I spend most of my time at Black Hills on the things that matter when alerts start stacking: detection quality, investigation workflows, and the operational habits that keep a team from drowning in noise. The goal is always fewer false positives, faster triage, and systems that analysts actually trust.
Through Antisyphon and Noct, I teach and package that same work: SIEM engineering, alert triage, and detection logic for defenders trying to build durable capability instead of checking compliance boxes.