Houston, Texas · Bilingual English/Spanish
I investigate security activity, remediate vulnerabilities, and build cloud-security projects across Azure and AWS. My work focuses on vulnerability management, threat hunting, least-privilege access, infrastructure as code, and security automation.
Portfolio · LinkedIn · GitHub Projects
Remote | February 2026–Present
- Perform authenticated Tenable scans across Windows and Linux systems in a live Azure environment.
- Build and test PowerShell remediations aligned with vulnerability findings and DISA STIG guidance.
- Helped reduce identified vulnerabilities by 100% critical, 90% high, and 76% medium through remediation and validation scans.
- Conduct threat hunts in Microsoft Sentinel and Defender for Endpoint for brute-force activity, ransomware behavior, and potential data exfiltration.
- Create endpoint detection rules, investigation workflows, dashboards, and network-security improvements.
Remote | April 2025–August 2025; August 2026–Present
- Protect PHI by applying HIPAA identity-verification and information-disclosure procedures.
- Investigate eligibility, claims, and authorization issues across Epic and internal systems.
- Document and escalate recurring issues that may indicate broader operational or system problems.
- Support members and healthcare providers in English and Spanish.
| Project | What I Demonstrated |
|---|---|
| Vulnerability Management Program | Built an end-to-end workflow for vulnerability discovery, prioritization, remediation, validation, and reporting |
| Secure Terraform Before Deployment | Added restricted SSH, input validation, sensitive-file protection, PowerShell security checks, and GitHub Actions CI |
| AWS CloudTrail Investigation Lab | Investigated AWS API activity using identity, source IP, timestamps, event details, and CloudTrail evidence |
| AWS IAM & EC2 Segmentation | Implemented least-privilege IAM, tag-based authorization, environment separation, and explicit-deny controls |
View all cloud, security, and automation projects →
- Security: Tenable, Microsoft Sentinel, Defender for Endpoint, KQL, threat hunting, vulnerability management, incident investigation, MITRE ATT&CK
- Cloud: Azure VMs, NSGs, RBAC and Monitor; AWS IAM, EC2, S3, VPC, Security Groups and CloudTrail
- Automation: Terraform, GitHub Actions, PowerShell, Bash, Git and CI/CD validation
- Systems: Windows, Linux, Docker, Active Directory, TCP/IP, DNS, DHCP, VPNs and firewalls
- Governance: NIST CSF, ISO 27001 concepts, HIPAA, risk assessment, third-party risk and security documentation
- CompTIA A+
- Microsoft Certified: Azure Fundamentals (AZ-900)
- Google Cybersecurity Professional Certificate
- SOC Analyst Training — Let’s Defend
- GRC Mastery — ISO 27001, NIST CSF, risk management and third-party risk
- In progress: Microsoft Azure Administrator (AZ-104)
Open to opportunities in SOC operations, cloud security, vulnerability management, security engineering, and DevSecOps.
