Security + Systems Engineer& Automation Specialist

Cybersecurity and Systems Engineer specializing in SecOps, EDR, and systems administration. I harden Windows/Linux fleets, build automation platforms and scripts, and keep infrastructure reliable at scale.

17,000+ endpoints secured700+ tenants managed6-region infra ops

Focus

SecOps, EDR engineering, and zero-trust controls

Strength

Automation platforms, scripting, and fleet hardening

Output

Reliable infrastructure with reduced alert noise

let profile = {

focus: 'SecOps · EDR · Automation',

experience: '10+ years',

location: 'Colorado Springs, CO',

email: 'root@bryant.dev',

}

Technical Skills

Operating stack:RHEL / RockyDebian / UbuntuWindows ServerVMwareHyper-VMikroTikUniFi
Endpoint Security
Automation (PwSh/Python)
Cloud & Identity (Entra ID)
Systems Administration
Networking & Firewalls
Security Tooling

Detailed Competencies

  • Endpoint Security: SentinelOne (Multi-tenant Admin, API), CrowdStrike Falcon (Flight Control, Fusion SOAR), ThreatLocker
  • Automation: PowerShell (Advanced), Python, Bash, REST APIs (S1, CS, Microsoft Graph)
  • Cloud & Identity: Microsoft Entra ID, Azure Administration, Microsoft Graph, Google Workspace
  • Infrastructure: Windows Server, Linux (Debian/Ubuntu/RHEL), VMware (vSphere/ESXi), Hyper-V, VirtualBox
  • Networking: Syslog, VPNs, ACLs, VLANs; WatchGuard, Cisco Firepower/Meraki, Fortinet
  • Tooling: Horizon3.ai NodeZero, BreachSecureNow, Acronis Cloud, PDQ, ConnectWise PSA/RMM, ScreenConnect, Splunk (Cribl)

Certifications

Experience

Cybersecurity Engineer (ThreatLocker Specialist)

Contract

2026

Details under NDA

ThreatLockerEndpoint SecurityZero Trust

Cybersecurity Engineer

Visual Edge IT

2025

Led EDR engineering and security automation for an MSP/MSSP fleet of ~17,000 endpoints, acting as Tier 3 escalation and bridging SecOps with systems administration and log visibility.

  • Enterprise EDR Engineering
    • Administered a multi-tenant SentinelOne deployment (~17,000 endpoints, 700+ tenants), tuning STAR rules, exclusions, and indicator blocklists to reduce false positives.
    • Led CrowdStrike Falcon onboarding with Flight Control and parent/child CIDs; scripted policy migrations with PSFalcon and leveraged Falcon RTR for rapid response.
    • Designed and implemented configurable network quarantine policies using JSON syntax to create granular allow-lists for essential services (DNS/DHCP/DC).
  • Security Automation & Tooling
    • Engineered custom PowerShell automation (SentinelOne AIO Toolkit) to standardize agent lifecycle management and execute mass remediation.
    • Developed automated incident response workflows via CrowdStrike Falcon Fusion (SOAR) and Microsoft Teams.
    • Scripted the automated provisioning of Azure App Registrations via Microsoft Graph API.
  • Vulnerability Management & Zero Trust
    • Administered ThreatLocker zero-trust endpoint policies (Ring-Fencing) and evaluated unknown binaries in sandbox environments.
    • Managed Horizon3.ai NodeZero autonomous pentesting platform to schedule regular continuous vulnerability assessments.
  • Infrastructure & Log Visibility
    • Integrated client networks into SOC SIEM by configuring syslog forwarding (WatchGuard, Meraki, Fortinet) and deploying Cribl collectors to Splunk.

Linux Systems Administrator

HardenedVPN LLC

2019 — 2024

Managed daily operations of a secure, globally distributed VPN infrastructure across 6 regions, ensuring high availability under active attack conditions.

  • Administered Debian/RHEL Linux servers across 6 regions with responsibility for uptime, patching, and OS hardening.
  • Managed SSH access controls (authorized_keys, sudoers, PAM) and enforced least-privilege authentication policies.
  • Built and maintained host-level firewall policies with iptables/nftables, including ACLs and rate limiting during incidents.
  • Architected L3/L4 DDoS mitigation using Cloudflare Magic Transit and GRE tunneling for latency-sensitive services.
  • Resolved Linux service failures and performance degradation through log analysis and configuration review.

System Administrator

Contract

2017 — 2019

Details under NDA

FirewallsInformation SecuritySystems Administration

Sr. Technical Support Advisor III

Apple Inc.

2014 — 2017

Senior escalation point within AppleCare, resolving the most complex macOS and iOS issues. Specialized in security-sensitive cases involving account recovery, data integrity, and device trust.

  • Provided Tier 3 support for macOS and iOS, handling security issues including Apple ID recovery and iCloud integrity.
  • Diagnosed and resolved software faults, system crashes, and performance issues via log analysis and profiling.
  • Mentored junior advisors on escalated cases, improving consistency in technical troubleshooting and support practices.
  • Collaborated with engineering teams to document edge-case bugs and contribute to internal knowledge base articles.

Projects

SentinelOne AIO Toolkit

Creator & Maintainer2025

Designed and shipped a one-touch S1 lifecycle tool that standardizes purge/install/rollback across heterogeneous Windows fleets. Used in production to recover endpoints broken by unstable agent builds.

PowerShellAutomationSentinelOne API

SocksFlareProx

Creator & Maintainer2025

Deploys HTTP proxy endpoints on Cloudflare Workers and runs local SOCKS proxies that tunnel traffic through those endpoints for IP masking and flexible routing.

PythonCloudflare WorkersSOCKSHTTP

NextgeNmap

Project Lead2023 - 2025

Cross-platform GUI for Nmap using Python and Qt. Adds reusable scanning profiles and report automation, transforming XML output into human-readable HTML reports.

PythonQtNmapSecurity Tools

Home Lab Platform

Designer & OperatorOngoing

Production-style home lab with MikroTik routing/switching (10GbE), UniFi gateway/APs, and Rocky Linux + Windows Server infrastructure. Hosts 100+ TB of storage, containers, and security tooling for sysadmin and IR prototyping.

Rocky LinuxWindows ServerMikroTikUniFi

Education

Cybersecurity Bootcamp (Professional Education)

2023

Colorado State University / Fullstack Academy

Completed 36 CEUs (360 hours) of hands-on labs in network, host, and application security.

Ranked 1st in cohort Capture-the-Flag (CTF) competitions.