BACKGROUND

Experience

A summary of my professional cybersecurity work. See the full history, including dates and titles, on my résumé.

Cybersecurity Analyst Cowbell February 2024 – Present

Summary

Cybersecurity analyst supporting mid-market and enterprise organizations ($250M–$1B revenue) through dark web monitoring, CVE/threat-intelligence analysis, and authorized external micro-penetration testing. Also lead internal reporting automation, building the team's metrics database and executive dashboards.

Selected Contributions

  • Performed dark web monitoring and aggregation, delivering reports within 1–2 business days
  • Researched and assessed CVEs using threat intelligence to identify actively exploited or high-risk vulnerabilities, delivering concise reporting to support timely risk-based alerting and decision-making
  • Conducted authorized micro-penetration tests (external, limited scope) with remediation reporting
  • Consulted with $250M–$1B revenue organizations on cybersecurity best practices
  • Configured API integrations across Microsoft 365, AWS, Google Workspace, Cloudflare, and Sophos
  • Led development of a team metrics database and executive reporting dashboards (Tableau and Salesforce)
  • Built automation for real-time cyber risk ratings based on internet-facing assets using dark web data

Technologies & Domains

Dark web monitoring · CVE/vulnerability analysis · External micro-penetration testing · API integrations (M365, AWS, Google Workspace, Cloudflare, Sophos) · Tableau & Salesforce reporting · Automation

Outcomes

Dark web monitoring reports consistently delivered within 1–2 business days; built and now maintain the team's metrics database and executive reporting dashboards.

Risk Administrator Cowbell Cyber April 2022 – February 2024

Summary

Supported Cowbell's risk engineering function and policyholders directly — request/meeting management, vulnerability reporting, and threat-intelligence research — before moving into the Cybersecurity Analyst role.

Selected Contributions

  • Managed request inbox and meeting queue, ensuring timely response and resolution
  • Aggregated risk engineering metrics (call volume, engagement type) for leadership reporting
  • Supported policyholders with platform onboarding, API connector setup, and security awareness training
  • Produced weekly vulnerability and Spotlight reports on emerging threats
  • Authored vulnerability summaries and determined alerting vs. direct-notification strategy
  • Built API adoption reports and maintained policyholder technology-stack data
  • Researched and summarized industry threat intelligence (Verizon DBIR, IBM Threat Report)

Technologies & Domains

Vulnerability reporting · Policyholder & API onboarding support · Threat-intelligence research · Security awareness training

Download full résumé →