During my time at MITRE, I contributed to several impactful projects that shaped modern cybersecurity practices. As part of the team that developed the industry-transforming ATT&CK ® framework, I worked on initiatives that bridged defensive and offensive security operations, building tools and techniques still used across the industry.

Roles

Senior Cyber Security Engineer

Apr 2015 - Jan 2017

  • CASCADE Project Lead: Created and led development of an application to automatically correlate and triage detected malicious activity on endpoints.
  • Adversary Emulation: Performed red teaming for MITRE and government sponsors, leveraging ATT&CK® and novel techniques to improve organizational resilience.
  • Windows Sensor Development: Designed and implemented a Windows endpoint sensor to detect and prevent malicious credential access.
  • CALDERA Development: Developed and patented CALDERA, a platform to automate adversary emulation based on ATT&CK® techniques.

Cyber Security Engineer

Jun 2013 – Apr 2015

  • Detection Engineering: Authored novel analytics for the Cyber Analytics Repository to reduce attacker dwell time and built custom tooling to enhance blue team investigation processes
  • API tracing and anomaly detection: Built software that encompassed a Windows driver and service to hook and trace Windows APIs, along with analysis to detect anomalies in system call flows with symbol matching.
  • Core Research Contributions: Collaborated on several neighboring projects tied to ATT&CK®, advancing both detection and response strategies.

Recognitions

  • Network Attack Simulation Systems and Methods: Patent for CALDERA (US #10218735, granted on 2019-02-16)
  • Program Recognition Award: For outstanding contributions to an adversary emulation program for a government sponsor

Skills

  • Detection Engineering
  • Adversary Emulation (Red Teaming)
  • Endpoint Security Development
  • Windows API Monitoring and Tracing
  • Windows Driver Development
  • Python Programming
  • Offensive and Defensive Security Research
  • C/C++ Programming
  • Splunk
  • Powershell