I started in access administration at Tata Consultancy Services, setting up SAP users and chasing down the reasons people could not get into the systems they needed. It was unglamorous work and it turned out to be the right foundation — deciding who is allowed to do what is where a great deal of security actually lives. I finished an M.S. in Cybersecurity at CSU Dominguez Hills in May 2026 and spent that time building the things I wanted to be able to point at.
What I am best at is detection: writing the rules that recognise an attack, and building the plumbing that gets the evidence to them. I built a security monitoring system, wrote 32 rules for it, and then pointed real machines at it — an Ubuntu machine, a Windows machine, and a Kali machine actually attacking them both. Two multi-step attacks were caught. Most of what I learned came from what broke afterwards.
I trust measurements over assumptions, which is mostly a habit of distrusting my own work. My scoring code looked fine until real traffic showed it was calling Cloudflare an attacker — around 82% false alarms. I fixed it, declared victory off one clean run, watched the false alarms come back, and only then went through all 25 addresses it had ever flagged and scored them again. That is the version I trust. The same habit turned up a limit that could be bypassed by asking a different server, and an application that could not see who any of its visitors actually were.
I led the CSUDH Cybersecurity Club as vice president and then president, recruited a six-person officer team, and ran a 120-member community. For our annual competition I designed and built the entire platform — 167 challenges, over a hundred servers, three difficulty tracks and a five-act story, on one rented machine, in 17 days. Sixty-two people competed on it for three and a half hours. Before that I spent two years as a supplemental instruction leader and teaching assistant, which is where I learned that explaining something clearly is a separate skill from knowing it.
My lab runs often enough to keep breaking in interesting ways. I am in the top 4% on TryHackMe with 119 rooms completed, and I write up the ones worth writing up — including the defensive rule, because stopping at the answer has always felt like doing half the job. Right now I am working through AI security, partly out of self-interest: I built five escalating prompt-injection challenges for the competition and I would like to be better at both sides of that.
I have unreasonably strong opinions about cooking. Every recipe gets my own edit, and you have not had a proper sandwich until you have had one of mine. I like people, which turns out to matter more in this work than it sounds like it should.