I'm a Senior Systems Analyst transitioning into DevSecOps Engineering, with 10+ years in systems analysis, network administration, and process automation. I build automated infrastructure and CI/CD pipelines with security built in from the start: secrets scanning, container hardening, and software supply-chain analysis. Army veteran with a disciplined, mission-focused approach to solving infrastructure and security challenges.
Used Trivy to scan container images for OS package and dependency vulnerabilities, secrets, and misconfigurations. Built a GitHub Actions pipeline to automate image scanning on every build, and documented the full workflow from a vulnerable base image through scan results and remediation.
Generated a Software Bill of Materials (SBOM) with Syft for a containerized application and scanned it for known vulnerabilities using Grype. Triaged 47 initial findings down to the one vulnerability with an available fix, remediated the vulnerable dependency, and rebuilt and rescanned to confirm the fix in CI.
Trained a Random Forest Regression model on ~156,000 NVD vulnerability records (CVE, CISA KEV, and EPSS data) to predict CVSS base severity from underlying attack characteristics (vector, complexity, privileges required, user interaction, scope, CIA impact) plus real-world exploit signals. Achieved an R² of 0.986 on held-out data, with integrity impact and network-based attack vectors as the strongest predictors. Caught and corrected an early data-leakage bug that had inflated an earlier version's accuracy to an unrealistic 99.99%.
Provisioned and configured a DigitalOcean VM for a team capture-the-flag exercise. Hardened SSH (disabled root login, created scoped user accounts), stood up nginx and vsftpd, and built deliberately vulnerable services - anonymous FTP access and path-traversal target directories - to give teammates a live environment for enumeration and exploitation practice.
Implemented Gitleaks to detect and prevent secrets leakage in Git repositories. Added pre-commit hooks for local enforcement, integrated CI/CD scanning with GitHub Actions, and showcased GitHub Advanced Security push protection. Originated as an in-class CI/CD security demo for Introduction to Cybersecurity. Demo includes fake secrets, failing pipeline, remediation, and history cleanup workflow.
To build a personal portfolio site with automated deployments using GitHub Actions + Cloudflare demonstrating GitOps workflow basics, static site hosting, version control, and deployment automation.
Executed and maintained Python scripts to generate datasets for DOE Grid Modernization grant reporting using scripting fundamentals, data extraction, and operational support for compliance workflows.
Open-source collaboration learning GitHub forking, branching, and PR submission workflow for basic open-source contribution practices, collaborative version control skills.
Upgraded Python client code for CloudRF API: refactored for Python 3 compatibility and organized Python 2/3 variants.
Git, GitHub Actions, GitHub Advanced Security, Gitleaks, Trivy, Syft, Grype, Pre-Commit Hooks, SBOM Generation, CVE/CVSS Vulnerability Analysis, Applied ML for Security Scoring
IT Governance, Infrastructure & Network Design, Project Management, Requirements Gathering, UAT, Digital Transformation
Python, Bash, C++, Java, SQL, YAML, Markdown
Linux, Windows Server, VMware, Proxmox, Docker, Kubernetes (k3s), Digital Ocean, nginx, vsftpd
nmap, Wireshark, VLANs, Subnetting, VPNs, Load Balancing, Hardware MFA (YubiKey), TCP/IP
Traefik, n8n, Pi-hole, Homelab Design & Deployment
SQL Server, Oracle, MySQL, PostgreSQL
Itron FDM, Fixed Network 100, OpenWay, SSMS, Oracle Billing & MDM, Cherwell
Coursework spans applied cryptography (symmetric/asymmetric ciphers, hashing, key management, and hardware-based authentication), big data mining with machine learning applied to vulnerability severity prediction, and a secrets-scanning CI/CD demo built for Introduction to Cybersecurity that grew into an ongoing security-tooling project line. Relevant coursework: Applied Cryptography, Big Data Mining & Analytics, Introduction to Cybersecurity.
Completed comprehensive training on IT service architecture design, service lifecycle management, and strategic service planning to align technology solutions with business objectives.
Mastered IT governance frameworks, strategic planning methodologies, and policy development techniques to ensure technology initiatives support organizational goals and compliance requirements.
Developed expertise in project financial management, cost estimation techniques, and timeline development to deliver projects within scope, budget, and schedule constraints.
Gained proficiency in risk identification, analysis, and mitigation strategies while mastering change management methodologies to ensure project adaptability and stakeholder acceptance.
Learned systematic approaches to project initiation, scope definition, stakeholder analysis, and comprehensive planning techniques that establish solid foundations for successful project delivery.
Completed general education with focus on mathematics and computer science, establishing a foundation for future technical studies and career development.
Serving as Secretary for the Student Veteran Organization at Stetson University, coordinating meetings, managing communications, and supporting veteran students in their academic and social endeavors.