Building out the internal penetration testing program, running iterative assessments across Azure, Microsoft 365, AWS, SaaS, identity systems, enterprise applications, and externally exposed assets. Findings address exploitable misconfigurations, privilege escalation paths, excessive permissions, authentication weaknesses, and attack surface exposure.
Core stakeholder in the internal AI security program, helping shape assessment scope, evaluate LLM-enabled workflows, identify data exposure risks, and define secure adoption boundaries around AI tooling, DLP controls, and prompt handling.
Advancing Zero Trust architecture across Microsoft 365 and Azure through Conditional Access hardening, Azure Policy and policy-as-code enforcement, privileged access reviews, PIM administration, least-privilege enforcement, and identity governance improvements.
Improving detection and response capabilities by tuning Microsoft Defender XDR and Sentinel analytics, refining suppression logic, building investigation workflows, and improving triage consistency.
Driving vulnerability validation and remediation through Rapid7 and Microsoft Defender findings, assessing exploitability and business impact, and working directly with system owners on risk-based remediation planning.
Developing Terraform and infrastructure-as-code security standards, reviewing module configurations, validating deployment risk, and defining enforceable cloud security guardrails through Azure Policy.
Contributing to cloud and network architecture reviews, including Azure NSG configurations, network segmentation design, and security engineering input on the network backbone rearchitecture.