About Me
Hi, I'm Christian! I'm a Computer Engineering graduate focused on Security Operations and Detection Engineering. I have real-world experience with incident response, SIEM/EDR alert monitoring, vulnerability management, and security automation within PCI DSS, HITRUST, and SOC 1/SOC 2-compliant environments. Security+ certified and seeking entry-level Cybersecurity Engineer, SOC, or Security Operations roles where I can apply and further develop hands-on security expertise.
Education
University of California Santa Cruz — Santa Cruz, CA
Bachelor of Science in Computer Engineering, Concentration in Networks | 2022 – 2026
- Relevant Coursework: Data Structures & Algorithms, Computer Networking, Computer Security, Computer Systems & Design, Cryptography, Software Engineering, Network Programming
- Research Focus: Network Security, Wireless Networks, Applied Machine Learning, Device Authentication, Device Identification and Device Impersonation
Experience
Cybersecurity Analyst Intern — XiFin
- Monitored, triaged, and investigated security alerts using enterprise SIEM and EDR platforms (Splunk, CrowdStrike), performing log analysis to identify true positives, prioritize severity, and escalate high-severity notables per established procedures to support day-to-day Security Operations Center (SOC) functions.
- Participated in incident response investigations spanning phishing, malware, business email compromise, and account compromise scenarios, using Microsoft Defender, Microsoft Entra ID, and Microsoft Purview to analyze indicators of compromise and support containment, remediation, and incident timeline documentation.
- Contributed to identity and access management reviews in Microsoft Entra ID, including Conditional Access policy validation and sign-in log analysis.
- Conducted vulnerability assessments and supported vulnerability management using Nucleus, incorporating threat intelligence to prioritize findings, validating and verifying results, coordinating remediation and mitigation efforts with IT teams, and tracking remediation status in Jira.
- Supported endpoint security operations through CrowdStrike, including host containment and remote remediation via PowerShell scripting, while automating incident response tasks through Fusion SOAR workflow development.
- Performed detection engineering in Splunk, creating, tuning, and modifying correlation searches and detection logic mapped to the MITRE ATT&CK framework to reduce false positives and improve alert accuracy.
- Configured and maintained security tools to established baselines, including Microsoft Entra Conditional Access policies, Palo Alto firewall rules, and CrowdStrike detection exclusions.
- Participated in firewall and network log architecture reviews using Palo Alto and Panorama, analyzing rule usage and traffic patterns to improve log filtering, ingest efficiency, and network visibility.
- Contributed to the development of a Shadow AI usage monitoring dashboard in Splunk, tracking AI application adoption, unique users, and usage trends to improve enterprise visibility into unsanctioned AI tool usage.
- Supported PCI DSS and HITRUST compliance audits by collecting and validating evidence for external auditors, and conducted risk assessments for new software prior to enterprise deployment.
- Helped maintain and improve internal security documentation, playbooks, and runbooks in Confluence, and supported the onboarding of a Managed Detection and Response (MDR) solution, collaborating with IT, security, and the vendor's team to strengthen enterprise security processes.
Skills Applied: Incident Response, SIEM/EDR Monitoring (Splunk, CrowdStrike), Vulnerability Management, Detection Engineering, Identity & Access Management, Security Automation (SOAR), Firewall & Network Security, PCI DSS / HITRUST Compliance
Network Security Undergraduate Researcher — Baskin School of Engineering | Inter-Networking Research Group
- Conducted undergraduate research in network security focused on radio frequency fingerprinting (RFF), physical-layer device authentication, and adversarial wireless signal analysis.
- Contributed to early survey research on whether RF fingerprints are truly unique but unclonable, reviewing work on transmitter hardware impairments, fingerprint feature types, channel effects, CNN-based classification, and GAN-based adversarial signal generation.
- Gained hands-on experience with HackRF One, USRP N200, GNU Radio Companion, and 802.11 Wi-Fi signal processing by building and modifying flowgraphs for wireless reception, transmission, frame decoding, and MAC address extraction.
- Configured and debugged SDR capture pipelines, including GNU Radio flowgraphs, UHD/USRP networking, Wi-Fi decoding blocks, file sinks, and scripts for organizing captured frames by MAC address.
- Captured over-the-air 802.11 Wi-Fi data across multiple campus locations, including 8.5K+ decoded frames, 300+ unique MAC addresses, and device-specific datasets filtered for downstream RF fingerprinting experiments.
- Ran captured RF data through a CNN classifier and GAN-based signal generation pipeline to evaluate closed-set model performance against unknown real devices and synthetic attacker-like signals.
- Prepared known, unknown, and attack-device data splits to support open-set recognition experiments and evaluate classifier behavior across real and synthetic RF samples.
Skills Applied: RF Fingerprinting & Device Authentication, IEEE 802.11 Wireless Security, Software-Defined Radio (HackRF One, USRP N200, GNU Radio Companion), Python, Adversarial Machine Learning (GANs), CNN Classification, Open-Set Recognition, Signal Processing
Software Engineer — UCSC Financial Department
Senior Capstone | UCSC Procurement and Supply Chain Services Department
- Developed a full-stack compliance automation platform for UCSC Financial Affairs to help auditors review OneCard transaction data more efficiently.
- Built application workflows for uploading Excel transaction files, parsing and normalizing records, running rule-based and AI-assisted compliance checks, reviewing flagged purchases, saving auditor notes, managing uploaded batches, and exporting reviewed results.
- Combined JSONLogic-based compliance rules with Vertex AI/Gemini evaluation to flag high-risk and ambiguous transactions and provide reviewer-facing explanations.
- Contributed to core platform features including transaction review, batch management, role-based access behavior, export functionality, auditor feedback handling, and AI prompt iteration.
- Collaborated directly with UCSC procurement and financial stakeholders to refine compliance logic, improve exception handling, and align the platform with real audit workflows.
- Supported a project targeting 50,000+ annual OneCard transactions, reaching 72.5% accuracy on auditor-validated complex test batches.
Skills Applied: React, TypeScript, Firebase, Vertex AI / Gemini, JSONLogic, Full-Stack Development, Compliance & Audit Support, Stakeholder Collaboration
Projects
Shadow AI Usage Monitoring Dashboard – Splunk Dashboard Studio
Built a Splunk Dashboard Studio report to track unsanctioned "Shadow AI" tool usage across the organization, covering 67 known AI applications. Designed KPIs for unique AI applications used, distinct AI domains accessed (rolled up by root domain), and unique application users, each with drill-down panels, and visualized usage trends via a distinct-users table, application-distribution pie chart, and adoption-trend area chart to surface unmonitored AI tool usage for the security team.
Vulnerability Management Lab – Tenable Nessus on KVM
Built a vulnerability management lab using Tenable Nessus Essentials to scan an intentionally misconfigured Windows 10 virtual machine running on a KVM/QEMU environment. The project walks through the full vulnerability management lifecycle—from discovery and credentialed scanning through prioritization, remediation, and validation—highlighting real CVEs, patching decisions, and measurable risk reduction.
Security Monitoring Homelab – Wazuh SIEM & Suricata IDS
Built an end-to-end security monitoring lab using Wazuh SIEM on Ubuntu Server and Suricata IDS on a Raspberry Pi. The lab collects host telemetry and network intrusion alerts, forwards structured JSON events into Wazuh, and visualizes detections in a centralized dashboard—demonstrating practical experience with log collection, IDS rule tuning, SIEM integration, and alert triage workflows.
Active Directory Homelab
Active Directory homelab demonstrating IAM fundamentals: OU structure, RBAC with security groups, PowerShell user provisioning, GPO password policies, and shared resource access control.
Skills
Security Tools & Platforms
- Splunk Enterprise Security
- CrowdStrike Falcon (Next-Gen SIEM)
- Microsoft Defender
- Microsoft Entra ID
- Azure
- Nucleus
- Panorama
Core Competencies
- Incident Response
- Vulnerability Management
- Alert Triage
- Log Analysis
- Detection Engineering
- Security Automation
- Identity & Access Management
Languages & Scripting
- Python
- C
- PowerShell
- SPL
- KQL
Frameworks & Compliance Knowledge
- MITRE ATT&CK
- NIST SP 800-61
- PCI DSS
- HITRUST
SOC Workflow & Documentation
- Jira
- Confluence
- FieldGuide
- Microsoft Purview
Certifications
Contact Information
Email: Email
GitHub: GitHub
LinkedIn: LinkedIn