Live Feed

Press ` to open terminal

Cybersecurity Analyst · SWIFT CSCF · AI Risk Governance

Kelvin
Rose

Cybersecurity analyst at ECS Fin. I assess SWIFT CSCF controls for tier-1 banks, monitor threats through Wazuh SIEM/XDR, and build — then govern — my own AI systems.

Scroll

Security
is my
craft.

I'm a cybersecurity analyst at ECS Fin, a SWIFT-certified Independent Assessment Provider, supporting threat monitoring and security operations for production financial systems in a regulated client environment. Day-to-day I triage and investigate alerts across Wazuh SIEM/XDR, perform detection tuning, support incident response, and conduct SWIFT Customer Security Controls Framework (CSCF) assessments for tier-1 banking clients.

Outside work I run a hands-on homelab replicating real SOC workflows — deploying and integrating tools like Clawdbot alongside GRC and AI-risk assessment work.

I've also run an independent e-commerce business since 2013 — inventory, logistics, fraud exposure, the works. I was managing operational risk long before I had a job title for it, which is probably why GRC felt less like a pivot and more like finally naming what I'd already been doing.

KR
Kelvin Rose
Sec. Engineer
1+
Yr Professional
3+
Certifications
3+
Yrs in Security
Currently Pursuing
SWIFT CSP Assessor
SWIFT · In Progress
Wazuh SIEM/XDR
SWIFT CSCF Assessments
Alert Triage & Investigation
Incident Response
Detection Tuning
Python / Bash
Linux (Ubuntu 24.04)
Nmap / Wireshark
Site24x7
TCP/IP · DNS · VLANs
MITRE ATT&CK
SOPs & Playbooks
Docker / KVM
Security+ Fundamentals (Self-Studied)
CCNA-Level Networking (Self-Studied)
SIEM / Detection Pentesting Networking Linux / OS Scripting Forensics

02 — Infrastructure

Homelab
Architecture.

pfSense
192.168.10.1
Firewall IDS/IPS VLAN GW
Wazuh SIEM
192.168.20.5
Log Ingest Detection Alerts
Kali Linux
192.168.30.12
Attack Box Pentest Isolated VLAN
Proxmox
192.168.40.3
Hypervisor 6 VMs Snapshots
Active Node
Monitored
Isolated

03 — Journey

How I Got
Here.

2023
Got Curious. Built a Homelab.

Started with a single VM running Kali Linux — just following tutorials and breaking things. Quickly expanded to a full network with pfSense, VLANs, and a dedicated attack machine.

Kali LinuxpfSenseVMs
2023 — Mid
Wazuh + Tines + Clawdbot Pipeline

Deployed Wazuh across my homelab and built automated response playbooks with Tines. Integrated Clawdbot — a Slack bot I deployed and configured to parse JSON alert payloads and fire formatted alert cards to my SOC channel. First time I saw a full detection-to-response pipeline work end-to-end.

WazuhTinesClawdbotSlack API
Aug 2024 – Jan 2025
Matlen Silver — Business Development Analyst

Built structured dashboards and analytical reports in Excel and SQL. Automated reporting workflows, sharpening data analysis and systematic problem-solving skills directly applicable to security operations.

SQLExcelAutomation
Jan 2025 → Now
ECS Fin — Cybersecurity Analyst

Supporting cyber threat monitoring and security operations for production financial systems in a regulated client environment. Triaging and investigating alerts across Wazuh SIEM/XDR, performing detection tuning, supporting incident response, authoring SOPs and playbooks, and contributing to CIS benchmark validation and audit readiness.

WazuhSOC OperationsIncident ResponseDetection TuningRegulated Env.
In Progress →
Pursuing SWIFT CSP Assessor

Working toward SWIFT CSP Assessor certification — deepening formal assessment methodology (IAF, DRL, KYC-SA attestation) behind the CSCF assessments I already conduct for tier-1 banking clients at ECS Fin.

SWIFTCSCFGRC

04 — Selected Work

What I've
Built.

Project 01
SIEMWazuhTinesClawdbotSlack API

Wazuh & Tines
SOAR Automation

End-to-end SOC pipeline — Wazuh detects and forwards alerts as JSON payloads to Tines, which parses fields and triggers automated responses: host isolation, ticket creation, and real-time Slack notifications via Clawdbot, a Slack bot I deployed and configured to deliver formatted alert cards to my SOC channel. Reduced MTTR from hours to seconds.

Project 02
NetworkingpfSenseVLANsProxmox

Homelab Network
Architecture

Segmented homelab with 6 VLANs, pfSense firewall with IDS/IPS, Proxmox hypervisor, and a dedicated attack network — simulating enterprise-grade infrastructure for realistic red/blue team exercises.

Project 03
PentestingBurp SuiteOWASP Top 10Windows Tablet

Web App Pentest
Report

Full-scope web application pentest documenting 12 vulnerabilities across the OWASP Top 10. Conducted assessments running Burp Suite on a Windows tablet — demonstrating toolset adaptability across hardware. Delivered exploitation PoCs, CVSS ratings, and remediation guidance.

Project 04
Active DirectoryBloodHoundSplunkMimikatz

Active Directory
Attack & Defend

Simulated full AD environment — ran Kerberoasting, Pass-the-Hash, and BloodHound path discovery offensively, then tuned Splunk detection rules and hardened GPOs on the defensive side.

Project 05
Active DirectoryGroup PolicyDNSCIS BenchmarksSIEM Integration

SWIFT-Aligned AD Implementation
& Multi-DC Validation

Built and validated a full Active Directory implementation from single-DC forest promotion through multi-master replication across two domain controllers — OU/GPO architecture, CIS-aligned hardening, and live audit-event validation tied to SIEM monitoring — translating a formal 11-section AD implementation plan into a working, tested deployment.

05 — GRC & AI Risk

Governance,
Risk & AI.

Framework 01
GRCNIST CSF 2.0SWIFT CSCFISO 27001

SWIFT CSCF → NIST CSF
Crosswalk

Mapping all 32 SWIFT CSCF v2027 controls against NIST CSF 2.0's six functions — Govern, Identify, Protect, Detect, Respond, Recover — verified directly against the official CSCF v2027 text, not third-party summaries, to translate tier-1 banking assessment methodology into the framework language used in SOC 2 and ISO 27001 engagements.

Framework 02
AI GovernanceNIST AI RMFRAGModel Risk

AI RMF Self-Assessment —
Azure RAG Pipeline

Applying NIST's AI Risk Management Framework (Govern / Map / Measure / Manage) plus all 12 NIST AI 600-1 generative-AI risk categories to my own Azure RAG pipeline — evaluating data governance, confabulation risk, and adversarial exposure in a system I designed, built, and now assess. Includes a live model-misuse case study drawn from a production Wazuh-to-LLM alert triage agent.

06 — Practice

Platforms &
CTF Activity.

TryHackMe
Top 5%
Global Ranking
Rooms Completed42
Linux FundamentalsJr Penetration Tester SOC Level 1Advent of Cyber
HackTheBox
User
Current Rank
Machines Owned8
LameBlue JerryNibbles
CTF Competitions
Events Competed
Challenges Solved24
PicoCTFCTFtime OSINTWeb Exploitation

07 — Writing

Writeups &
Notes.

Aug 2026 · Read
SWIFT CSCF → NIST CSF: Why Framework Fluency Beats Memorization

Mapping all 32 SWIFT CSCF v2027 controls against NIST CSF 2.0's six functions — verified against the official framework text, not third-party summaries — with a close look at where the two frameworks converge and where CSCF's coverage genuinely runs thin.

GRC
Aug 2026 · Read
What NIST AI RMF Looks Like From the Builder's Seat

A governance self-assessment of my own Azure RAG pipeline — applying Govern/Map/Measure/Manage and all 12 NIST AI 600-1 generative-AI risk categories mid-build, not after launch, including the gaps I found in my own work.

AI Governance
Ongoing · On this site
Why My AI Alert Triage Agent Doesn't Get to Close Tickets

The Wazuh-to-LLM triage agent I built enriches and reasons about alerts — but every output is a recommendation, never an action. A short case study in designing human-in-the-loop controls before a compliance review forces the question.

Model Risk

08 — Education

Academic
Foundation.

M.S. Cybersecurity
Georgia Institute of Technology · Information Security Track (OMS)
Active
B.S. Business Analytics & IT
Rutgers Business School
Completed

09 — Credentials

Certifications.

SWIFT CSP Assessor
SWIFT · Customer Security Programme
In Progress

Let's
Work
Together.

Currently working as a Cybersecurity Analyst at ECS Fin. Open to conversations about GRC, AI risk governance, and cyber risk assessment roles — especially ones that use SWIFT CSCF experience as a way into broader framework work.