I'm an ISO 27001 Certified Lead Auditor with 3+ years in IT, now focused on cybersecurity and GRC — governance, risk assessment, security controls, and audit-ready compliance. I pair an operations mindset with hands-on blue-team practice through home labs (Wazuh, Sentinel, Sysmon, MITRE ATT&CK).
Who I am and what I bring to a team.
I'm an ISO 27001 Certified Lead Auditor and IT professional with hands-on experience managing IT operations, supporting users, and administering systems and networks in fast-paced environments.
My focus is cybersecurity and GRC — governance, risk assessment and management, security controls, and compliance processes — backed by practical blue-team work with Wazuh, Microsoft Sentinel, Sysmon, and MITRE ATT&CK, documented on my blog.
My six newest repositories, pulled live from GitHub — ordered by when I created them, so updating an older repo won't push it into this list.
My six latest posts, pulled automatically from Medium as I publish.
A tight overview of what I do and what I've earned — the full picture on request.
ISO 27001 Lead Auditor — cybersecurity governance, risk assessment & management, security controls, compliance processes, and GRC frameworks.
Blue-team fundamentals — SIEM (Wazuh, Microsoft Sentinel), Sysmon, MS Defender, VirusTotal, MITRE ATT&CK, and Windows event-log analysis.
Linux & Red Hat Enterprise Linux, VMware virtualization, network switch & wireless AP configuration.
3+ years in IT — IT management, user support, and systems & network administration.
Open to IT support, GRC, and SOC opportunities. The fastest way to reach me is below.
Say hello