Security + Systems Engineer& Automation Specialist
Cybersecurity and Systems Engineer specializing in SecOps, EDR, and systems administration. I harden Windows/Linux fleets, build automation platforms and scripts, and keep infrastructure reliable at scale.
Focus
SecOps, EDR engineering, and zero-trust controls
Strength
Automation platforms, scripting, and fleet hardening
Output
Reliable infrastructure with reduced alert noise
let profile = {
focus: 'SecOps · EDR · Automation',
experience: '10+ years',
location: 'Colorado Springs, CO',
email: 'root@bryant.dev',
}
Technical Skills
Detailed Competencies
- Endpoint Security: SentinelOne (Multi-tenant Admin, API), CrowdStrike Falcon (Flight Control, Fusion SOAR), ThreatLocker
- Automation: PowerShell (Advanced), Python, Bash, REST APIs (S1, CS, Microsoft Graph)
- Cloud & Identity: Microsoft Entra ID, Azure Administration, Microsoft Graph, Google Workspace
- Infrastructure: Windows Server, Linux (Debian/Ubuntu/RHEL), VMware (vSphere/ESXi), Hyper-V, VirtualBox
- Networking: Syslog, VPNs, ACLs, VLANs; WatchGuard, Cisco Firepower/Meraki, Fortinet
- Tooling: Horizon3.ai NodeZero, BreachSecureNow, Acronis Cloud, PDQ, ConnectWise PSA/RMM, ScreenConnect, Splunk (Cribl)
Certifications
Experience
Cybersecurity Engineer (ThreatLocker Specialist)
Contract
Details under NDA
Cybersecurity Engineer
Visual Edge IT
Led EDR engineering and security automation for an MSP/MSSP fleet of ~17,000 endpoints, acting as Tier 3 escalation and bridging SecOps with systems administration and log visibility.
- Enterprise EDR Engineering
- Administered a multi-tenant SentinelOne deployment (~17,000 endpoints, 700+ tenants), tuning STAR rules, exclusions, and indicator blocklists to reduce false positives.
- Led CrowdStrike Falcon onboarding with Flight Control and parent/child CIDs; scripted policy migrations with PSFalcon and leveraged Falcon RTR for rapid response.
- Designed and implemented configurable network quarantine policies using JSON syntax to create granular allow-lists for essential services (DNS/DHCP/DC).
- Security Automation & Tooling
- Engineered custom PowerShell automation (SentinelOne AIO Toolkit) to standardize agent lifecycle management and execute mass remediation.
- Developed automated incident response workflows via CrowdStrike Falcon Fusion (SOAR) and Microsoft Teams.
- Scripted the automated provisioning of Azure App Registrations via Microsoft Graph API.
- Vulnerability Management & Zero Trust
- Administered ThreatLocker zero-trust endpoint policies (Ring-Fencing) and evaluated unknown binaries in sandbox environments.
- Managed Horizon3.ai NodeZero autonomous pentesting platform to schedule regular continuous vulnerability assessments.
- Infrastructure & Log Visibility
- Integrated client networks into SOC SIEM by configuring syslog forwarding (WatchGuard, Meraki, Fortinet) and deploying Cribl collectors to Splunk.
Linux Systems Administrator
HardenedVPN LLC
Managed daily operations of a secure, globally distributed VPN infrastructure across 6 regions, ensuring high availability under active attack conditions.
- Administered Debian/RHEL Linux servers across 6 regions with responsibility for uptime, patching, and OS hardening.
- Managed SSH access controls (authorized_keys, sudoers, PAM) and enforced least-privilege authentication policies.
- Built and maintained host-level firewall policies with iptables/nftables, including ACLs and rate limiting during incidents.
- Architected L3/L4 DDoS mitigation using Cloudflare Magic Transit and GRE tunneling for latency-sensitive services.
- Resolved Linux service failures and performance degradation through log analysis and configuration review.
System Administrator
Contract
Details under NDA
Sr. Technical Support Advisor III
Apple Inc.
Senior escalation point within AppleCare, resolving the most complex macOS and iOS issues. Specialized in security-sensitive cases involving account recovery, data integrity, and device trust.
- Provided Tier 3 support for macOS and iOS, handling security issues including Apple ID recovery and iCloud integrity.
- Diagnosed and resolved software faults, system crashes, and performance issues via log analysis and profiling.
- Mentored junior advisors on escalated cases, improving consistency in technical troubleshooting and support practices.
- Collaborated with engineering teams to document edge-case bugs and contribute to internal knowledge base articles.
Projects
SentinelOne AIO Toolkit
Designed and shipped a one-touch S1 lifecycle tool that standardizes purge/install/rollback across heterogeneous Windows fleets. Used in production to recover endpoints broken by unstable agent builds.
SocksFlareProx
Deploys HTTP proxy endpoints on Cloudflare Workers and runs local SOCKS proxies that tunnel traffic through those endpoints for IP masking and flexible routing.
NextgeNmap
Cross-platform GUI for Nmap using Python and Qt. Adds reusable scanning profiles and report automation, transforming XML output into human-readable HTML reports.
Home Lab Platform
Production-style home lab with MikroTik routing/switching (10GbE), UniFi gateway/APs, and Rocky Linux + Windows Server infrastructure. Hosts 100+ TB of storage, containers, and security tooling for sysadmin and IR prototyping.
Education
Cybersecurity Bootcamp (Professional Education)
Colorado State University / Fullstack Academy
Completed 36 CEUs (360 hours) of hands-on labs in network, host, and application security.
Ranked 1st in cohort Capture-the-Flag (CTF) competitions.