Cyber Automation Engineer at North Dakota IT specializing in SOAR, incident response, and threat detection. I build automated security solutions that reduce alert fatigue and improve response times.
Current Focus: Building agentic SOC assistants with LLMs, container security tools, and SOAR playbook automation.
- Developed Python scripts to automate security tasks, reducing MTTR by 30%
- Monitored 10+ EDR alerts weekly, lowering false positives by 20%
- Built SOAR playbooks that reduced alert fatigue by 45%
- Used SPL/XQL queries on Splunk/Cortex XSIAM, improving threat detection by 20%
- Performed security design reviews on SaaS infrastructure to validate security measures put in place
- Translated security vulnerabilities into business impact through presentations for non-technical stakeholders
- Tuned detection rules in cloud SIEMs to increase visibility across cloud assets and built playbooks for faster alert triage
- Built APIs for security telemetry across 5,000+ assets
- Created CI/CD pipeline, reducing deployment time from 10 to 4 hours
- Led vulnerability remediation, utlizing the asset inventory tool to reduce vulnerability backlog
- Built Django backend integrations with MySQL databases
- Automated deployments using Fabric and Ansible
Ollama, LangChain, Tines, Splunk, FastAPI
- AI-powered SOC assistant that automates alert triage using 20B-parameter LLM
- Reduces MTTR by 40% through automated SOAR playbook mapping
- Maps Splunk alerts to appropriate incident response workflows
Golang, Docker, Linux
- Automated vulnerability detection for Docker containers
- Real-time dashboard with security insights and remediation guidance
- Covers 5,000+ containers with 99.8% visibility
JavaScript, Gmail.js, Chrome Extensions
- Chrome extension for automated follow-up emails based on labels
- Smart scheduling with customizable intervals
- Improves response rates from 35% to 67%
Security Tools: CrowdStrike Falcon, Splunk ES, Cortex XSIAM, Wazuh, Wireshark, Tenable, Volatility, TheHive
Programming: Python, Golang, Bash, SQL
Cloud: AWS (EC2, EBS, CloudTrail, GuardDuty), Azure (AD, Defender for Cloud)
AI/ML: Ollama, LangChain, FastAPI
Other: Docker, VS Code, Jupyter, ServiceNow, Linux, Windows
π CompTIA Security+
π GIAC Python Coder (GPYC)
βοΈ Microsoft Azure Security Engineer (AZ-500)
Master of Engineering in Cybersecurity - University of Maryland, College Park (2022-2024)
Bachelor of Technology in Computer Science - SRM University, India (2018-2022)
I'm interested in discussing cybersecurity automation, threat detection, and security tooling. Open to collaboration opportunities and industry discussions.