Security Operations & Infrastructure
Recommend, design, manage, and document system security requirements; configure and troubleshoot security infrastructure
Ensure management and the BOD are notified promptly of security incidents
Run security tests (audit/pentest) on web, mobile, and desktop applications; identify and exploit vulnerabilities
Review code/application flows and recommend fixes; work with teams to remediate vulnerabilities and meet compliance standards
Investigate security incidents and produce findings reports
Knowledge Sharing & Governance
Research emerging threats and techniques (hacking, malware, bug bounty, etc.)
Write security best-practice standards for
developers; train staff to enforce security policy
AI Integration into Security (Claude-Powered)
Design Claude-integrated workflows for alert triage, log analysis, and incident investigation across SIEM/SOAR platforms (Splunk, QRadar, Elastic, XSOAR)
Build prompt engineering pipelines to parse, correlate, and summarize logs, reducing analyst workload and MTTI
Develop playbooks that turn raw alerts into structured incident summaries, root-cause hypotheses, and response recommendations
Enable natural-language log querying so analysts can investigate without deep SPL/KQL expertise
Auto-generate incident reports, threat intel summaries, and post-mortems from raw event data
Manage Claude API integrations, context windows, and token efficiency; refine prompts via analyst feedback loops
Digital Forensics
Apply memory analysis, disk imaging, log correlation, and timeline reconstruction to investigate breaches
Conduct malware analysis and reverse engineering to identify attack vectors and build detection signatures
Maintain forensic chain of custody per legal/compliance requirements; produce forensic reports for management, legal, and regulators