SOC ANALYST · OT/ICS SECURITY LEAD

OPEN TO SELECTED COLLABORATIONS

I watch industrial networks so a breach doesn't reach the physical world.

I monitor and investigate security events across industrial environments — turning network telemetry from passive OT monitoring platforms into risk decisions, incident response and client-facing reporting grounded in ISA/IEC 62443 and MITRE ATT&CK for ICS.

ENGINEERING LENS
OT-first risk context
OPERATING MODEL
Detection to decision
FRAMEWORKS
62443 · ATT&CK for ICS
01

OT / ICS Security

Passive network visibility, asset inventory, industrial risk and alignment to ISA/IEC 62443.

02

Security Operations

Alert triage, investigation and incident response mapped to MITRE ATT&CK for ICS.

03

Technology & Data

Automation, dashboards and practical experimentation with AI in security workflows.

01 / STORY

Security is more than tools. It is context.

I trained as a mechatronics engineer, which means I started by learning how physical systems actually work before I ever looked at a security alert.

That background shapes how I work a SOC OT queue today. An alert on a PLC or an engineering workstation isn't just an IOC — it's tied to a process, a Purdue level, a piece of equipment that can't just be patched or rebooted like an office laptop. Useful security in industrial environments starts with understanding how the plant actually runs, not just what the sensor flagged.

Day to day, that means passive network monitoring, investigating and escalating alerts, tracking vulnerabilities against what's actually exploitable, and writing client-facing reports that hold up against ISA/IEC 62443 and MITRE ATT&CK for ICS. Increasingly, it also means building small tools — dashboards, automation, AI-assisted workflows — to make that work faster and less repetitive.

C-Level Reporting

Translating technical risk into language executives can act on and decide from.

Client Risk Communication

Explaining vulnerability exposure and prioritization clearly to clients, not just to other analysts.

Cross-Functional Collaboration

Working daily across networking, IT support, automation and maintenance engineering teams, and C-Levels.

TECHNICAL STACK

OT/ICS Visibility Platforms Secure Remote Access Platforms OT Endpoint Protection Platforms SIEM Power BI Python Agentic AI-Assisted Development
Mechatronics Engineering
Cybersecurity
Security Operations
OT / ICS Security
Next

02 / SELECTED WORK

Problems I like solving.

The areas I spend most of my time in. Client and site-specific details stay out by design.

SOC / DETECTION

Detection Engineering

Turning raw telemetry into actionable detections, correlations and repeatable analyst workflows.

SOCSIEMDetection

DATA / OBSERVABILITY

Security Analytics

Using dashboards and automation to make operational data easier to interpret and act on.

AnalyticsBIAutomation

PERSONAL PROJECT / VULNERABILITY INTELLIGENCE

CVEMaxxing

A vulnerability-prioritization app I built and deployed on Vercel, combining NVD, CISA KEV and EPSS into one view — so "is this CVE actually worth escalating" has a faster, evidence-based answer. Access is gated behind Google sign-in or an invite token.

Visit OT Daily
NVDCISA KEVEPSSVercel

03 / EXPERIENCE

A career built across operations, engineering and consulting.

CURRENT CHAPTER

SOC Analyst N2 & OT Security Lead, Cybolt

Passive network monitoring, incident investigation, vulnerability management and client-facing reporting for industrial managed-security clients.

FOUNDATION

SOC Analyst, Security Operations

Alert triage, detection and investigation workflows, building the operational habits that now carry over into OT-specific work.

ORIGIN

Mechatronics Engineering

Trained on how physical and control systems actually operate — the lens I still use when I look at an OT alert today.

04 / AI & EMERGING TECHNOLOGY

Building with AI, without treating security as an afterthought.

Where I use AI day-to-day in security work — and how I think about the risk of AI systems that act, not just answer.

AI + SECURITY

AI-assisted security engineering

Exploring where AI can accelerate analysis, coding, research and security workflows while keeping human judgment, validation and security-by-design in the loop.

AICybersecurityAutomationHuman-in-the-loop

AGENTIC SYSTEMS

Security by design for agents

Thinking about identity, permissions, tool access, data boundaries and observability as AI systems become more autonomous.

AI-NATIVE WORKFLOWS

From assistant to operational leverage

Experimenting with ways AI can reduce repetitive work, help structure technical information and make security knowledge easier to use.

05 / SECURITY ANALYTICS LAB

Security data, shaped into decisions.

A live dashboard I built for this site, pulling directly from the CISA KEV catalog — the kind of vulnerability-prioritization view I build for OT clients, minus the client data.

SECURITY ANALYTICS LAB / 001

No embedded BI service — this fetches CISA's Known Exploited Vulnerabilities feed in your browser, with an automatic GitHub mirror fallback if the primary source is unreachable. Filter by vendor, product, ransomware activity or date range to see how it holds up under real data.

06 / INSIGHTS

What I am writing about.

Follow on LinkedIn ↗

Three pieces I'm currently drafting, based on questions I run into often on the OT SOC floor. Follow on LinkedIn for early notes as they're written, or check back here once they're published.

OT SECURITY

Visibility before detection

Why understanding coverage and telemetry is essential before evaluating whether a control can detect a threat.

DRAFTING · PUBLISHING SOON

AI + SECURITY

Security by design in the agentic era

Thoughts on what increasingly capable AI systems mean for engineering and cybersecurity teams.

DRAFTING · PUBLISHING SOON

SOC

Measuring the value of security operations

Why alert and ticket volume alone rarely tell the complete story of a security operation.

DRAFTING · PUBLISHING SOON

07 / OUTSIDE THE SOC

Photography.

The same habit that makes me good at OT visibility — noticing structure, patterns and what's actually in frame — shows up here too, pointed at skylines instead of network maps.

San FranciscoSkyline / 01
San FranciscoArchitecture / 02
San FranciscoTravel / 03
San FranciscoCity / 04
San FranciscoBay / 05
ChicagoLakefront / 06
ChicagoNight / 07
ChicagoRiver / 08
ChicagoSkyline / 09
ChicagoArchitecture / 10
New YorkCity / 11
New YorkPortrait / 12

08 / CONTACT

Open to OT security, SOC and analytics conversations.