Press ` to open terminal
Press ` or ESC to close
Cybersecurity Analyst · SWIFT CSCF · AI Risk Governance
Cybersecurity analyst at ECS Fin. I assess SWIFT CSCF controls for tier-1 banks, monitor threats through Wazuh SIEM/XDR, and build — then govern — my own AI systems.
01 — About
I'm a cybersecurity analyst at ECS Fin, a SWIFT-certified Independent Assessment Provider, supporting threat monitoring and security operations for production financial systems in a regulated client environment. Day-to-day I triage and investigate alerts across Wazuh SIEM/XDR, perform detection tuning, support incident response, and conduct SWIFT Customer Security Controls Framework (CSCF) assessments for tier-1 banking clients.
Outside work I run a hands-on homelab replicating real SOC workflows — deploying and integrating tools like Clawdbot alongside GRC and AI-risk assessment work.
I've also run an independent e-commerce business since 2013 — inventory, logistics, fraud exposure, the works. I was managing operational risk long before I had a job title for it, which is probably why GRC felt less like a pivot and more like finally naming what I'd already been doing.
Tools & Technologies
02 — Infrastructure
03 — Journey
Started with a single VM running Kali Linux — just following tutorials and breaking things. Quickly expanded to a full network with pfSense, VLANs, and a dedicated attack machine.
Kali LinuxpfSenseVMsDeployed Wazuh across my homelab and built automated response playbooks with Tines. Integrated Clawdbot — a Slack bot I deployed and configured to parse JSON alert payloads and fire formatted alert cards to my SOC channel. First time I saw a full detection-to-response pipeline work end-to-end.
WazuhTinesClawdbotSlack APIBuilt structured dashboards and analytical reports in Excel and SQL. Automated reporting workflows, sharpening data analysis and systematic problem-solving skills directly applicable to security operations.
SQLExcelAutomationSupporting cyber threat monitoring and security operations for production financial systems in a regulated client environment. Triaging and investigating alerts across Wazuh SIEM/XDR, performing detection tuning, supporting incident response, authoring SOPs and playbooks, and contributing to CIS benchmark validation and audit readiness.
WazuhSOC OperationsIncident ResponseDetection TuningRegulated Env.Working toward SWIFT CSP Assessor certification — deepening formal assessment methodology (IAF, DRL, KYC-SA attestation) behind the CSCF assessments I already conduct for tier-1 banking clients at ECS Fin.
SWIFTCSCFGRC04 — Selected Work
End-to-end SOC pipeline — Wazuh detects and forwards alerts as JSON payloads to Tines, which parses fields and triggers automated responses: host isolation, ticket creation, and real-time Slack notifications via Clawdbot, a Slack bot I deployed and configured to deliver formatted alert cards to my SOC channel. Reduced MTTR from hours to seconds.
Segmented homelab with 6 VLANs, pfSense firewall with IDS/IPS, Proxmox hypervisor, and a dedicated attack network — simulating enterprise-grade infrastructure for realistic red/blue team exercises.
Full-scope web application pentest documenting 12 vulnerabilities across the OWASP Top 10. Conducted assessments running Burp Suite on a Windows tablet — demonstrating toolset adaptability across hardware. Delivered exploitation PoCs, CVSS ratings, and remediation guidance.
Simulated full AD environment — ran Kerberoasting, Pass-the-Hash, and BloodHound path discovery offensively, then tuned Splunk detection rules and hardened GPOs on the defensive side.
Built and validated a full Active Directory implementation from single-DC forest promotion through multi-master replication across two domain controllers — OU/GPO architecture, CIS-aligned hardening, and live audit-event validation tied to SIEM monitoring — translating a formal 11-section AD implementation plan into a working, tested deployment.
05 — GRC & AI Risk
Mapping all 32 SWIFT CSCF v2027 controls against NIST CSF 2.0's six functions — Govern, Identify, Protect, Detect, Respond, Recover — verified directly against the official CSCF v2027 text, not third-party summaries, to translate tier-1 banking assessment methodology into the framework language used in SOC 2 and ISO 27001 engagements.
Applying NIST's AI Risk Management Framework (Govern / Map / Measure / Manage) plus all 12 NIST AI 600-1 generative-AI risk categories to my own Azure RAG pipeline — evaluating data governance, confabulation risk, and adversarial exposure in a system I designed, built, and now assess. Includes a live model-misuse case study drawn from a production Wazuh-to-LLM alert triage agent.
06 — Practice
07 — Writing
Mapping all 32 SWIFT CSCF v2027 controls against NIST CSF 2.0's six functions — verified against the official framework text, not third-party summaries — with a close look at where the two frameworks converge and where CSCF's coverage genuinely runs thin.
GRCA governance self-assessment of my own Azure RAG pipeline — applying Govern/Map/Measure/Manage and all 12 NIST AI 600-1 generative-AI risk categories mid-build, not after launch, including the gaps I found in my own work.
AI GovernanceThe Wazuh-to-LLM triage agent I built enriches and reasons about alerts — but every output is a recommendation, never an action. A short case study in designing human-in-the-loop controls before a compliance review forces the question.
Model Risk08 — Education
09 — Credentials
10 — Contact
Currently working as a Cybersecurity Analyst at ECS Fin. Open to conversations about GRC, AI risk governance, and cyber risk assessment roles — especially ones that use SWIFT CSCF experience as a way into broader framework work.