Vulnerability Management
- Tenable on-prem and Cloud
- scan policy design
- CrowdStrike EDR
- sandbox CVE impact evaluation
- risk-ranked triage
- remediation verification
Endpoint Security Engineer
Endpoint security engineer working across Mac, Windows, and Linux fleets at enterprise scale. At NVR I expanded vulnerability scanning from on-prem-only Tenable to Tenable Cloud, then designed the automation program that took a standing backlog of 5,000+ open findings down to a steady state holding 98%+ patch compliance across 6,500+ devices. The mechanism was a library of Ivanti Neurons bots enforcing configuration uniformity — killing whole classes of finding at the source rather than re-remediating the same ones every cycle. I threat-model systems before they enter the environment, evaluate CVEs in a sandbox against our own configuration rather than trusting vendor severity, and hunt embedded dependencies across the software estate when something like Log4Shell lands. I own the full loop: find the exposure, decide what matters, write the fix when no vendor patch exists, and land it without taking the business offline.
NVR, Inc. Reston, VA
February 2021 — Present
ATPCO Herndon, VA
July 2019 — January 2021
Neustar, Inc. Sterling, VA
2017 — 2019
The proving ground
Everything I deploy at work gets built and broken here first. It is a production-grade environment I run end to end — compute, storage, networking, identity, secrets, monitoring, and CI — which means I hit the failure modes on my own time instead of during a change window.
Three-node Proxmox VE cluster with Ceph distributed storage and shared CephFS, plus two Unraid servers for bulk and backup. HA failover across nodes; serial reboots gated on verified kernel/boot-id change rather than SSH reachability.
Public traffic terminates on a cloud VPS running Pangolin, tunnels in over WireGuard-based Newt agents, and lands on Traefik for routing and ACME certificates via DNS challenge. Segmented VLANs separate management, VM, and IoT traffic behind a UDM.
Authentik provides SSO and forward-auth in front of internal services. OpenBao holds every stack secret in KV v2 — machine access via a read-only AppRole, human access via OIDC, auto-unseal on restart, and the initial root token revoked in favour of a documented break-glass path.
Trimmed Traefik from blanket trust of forwarded headers down to an explicit trusted-proxy list after proving a LAN client could forge X-Forwarded-For and poison downstream audit logs and brute-force reputation. Fixing it at the proxy corrected every backend at once — the same reasoning I apply to enterprise control placement.
Kestra and n8n orchestrate scheduled and event-driven jobs; Semaphore drives Ansible; Gitea hosts source and act-runner executes pipelines. Infrastructure and stack definitions live in git and deploy with secrets rendered at deploy time, never committed.
Prometheus and Grafana for metrics, Uptime Kuma for external probes, node-exporter across hosts, PatchMon for patch state, and ntfy for alert delivery — so drift and outages surface before anyone notices them.
Northern Virginia Community College · 2015