Security operations · Instructor

Learn how to build defenses that hold under pressure.

I lead security operations at Black Hills Information Security, teach SOC and SIEM courses through Antisyphon Training, and run Noct InfoSec for independent projects and content.

About

Nearly a decade in the SOC.

Operations, incident response, detection engineering, automation, and teaching — usually all at once.

I spend most of my time at Black Hills on the things that matter when alerts start stacking: detection quality, investigation workflows, and the operational habits that keep a team from drowning in noise. The goal is always fewer false positives, faster triage, and systems that analysts actually trust.

Through Antisyphon and Noct, I teach and package that same work: SIEM engineering, alert triage, and detection logic for defenders trying to build durable capability instead of checking compliance boxes.

Focus

Where the work happens.

Projects

Things I've shipped.

Connect

Get in touch.

Most active on GitHub and LinkedIn.