01
Malware Analysis & Reverse Engineering
Unpack malicious behavior, inspect execution paths, and translate opaque samples into operationally useful findings.
Technical Depth for High-Stakes Security Work
Cybersecurity Engineer | Reverse Engineering | Security Automation
I build analyst-facing systems, investigation workflows, and automation that help teams move faster from suspicious signal to defensible engineering output across malware analysis, detection, and large-scale network environments.
Operational security tooling
Build investigation aids, triage systems, and enrichment workflows that reduce repetitive analyst effort without hiding the evidence.
Reverse engineering with practical outcomes
Translate suspicious behavior into detection ideas, response context, and engineering decisions that are useful beyond a single incident.
Infrastructure-aware security execution
Work across network telemetry, cloud-connected systems, and platform operations to improve resilience, observability, and response speed.
Core Strength
Reverse engineering, malware triage, and detection-focused security tooling
Operating Range
Security operations, network engineering, and infrastructure automation
What Teams Get
Faster analyst workflows, clearer evidence, and higher-signal engineering outputs
Value Proposition
This portfolio is centered on technical depth: understanding malicious behavior, engineering repeatable workflows, and producing outputs that analysts and security teams can use immediately.
01
Unpack malicious behavior, inspect execution paths, and translate opaque samples into operationally useful findings.
02
Design analyst-facing workflows, AI-assisted triage systems, and detection pipelines that reduce repetitive investigation time.
03
Connect network telemetry, indicators, behaviors, and infrastructure into engineering outputs that improve reliability, detection, response, and decision support.
Featured Projects
Each project is structured as a technical case study with problem framing, design decisions, workflow architecture, and security impact.
An analyst-focused triage environment that reduces the time required to classify suspicious binaries and scripts.
A pipeline for unpacking heavily obfuscated JavaScript and extracting behavior relevant to detection and threat understanding.
A contained research environment for emulating IoT threats, observing device behavior, and validating security hypotheses.
A rule-driven code analysis engine for identifying risky patterns and surfacing high-value security findings early.
A correlation layer that links infrastructure, indicators, and behaviors into a usable analyst-facing threat picture.
Research
These write-ups support the case studies above by showing how analysis thinking, deobfuscation work, and automation patterns are documented and explained.
A workflow for profiling obfuscated JavaScript, simplifying AST structure, recovering behavior, and converting findings into useful defensive output.
A structured workflow for moving from suspicious sample intake to evidence, behavioral conclusions, and defensive output.
Skills
The emphasis here is not keyword volume. It is capability across reverse engineering, analyst tooling, detection workflows, and platform operations.
Experience Highlights
This section stays compact by design. The emphasis is on engineering scope, operational impact, and the ability to work across network infrastructure, incident response, and automation.
Designed and supported network operations across WAN, MPLS, IPVPN, SaaS, and hybrid environments while applying Python, PowerShell, APIs, and Terraform-based automation to improve validation, observability, and escalation response.
Led deep-dive malware investigations, converted reverse engineering output into actionable detections, and improved analyst decision speed through automation-assisted suspicious file triage.
Built and tuned static analysis logic, automation workflows, and telemetry-driven investigation processes to surface risky code behaviors earlier and reduce manual review overhead.
Produced technical threat narratives, research artifacts, and automation-ready knowledge outputs that helped teams understand adversary behavior, investigation strategy, and cross-domain telemetry patterns.
Maintained visibility into network events, handled escalations across routers, switches, and WAN links, and supported disciplined incident workflows for fault isolation and service restoration.
Why Teams Hire Me
I work at the intersection of network engineering, security analysis, and automation execution. The common thread is turning ambiguous security problems into practical workflows, clearer evidence, and more reliable operator decisions.
That means moving beyond isolated analysis into reusable output: triage systems, investigation tooling, deobfuscation workflows, static analysis logic, and infrastructure-aware security processes that improve signal quality without increasing noise.
Contact
The fastest path is email. Public profiles are also available for hiring teams, collaborators, and clients who want a faster review cycle.