Security engineering
Building and improving the systems a security team relies on every day.
- SOC engineering. Log pipelines, SIEM configuration, alert routing, and the operational plumbing that keeps a security operations center running.
- Detection engineering. Writing, tuning, and testing detections against real log data, with documentation an analyst can act on.
- AI-assisted security operations. Putting AI tools to work on triage, investigation support, and detection authoring, with a human engineer reviewing every result.
- Vulnerability management. Scanning, prioritization, and remediation workflows that fit how your environment is actually built.
- Cloud security. Reviewing and hardening cloud configurations, identity, and logging coverage.
- Security automation. Scripts, integrations, and small internal tools that remove manual steps from security work, often built with Claude Code.