTAR, Pulsedive, ZeroFox, MISP
- Splunk, DataDog, Anvilogic
- CrowdStrike, Carbon Black, Umbrella, Netskope, Mimecast, AWS
- Python, Terraform, Atlantis, GitHub, XSOAR, Torq, Cursor, MCPs, Anthropic/OpenAI models
- VirusTotal, DomainTools, Shodan, Talos, URLScan, Jira, Zendesk
- MITRE ATT&CK, MITRE DeTT&CT, MITRE INFORM, Diamond Model, Cyber Kill Chain, NIST, CIS, OWASP
Certifications and Trainings
- GIAC GSEC
- Recorded Future Certified Analyst
- Mandiant Cyber Intelligence Production
- SANS FOR578 Cyber Threat Intelligence Class Challenge Coin Recipient
- Splunk User Certified
- AWS Cloud Practitioner
- Zendesk Support Administrator
- Python3 - Codecademy
- CS50: Introduction to Computer Science (Harvard, in progress)
Education: B.S. Rehabilitation Psychology - University of Wisconsin-Madison (December 2013)