OT / ICS Security
Passive network visibility, asset inventory, industrial risk and alignment to ISA/IEC 62443.
SOC ANALYST · OT/ICS SECURITY LEAD
OPEN TO SELECTED COLLABORATIONS
I monitor and investigate security events across industrial environments — turning network telemetry from passive OT monitoring platforms into risk decisions, incident response and client-facing reporting grounded in ISA/IEC 62443 and MITRE ATT&CK for ICS.
Passive network visibility, asset inventory, industrial risk and alignment to ISA/IEC 62443.
Alert triage, investigation and incident response mapped to MITRE ATT&CK for ICS.
Automation, dashboards and practical experimentation with AI in security workflows.
01 / STORY
I trained as a mechatronics engineer, which means I started by learning how physical systems actually work before I ever looked at a security alert.
That background shapes how I work a SOC OT queue today. An alert on a PLC or an engineering workstation isn't just an IOC — it's tied to a process, a Purdue level, a piece of equipment that can't just be patched or rebooted like an office laptop. Useful security in industrial environments starts with understanding how the plant actually runs, not just what the sensor flagged.
Day to day, that means passive network monitoring, investigating and escalating alerts, tracking vulnerabilities against what's actually exploitable, and writing client-facing reports that hold up against ISA/IEC 62443 and MITRE ATT&CK for ICS. Increasingly, it also means building small tools — dashboards, automation, AI-assisted workflows — to make that work faster and less repetitive.
Translating technical risk into language executives can act on and decide from.
Explaining vulnerability exposure and prioritization clearly to clients, not just to other analysts.
Working daily across networking, IT support, automation and maintenance engineering teams, and C-Levels.
TECHNICAL STACK
02 / SELECTED WORK
The areas I spend most of my time in. Client and site-specific details stay out by design.
OT SECURITY / VISIBILITY
Building visibility around industrial assets, communications, risk and security-relevant activity.
SOC / DETECTION
Turning raw telemetry into actionable detections, correlations and repeatable analyst workflows.
DATA / OBSERVABILITY
Using dashboards and automation to make operational data easier to interpret and act on.
PERSONAL PROJECT / VULNERABILITY INTELLIGENCE
A vulnerability-prioritization app I built and deployed on Vercel, combining NVD, CISA KEV and EPSS into one view — so "is this CVE actually worth escalating" has a faster, evidence-based answer. Access is gated behind Google sign-in or an invite token.
Visit OT Daily↗03 / EXPERIENCE
CURRENT CHAPTER
Passive network monitoring, incident investigation, vulnerability management and client-facing reporting for industrial managed-security clients.
FOUNDATION
Alert triage, detection and investigation workflows, building the operational habits that now carry over into OT-specific work.
ORIGIN
Trained on how physical and control systems actually operate — the lens I still use when I look at an OT alert today.
04 / AI & EMERGING TECHNOLOGY
Where I use AI day-to-day in security work — and how I think about the risk of AI systems that act, not just answer.
AI + SECURITY
Exploring where AI can accelerate analysis, coding, research and security workflows while keeping human judgment, validation and security-by-design in the loop.
AGENTIC SYSTEMS
Thinking about identity, permissions, tool access, data boundaries and observability as AI systems become more autonomous.
AI-NATIVE WORKFLOWS
Experimenting with ways AI can reduce repetitive work, help structure technical information and make security knowledge easier to use.
05 / SECURITY ANALYTICS LAB
A live dashboard I built for this site, pulling directly from the CISA KEV catalog — the kind of vulnerability-prioritization view I build for OT clients, minus the client data.
SECURITY ANALYTICS LAB / 001
No embedded BI service — this fetches CISA's Known Exploited Vulnerabilities feed in your browser, with an automatic GitHub mirror fallback if the primary source is unreachable. Filter by vendor, product, ransomware activity or date range to see how it holds up under real data.
SOC PORTFOLIO DASHBOARD / KEV
| CVE | Vulnerability name | Vendor | Product | Date added | Due date | Ransomware |
|---|---|---|---|---|---|---|
| Loading CISA KEV data… | ||||||
SECURITY ANALYTICS LAB
Same filters I'd reach for when triaging a vulnerability list against a client's environment: what's being actively exploited, which vendors and products show up most, and what changed recently enough to matter for this week's prioritization call.
06 / INSIGHTS
Three pieces I'm currently drafting, based on questions I run into often on the OT SOC floor. Follow on LinkedIn for early notes as they're written, or check back here once they're published.
OT SECURITY
Why understanding coverage and telemetry is essential before evaluating whether a control can detect a threat.
DRAFTING · PUBLISHING SOONAI + SECURITY
Thoughts on what increasingly capable AI systems mean for engineering and cybersecurity teams.
DRAFTING · PUBLISHING SOONSOC
Why alert and ticket volume alone rarely tell the complete story of a security operation.
DRAFTING · PUBLISHING SOON07 / OUTSIDE THE SOC
The same habit that makes me good at OT visibility — noticing structure, patterns and what's actually in frame — shows up here too, pointed at skylines instead of network maps.