Security professional with 5+ years in GRC, vulnerability management, and compliance — currently a GRC Information Security Analyst leading PCI-DSS assessments, SOC 2 audits, and vendor risk programs. Manage Crowdstrike and Nessus. CISSP certified. Double B.S. in Cyber Operations and Network & Security Administration from Dakota State University.
breachday.io — a SaaS tabletop exercise platform for enterprise security teams. Facilitators run live incident response (BC/IR) simulations with real-time inject delivery, role-based participation, and post-exercise reporting. No participant accounts needed — just a room code.
vigilus.dev — a self-hosted AI operations platform that orchestrates model-agnostic agents ("Operators") against real infrastructure (SSH, Docker, Wazuh SIEM via MCP), enforcing a just-in-time, scoped-token permission system with full audit logging for all read/write actions.
|
|
|
|
|
|
|
|
| area | tools & frameworks |
|---|---|
| compliance | PCI-DSS · SOC 2 · NIST · ISO 27001 |
| vuln management | Tenable.SC · Nessus · Qualys |
| threat management | CrowdStrike · LogRhythm · Palo Alto · Proofpoint |
| offensive | penetration testing · DevSecOps · CTF competitor |
| scripting | Python · PowerShell · Bash |
🏆 CISSP · CrowdStrike Fal.Con CTF — 9th/53 · LogRhythm CTF — 29th/105 · TryHackMe top 7% · USAF Cyber Patriot — 3rd Place State
layout affectionately stolen from jc21, who affectionately stole it from Pius Walter



