•Hardened email authentication (SPF, DKIM, DMARC) across 1,300+ domains for 150+ portfolio startups, achieving 98%+ authentication alignment and reducing spoofing incidents by 60% within six months.
Infrastructure Monitoring Dashboard
•Developed a real-time infrastructure monitoring dashboard delivering live visibility across 1,300+ domains and 2,700+ inboxes, replacing a two-hour manual daily health-check process.
IOC Hunting & Detection Engineering
•Conducted IOC/IOA indicator hunting across 250+ phishing, BEC, and malware incidents triaging with VirusTotal, tri.ge, Hunt.io, SOCRadar, and IBM X-Force; extracting indicators across sender IPs, domains, and file hashes; and writing YARA/Sigma rules sustaining a 90%+ remediation rate and reducing false positives by 25%.
SOC Automation
•Built n8n SOAR pipelines automating phishing triage, IOC enrichment, and email blocking, cutting mean incident response time from 4 hours to under 75 minutes across high-volume alert queues.
Threat Intelligence Pipelines
•Engineered MCP-based threat intelligence pipelines correlating CVEs, adversary TTPs, and OSINT indicators, and mapped campaign techniques to MITRE ATT&CK to shift team posture from reactive ticket-closing to proactive threat profiling.
Domain Abuse Monitoring
•Hunted and dismantled 30+ lookalike-domain and phishing URL campaigns, shrinking the portfolio attack surface by 40%, by conducting domain threat hunting with Webamon, WHOIS, and Cloudflare RDAP to trace attacker infrastructure and identify malicious patterns before user impact.
Worked with
Brands I’ve worked with
Email infrastructure, DFIR, and detection work shipped across 150+ startups and enterprises in AI, HealthTech, and SaaS.