20 years in telecommunications, the last four building and troubleshooting Layer 2 and Layer 3 services on Nokia carrier-grade MPLS infrastructure across California, Nevada, Arizona, and Idaho. GIAC-certified in incident handling (GCIH) and security essentials (GSEC), with penetration testing credentials in progress. Runs a self-operated security research homelab and is applying two decades of carrier-level network depth to a move into network security.
Raspberry Pi 4 running Cowrie SSH/Telnet honeypot and Suricata 7.0 IDS with Emerging Threats ruleset, reporting to the SANS Internet Storm Center (sensor ID 3000055796). Live threat intelligence dashboard auto-updated every 30 minutes. Authored two threat intelligence reports documenting the Redtail cryptominer campaign (May 2026) and Outlaw/mdrfckr IRC botnet infrastructure (May 2026).
TryHackMe Jr Penetration Tester path, top 2% globally, 157 rooms completed. HackTheBox Starting Point machines. Methodology, tooling, and findings documented in a public GitHub vault. Active tools: nmap, gobuster, Burp Suite, Caido, Metasploit, Responder, Hashcat.