About Me
CTI and DFIR leader based in Nashville. For 12 years I’ve defended a Fortune 100 healthcare environment, investigating major intrusions and leading the team that shut them down.
I spent most of my career in incident response, but the analysis held my attention more than the response. I wanted to know what the adversary was after and whether they got it. Forensics got me in the habit of checking the source before trusting the report, and that habit pushed me toward threat intelligence. So did seeing what a breach can do to patient care.
I moved into management in 2021, built a 15-person SOC and IR group, then split it and took the new DFIR and M&A security function. Today I lead the DFIR practice and the security integration of acquired networks into enterprise monitoring.
I still do the technical work alongside the team. I apply structured analytic techniques to incident investigations, write Python to automate the repetitive work, and teach graduate-level threat intelligence and incident response as adjunct faculty.
Technical Focus & Core Competencies
- Intelligence-Led Incident Response
- Structured Analytic Techniques
- Threat-Informed Defense & MITRE ATT&CK Coverage Measurement
- Detection Engineering & Python Scripting
Education
- B.B.A., M.S. Computer Information Systems, Middle Tennessee State University
Certifications
- GIAC Cyber Threat Intelligence (GCTI)
- GIAC Reverse Engineering Malware (GREM)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Certified Incident Handler (GCIH)
- GIAC Security Essentials (GSEC)
Outside of work
PC hardware, guitar, blues music, geopolitics, and two boys who keep me busy.