Security-focused IT professional with 4+ years investigating business email
compromise, triaging email threats, and administering identity and endpoint
security across Microsoft 365 and Azure environments.
SOC-Relevant Experience
// grouped by function, pulled across roles
Email Threat Triage & BEC Response
Triaged Proofpoint quarantine alerts — validated flagged messages with end users, made release/block determinations
Investigated and remediated Business Email Compromise: removed malicious inbox rules, reset compromised credentials per Microsoft best-practice procedures
Co-developed annual phishing simulation playbook (Cofense) — designed campaign scenarios and cadence to measure user detection capability
Identity & Log Analysis
Pulled and analyzed Active Directory / Entra ID logs during access investigations to identify unauthorized access and anomalous authentication activity
Administered Entra ID identity lifecycle — provisioning, deprovisioning, MFA enforcement
Built a Power Automate flow to automate MFA reset alerting to the security team, replacing a manual process
Triaged Proofpoint email quarantine alerts, validating flagged messages with end users and making release or block determinations to protect against phishing and malicious content.
Pulled and analyzed Active Directory and Azure Entra ID logs during access investigations to identify unauthorized access attempts and anomalous authentication activity.
Built a Power Automate flow to automate MFA reset notifications to the security team, replacing a manual email process and ensuring consistent alerting on every reset.
Administered BeyondTrust endpoint privilege management — deploying agents, troubleshooting permission issues, and analyzing blocked path logs to resolve access control conflicts.
Provisioned with CrowdStrike Falcon access to perform endpoint containment actions on managed laptops.
Contributed to SCCM to Microsoft Intune migration — performing device conversions, troubleshooting enrollment and policy issues, and documenting procedures for the transition.
Executed hands-on Windows device upgrades across 500+ global endpoints, handling coordination and knowledge base documentation throughout the initiative.
IT Service Desk Level 2 (Contract)
Century Therapeutics, Philadelphia, PA
Sept 2023 – Aug 2024
Managed SentinelOne endpoint agent deployments and decommissioning through the console across the organization.
Administered Azure AD / Entra ID identity lifecycle including user provisioning, deprovisioning, and MFA enforcement — serving as the primary IT resource during MSP-to-in-house IT transition.
IT Coordinator / Support Engineer
Qualitest, Remote
Feb 2023 – Aug 2023
Improved device recovery rates by 35% and achieved 100% on-time delivery by redesigning laptop and mobile device deployment processes across North America.
Implemented Power Automate workflows to reduce manual effort in device allocation and recovery, improving operational consistency and reducing error rates.
Reduced IT procurement costs by 10% through vendor selection improvements, increasing service quality for end users.
Senior IT Support Analyst
Mutual of Omaha Mortgage, San Diego, CA
Dec 2020 – Feb 2023
Investigated and remediated Business Email Compromise incidents — identifying and removing malicious inbox rules, resetting compromised credentials, and following Microsoft best practice remediation procedures.
Performed malware identification and removal on compromised endpoints using Malwarebytes, serving as the sole IT and security resource during transition from MSP to in-house IT operations.
Co-developed annual phishing simulation playbook using Cofense, designing campaign scenarios and testing cadence to measure and improve user threat detection capabilities.
Served as first-line incident responder across all security and IT events with no dedicated security team, independently triaging and resolving threats.