I started at the help desk. Moved through systems engineering and network security, then into the SOC. I love all of it. Working alerts, hunting through telemetry for things that automated tools miss, handling incidents from first alert to resolution. Threat hunting and incident handling feed each other and I want to be good at both.
At Red Canary I hunted full time across major EDR platforms. Found a threat actor with a 2-month undetected VPN compromise running AD brute force. Identified malicious LNK files pointing to C2 and infostealers like Chihuahua Stealer. I got to take real hunts and work with the detection engineering team to convert them into production rules.
At Secnap Network Security, I hunted across customer environments, handled incidents from triage through resolution, and helped build the operation's endpoint coverage, customer portal, SOC dashboard, workflow system, and response processes.
I'm starting as a Security Analyst II at Garner Health. The role covers security operations, threat hunting, cloud infrastructure, observability, detection engineering, automated response, AWS security controls, SQL-based analysis, and LLM-assisted security workflows.