[{"content":"The looser register. One argument per post, three or four minutes, my own voice. The reasoning behind a decision, the tradeoff I picked, and the occasional mistake worth writing down.\nIn the drafts folder # Post The argument Why I did not buy a used Dell Rack servers are cheap until you price the power, the noise, and the drive caddies RAM ate my budget How memory pricing reshaped the whole build plan writing Drafts, not posts yet Two pieces are written and sitting in drafts. They go up once they are worth your four minutes.\nIf you want the technical detail instead of the reasoning, that lives in Writeups.\n","externalUrl":null,"permalink":"/blog/","section":"Blog","summary":"","title":"Blog","type":"blog"},{"content":"","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"A living reference, not a dated post. The lab exists to keep the hands-on side current: segmentation designed like production, telemetry that actually lands somewhere, and detections written against behavior rather than signatures. This page changes as the build does.\nBuild Status # Host and hypervisor Converting the desktop to a Proxmox host, parts sourced In progress Network segmentation Management, services and detonation VLANs with policy between them Ongoing Telemetry and detection Log pipeline first, then detection rules mapped to MITRE ATT\u0026amp;CK Queued Hardware # Proxmox Hypervisor Host Ryzen 9 5900X, 12C/24T 64GB DDR4-3200 A repurposed desktop rather than a used enterprise server. Gigabyte B550 AORUS ELITE V2 board, EVGA SuperNOVA G3 1000W supply. Enough cores and memory to run a segmented lab without a second box or a rack in the garage.\nProxmox KVM Virtualization Quad-Port Intel I350 Network NICGIGA Four gigabit ports Four ports means real segmentation instead of everything sharing one interface. Management, services, and the detonation network stay separate at the NIC rather than only in software.\nVLANs Trunking Segmentation Out-of-Band Management Access Sipeed NanoKVM-PCIe Remote KVM over IP Console access that survives the host being unreachable. The point of a lab is breaking things on purpose, which means needing a way back in that does not depend on whatever just broke.\nRemote Console Recovery 1000VA LiFePO4 UPS Power GoldenMate 600W output Lithium iron phosphate rather than sealed lead acid, for the cycle life and the absence of a replacement schedule. Sized for graceful shutdown, not for riding out an outage.\nRuntime Graceful Shutdown The GPU is still open: an RTX 3080 already on hand against an RTX 3060 12GB for lower idle draw, with local model work and hashcat on the other side of that tradeoff.\nNetwork Design # Three segments, with policy between them rather than a flat network and good intentions.\nflowchart LR WAN((Internet)) --\u003e RTR[Router / Firewall] RTR --\u003e MGMT[Management VLAN] RTR --\u003e SVC[Services VLAN] RTR --\u003e LAB[Lab / Detonation VLAN] MGMT --\u003e PVE[Proxmox Host] SVC --\u003e PVE LAB --\u003e PVE Management carries the hypervisor and out-of-band access. Services carries the things meant to stay up. The detonation segment is where anything untrusted runs, and it does not get to talk to the other two.\nPlanned Services # The stack the lab is being built to support, and what each piece is there to prove.\nGuest Role Why it is here Wazuh SIEM and endpoint telemetry Detection engineering against real host data Grafana + Prometheus Metrics and dashboards Observability that predates the incident OpenVAS / Greenbone Vulnerability scanning Assessment, then the harder half: remediation tracking Ansible Configuration management Rebuilds that are repeatable rather than remembered Documentation wiki Runbooks and architecture The artifact that outlives the lab Still cooking Resource allocation, backup targets, and the writeups that come out of each milestone are not finished yet. Everything above gets documented as it lands, with sanitized configs and playbooks published alongside on GitHub.\nCheck the Writeups section for the pieces that are done.\n","externalUrl":null,"permalink":"/homelab/","section":"Homelab","summary":"","title":"Homelab","type":"homelab"},{"content":" Skills \u0026amp; Tools # AWS AWS Azure / Entra ID Azure / Entra ID Microsoft 365 Microsoft 365 Dynatrace Dynatrace PagerDuty PagerDuty Jenkins Jenkins VMware VMware Cisco Cisco Wireshark Wireshark Linux Linux Ubuntu Ubuntu Debian Debian AWS AWS Azure / Entra ID Azure / Entra ID Microsoft 365 Microsoft 365 Dynatrace Dynatrace PagerDuty PagerDuty Jenkins Jenkins VMware VMware Cisco Cisco Wireshark Wireshark Linux Linux Ubuntu Ubuntu Debian Debian What I do # Incident Management Calls made while the room is loud. Problem Management Root cause reviews that change something. Change Management Maintenance windows nobody has to undo. Service Delivery \u0026amp; SLAs Commitments tracked, not assumed. Team Leadership Five engineers, vendors, and a budget. Cloud \u0026amp; Infrastructure On-prem and cloud run as one estate. Security Operations Triage that surfaces the real one. Compliance \u0026amp; Control Testing Evidence that survives an audit. Identity \u0026amp; Access Least privilege, actually enforced. Monitoring \u0026amp; Observability Alerts that still mean something. Vulnerability Management Findings tracked to closure. Runbooks \u0026amp; Process Documentation that outlives the author. What\u0026rsquo;s cooking # CISSP Targeting November 2026. Deepening the security governance and risk side In progress Home lab buildout Segmentation, telemetry and detection engineering, documented as I go Ongoing Professional Experience # Operations Manager 2021 Beyondsoft Consulting United States (Remote) Led a five-person engineering team supporting enterprise client infrastructure on a five-year assignment at Toyota Motor North America, serving as incident manager for high-impact production events. Audited client AWS accounts for exploitable misconfigurations, administered Entra ID conditional access and MFA, and remediated DDoS vectors through AWS Shield, WAF, and CDN. Owned SLA performance, vendor contracts, and hiring while running the post-incident reviews that turned recurring failures into preventive controls.\nIncident Management AWS Security Entra ID Dynatrace PagerDuty Team Leadership Information Security Analyst 2019 TelevisaUnivision United States (Remote) Triaged SIEM alerts across networks, endpoints, and servers, correlating events to reconstruct incident timelines and investigating spear-phishing campaigns aimed at senior staff. Served as lead LogRhythm administrator, building correlation rules, writing custom parsers for malformed log sources, and mapping detection coverage to MITRE ATT\u0026amp;CK. Planned and executed the SIEM migration onto a restructured server architecture, then validated coverage afterward so monitoring did not silently degrade.\nSIEM Engineering LogRhythm MITRE ATT\u0026amp;CK Detection Rules NIST 800-53 Rapid7 System Administrator 2014 Cigna HealthCare Doral, FL Served as Level 3 escalation point for a support team of four across roughly 350 employees in a HIPAA-regulated environment. Administered Active Directory and Azure AD, Exchange permissions, Group Policy, and MFA, applying least privilege at provisioning and treating revocation at termination as a controlled step rather than an afterthought. Built the standard images and SOPs behind onboarding, deployed security agents through SCCM, and supplied access records and evidence through HIPAA and CMS audit cycles.\nActive Directory Azure AD Group Policy SCCM HIPAA Disaster Recovery IT Support Specialist 2013 Commonwealth-Altadis Fort Lauderdale, FL Imaged and deployed more than 300 machines supporting a sales force of over 1,500 agents. Provisioned Active Directory accounts and OU changes while maintaining ServiceNow asset and user records accurate enough to be worth trusting.\nEndpoint Deployment Active Directory ServiceNow Asset Management Education # B.S. Network Operations and Security 2017 Western Governors University United States (Online) A competency-based program covering network design, network operations, network security, and cloud security, built on a core IT curriculum spanning systems and services, scripting and programming, data management, the business of IT, and web development. Coursework emphasizes network administration methods for uptime, performance, and security, with industry certifications embedded in the degree path. Completed while working full time.\nNetwork Architecture Systems Security Infrastructure Operations National Cyber League, Individual Game 2019 Cyber Skyline United States (Remote) A proctored, hands-on skills assessment scored on both accuracy and completion across ten challenge modules. Competed in the 2019 and 2020 seasons, scoring 1,470 of 3,000 points at 72.9% accuracy in Fall 2019. Strongest in OSINT, cryptography, wireless access exploitation, network traffic analysis, password cracking, and log analysis.\nOSINT Cryptography Network Traffic Analysis Password Cracking Log Analysis Certifications # Security Certified Ethical Hacker (CEH) CompTIA Security\u0026#43; Cloud AWS Certified Cloud Practitioner Network Cisco CCNA Routing \u0026amp; Switching Process ITIL v4 Foundation CompTIA Project\u0026#43; Open to What\u0026rsquo;s Next # \u0026gt; connect --linkedin Open to operations, infrastructure, and security roles: operations and service delivery management, incident and problem management, and security engineering or governance. LinkedIn is the fastest way to reach me. Come say hi.\nConnect on LinkedIn \u0026rarr; ","externalUrl":null,"permalink":"/","section":"Operations, security, and service delivery for enterprise infrastructure","summary":"","title":"Operations, security, and service delivery for enterprise infrastructure","type":"page"},{"content":"Tags appear here as posts get published. They are the fastest way to pull every piece on segmentation, or detection, or compliance, without scrolling two sections.\nwaiting on posts No tags yet Tags are generated from published posts, so this page fills itself in as Writeups and the Blog come online.\n","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":" Add assets/img/author.jpg Ten years in enterprise IT. A decade of operations, five years in a HIPAA-regulated healthcare environment, a year inside a SOC, and five years running operations for the largest automotive brand in the world.\nThe short version # Ten years in enterprise IT, and most of it spent where operations and security overlap.\nThe last five as Operations Manager at Beyondsoft Consulting, embedded at Toyota Motor North America. Five engineers, a global client account, and the phone that rings when something large is broken. I was the incident manager on those calls: severity, coordination, restoration, and the executive update that follows.\nBefore that, a year as an Information Security Analyst at TelevisaUnivision, where the title matched the work. SOC triage, LogRhythm administration, correlation rules, and the SIEM migration I planned and ran end to end.\nBefore that, five years as a system administrator at Cigna HealthCare. HIPAA-regulated, Level 3 escalation, and the place where I learned that audit evidence and a ticket queue are the same job.\nBased out of Florida. Bilingual, hablo español.\nThe through line # Two tracks have run side by side for my whole career: keeping environments operating, and keeping them defensible. Most of my roles have asked for both at once, and the ones that only asked for one were the exception.\nAt Cigna I was the escalation point for a support team in a HIPAA-regulated environment, which meant identity administration and audit evidence were part of the same job as the ticket queue. At TelevisaUnivision the title was security analyst and the work matched it: SOC triage, lead LogRhythm administrator, correlation rules and custom parsers, detection coverage mapped to MITRE ATT\u0026amp;CK, spear-phishing investigations, and a SIEM migration I planned and executed end to end.\nThen I moved into operations leadership at Beyondsoft, and neither track stopped. I ran incident and problem management for a global client account, owned SLA performance and vendor contracts, coordinated change and maintenance windows, and led five engineers. In the same role I audited client AWS accounts for exploitable misconfigurations, administered Entra ID conditional access and MFA, remediated DDoS vectors through Shield and WAF, owned the certificate lifecycle, and supported the annual SOC review against ISO 27001.\nAcross three employers I have supported audit and control testing in five regulatory domains: SOX and PCI DSS in media, HIPAA and CMS in healthcare, ISO 27001 in consulting. I have tested control design and operating effectiveness against NIST 800-53 and NIST CSF, tracked findings to closure in ServiceNow against the CMDB, performed user access reviews, and documented formal risk acceptance for approved exceptions.\nSo I am not picking a lane. Operations leadership and security engineering draw on the same instincts, and I would rather be useful in both than narrow to one. The CISSP and the lab are how I keep the technical side current while the leadership side keeps growing.\nWhere I\u0026rsquo;m Strongest # Incident management # When a production system is down and five teams are talking at once, someone assigns severity, coordinates the response, decides when to escalate, and tells the client\u0026rsquo;s executives what is happening in language they can act on. I did that for five years. The underrated part is the post-incident review that turns a recurring failure into a runbook change.\nRunning a team and a queue # Five engineers, a shared backlog, an on-call rotation, and SLA commitments somebody is measuring. The work is triage discipline, clear ownership, and removing the recurring noise so the team spends its time on what actually matters. Hiring, one-on-ones, and vendor contracts come with it.\nDetection engineering # Writing a correlation rule is easy. Writing one that fires on real adversary behavior, does not bury the analyst in false positives, and maps to a technique you can name is the actual skill. Suppression logic and signal-to-noise are where most SIEM deployments quietly fail.\nControl testing that survives an auditor # Evidence, ownership, and closure. Correlating a finding against the CMDB so it lands on the team that can fix it, then capturing closure evidence before the audit cycle asks for it.\nIdentity lifecycle # Joiner, mover, leaver. Least privilege at provisioning, revocation at termination treated as a controlled step rather than an afterthought, and access reviews across AD, Entra ID, and AWS IAM.\nTranslating between audiences # Explaining a SIEM finding to an application team, the same finding to a compliance stakeholder, and the business impact of both to a client executive. This is most of the job in any senior role and almost nobody lists it.\nWhat this site is # Three things, in three registers.\nHomelab is the maintained architecture reference for the lab I am building. Hardware, segmentation, service layout. A living document, not a dated post. Writeups are the formal technical pieces: network segmentation, telemetry pipelines, detection engineering, vulnerability management, control mapping. Methodology and evidence, written for practitioners. Blog is looser and shorter. The reasoning behind a decision, the tradeoff I picked, the occasional mistake worth writing down. Sanitized artifacts live alongside the writing on GitHub: playbooks, configs, detection rules, control mappings.\nWhat\u0026rsquo;s cooking # CISSP Targeting November 2026. Deepening the security governance and risk side In progress Home lab buildout Segmentation, telemetry and detection engineering, documented as I go Ongoing Find Me # ","externalUrl":null,"permalink":"/about/","section":"Operations, security, and service delivery for enterprise infrastructure","summary":"","title":"whoami","type":"page"},{"content":"The formal register. Methodology, decisions, and evidence, written for practitioners rather than recruiters. Each piece comes out of a milestone in the lab, with sanitized configs and playbooks published alongside on GitHub.\nWhat\u0026rsquo;s planned # Writeup Covers Network segmentation VLAN design, inter-segment policy, and what the detonation network is allowed to reach Asset and software inventory Knowing what is on the network before trying to defend it Telemetry pipeline Log sources, collection, retention, and the cost of keeping everything Detection engineering Rules written against behavior, mapped to MITRE ATT\u0026amp;CK, tuned for signal Vulnerability assessment Scanning, scoping, and reading output without drowning in it Vulnerability management The harder half: ownership, remediation, and tracking to closure CIS Controls v8 mapping The capstone. Controls mapped to implemented evidence drafting Nothing published yet The lab has to run before the writeups mean anything. First pieces land as each milestone completes, starting with segmentation.\nIn the meantime, the Homelab page tracks build status, and the Blog will carry the shorter reasoning behind decisions.\n","externalUrl":null,"permalink":"/writeups/","section":"Writeups","summary":"","title":"Writeups","type":"writeups"}]