Keith D.

AI Researcher

Allen Park, Michigan, United States24 yrs 2 mos experience
Highly Stable

Key Highlights

  • 10+ years of experience in cybersecurity.
  • Expert in building high-fidelity detection pipelines.
  • Proven track record in reducing false positive rates.
Stackforce AI infers this person is a Cybersecurity Specialist with expertise in Threat Detection and Incident Response.

Contact

Skills

Core Skills

Threat ResearchDetection EngineeringLog ManagementSecurity ConsultingSiem ManagementSoc OperationsWindows Desktop EngineeringDeployment Engineering

Other Skills

Security AutomationMITRE ATT&CKRegular ExpressionsPythonInvestigationCyber DefenseSumo LogicCyber Threat Intelligence (CTI)Crowdstrike FalconSecurity Information and Event Management (SIEM)Threat DetectionCarbon BlackCyber Threat Hunting (CTH)Kusto Query Language (KQL)Security Research

About

Threat Detection Engineer and Security Analyst with 10+ years of experience across SIEM engineering, endpoint detection, incident response, and threat intelligence. Proven track record building high-fidelity detection pipelines, reducing false positive rates, and operationalizing threat intelligence in Fortune 500 and managed security environments. Adept at translating adversary TTPs into actionable detections across EDR, SIEM, and network security platforms.

Experience

24 yrs 2 mos
Total Experience
3 yrs 7 mos
Average Tenure
--
Current Experience

Esentire

2 roles

Threat Reseacher

Promoted

Oct 2019Apr 2026 · 6 yrs 6 mos

  • Threat Researcher and Detection Engineer with 5+ years of experience translating adversary behavior into high-fidelity detections across enterprise environments. I built and maintained detection pipelines, automated security operations workflows, and operationalized threat intelligence across Carbon Black Enterprise EDR, Sumo Logic Cloud SIEM Enterprise, and CrowdStrike Falcon.
  • My work sits at the intersection of research and engineering — I understand how attackers operate and I build durable, scalable defenses because of it. Over my career I authored hundreds of behavioral detections, led proactive threat hunts, and delivered automation that measurably reduced analyst toil and mean time to respond. Researched threat actor TTPs using MITRE ATT&CK, open-source intelligence, and private threat feeds, translating findings into detection opportunities across the security tooling stack.
  • Open to new opportunities in Detection Engineering, Threat Research, or Security Platform roles where I can continue doing deep adversary research and shipping things that make a real operational difference.
  • Core competencies:
  • Threat research
  • Detection Engineering (Sumo Logic, Sumo Logic Cloud SIEM, Carbon Black Enterprise, Microsoft MDE, Microsoft Sentinel)
  • Security automation
  • MITRE ATT@CK
Threat ResearchDetection EngineeringSecurity AutomationMITRE ATT&CKRegular ExpressionsPython+14

Information Security Consultant

Jan 2016Oct 2019 · 3 yrs 9 mos

  • As a member of the Professional Services team, I am responsible for the deployment and configuration of the Log Sentry logging solution.
  • Manage and consult with clients on best security practices and approaches for log management.
  • Develop use case scenarios designed around NIST Cybersecurity Framework.
  • Day to day work with Linux, database technologies, SQL, python, and various CLI tools.
  • Conducts large-scale investigations and examine endpoint and network-based sources of evidence.
  • Supports upper management in refining and expanding service offering capabilities.
  • Develops comprehensive and accurate reports and presentations for both technical and executive audiences.
  • Develop streamlined processes for data analysis and SIEM management through Python scripts
Log ManagementNIST Cybersecurity FrameworkLinuxDatabase TechnologiesSQLPython+5

Ally financial inc.

SIEM Manager

Aug 2014Jan 2016 · 1 yr 5 mos · Greater Detroit Area

  • As a member of the Cyber Response team, I am responsible for the day to day operations and maintenance of the RSA Security Analytics SIEM to allow expedient security incident investigations.
  • Manage and maintain 19 server SIEM infrastructures health and availability.
  • Integrate new log sources and verify logging functionality to meet regulatory requirements and troubleshoot any logging issues.
  • Perform quarterly/yearly formal health check and administrative functions.
  • Provide enhancements to the SIEM through various data enrichment methodologies including proper contextual information.
  • Provide threat analysis to Incident Response team lead on current investigations analyzing various log sources.
  • Implement various open and closed source threat intelligence feeds and analyze for proper alerting.
  • Investigate and integrate various open source projects to better enhance Ally’s security posture.
  • Create custom alerts, reports and other monitoring processes to ensure business continuity and various audit requirements.
  • Develop streamlined processes for data analysis and SIEM management through Python scripts
  • Perform mentoring and training of SIEM users
Security Information and Event Management (SIEM)Threat DetectionSIEM Management

Stratagem - a linux based honeypot distribution

Author

Jun 2013Jun 2018 · 5 yrs · http://sourceforge.net/projects/stratagem/

  • Stratagem is a Linux distribution for honeypots, network forensics, malware analysis and other supporting tools. Stratagem is based on Linux Mint 14 XFCE.
  • The following honeypots are setup and ready to go.
  • Dionaea
  • Kippo
  • Glastopf
  • HoneyD
  • Amun
  • labrea
  • Tinyhoneypot
  • Thug
  • Conpot
  • http://sourceforge.net/projects/stratagem/

Blue cross blue shield of michigan

Security Operations Center Analyst

Feb 2013Aug 2014 · 1 yr 6 mos

  • As a member of the Information Security Operations Center (SOC) team, I am responsible for the day to day Information Security activities to protect the confidentiality, integrity, and availability of member, employee, and business information system resources. Primary responsibilities include monitoring and investigating security events on over 2000 Windows, Linux, and Unix servers and over 800 routers, switches, and 20,000 endpoints.
  • Provide threat analysis to Incident Response team lead on current investigations
  • Analyze network intrusion alerts indicating potential botnet activity using CheckPoint Anti-bot blade
  • Perform memory analysis of infected systems to determine the scope and impact to the Blue Cross environment
  • Perform weekly scanning of the Blue Cross Blue Shield infrastructure using QualysGuard
  • Research new analysis techniques using Qradar SIEM to improve overall techniques and resolution times
  • Monitor, detect, and block rogue wireless access points using Air Magnet Enterprise
  • Coordinate cross-departmental meetings to address zero-day vulnerabilities, and Risk Management reporting.
Security Information and Event Management (SIEM)Threat DetectionSOC Operations

Chrysler

Windows Desktop Architect

Mar 2010Feb 2013 · 2 yrs 11 mos · Auburn Hills, Michigan

  • Windows Client Engineer responsible for developing and supporting the Windows 7 and Windows XP Professional desktop images used in the Chrysler environment.
  • Develop, maintain and support the Windows 7 and Windows XP Professional desktop images for Chrysler for distribution using Microsoft Deployment Toolkit 2010 and Microsoft Systems Center Configuration Manager.
  • Develop and update various VBScript automated processes used during image creation as needed.
  • Develop and maintain Group Policy objects to meet security standards as well as business needs.
  • Test and implement monthly security patches for all affected systems.
  • Current projects
  • BitLocker compliance
  • Develop process to ensure 100% BitLocker compliance per Chrysler corporate standards within 24 hours after user receives new laptop.
  • User State Migration Tool - Windows 7 migration
  • Customize settings of Microsoft tool to provide a smoother user-profile migration of all appropriate data and settings specific to the Chrysler user base.
  • Created adaptable GUI front end for onsite technicians to initiate a backup and restore process quickly.
  • Windows 7 migration - Application Compatibility Toolkit
  • Lead engineer responsible for using the Microsoft Application Compatibility Toolkit to create customized "shims" to remediate some applications that have issues running on Windows 7.
  • Windows XP Office Automation image development
  • Develop and maintain standardized Windows XP operating system image to cover many platforms across 30,000 systems through Chrysler.
Windows DeploymentVBScriptGroup Policy ManagementSecurity PatchingWindows Desktop Engineering

Hewlett-packard

Windows Systems Consultant

Jan 2007Sep 2009 · 2 yrs 8 mos

  • Lead engineer responsible for operating system, applications, and critical security patch distribution projects to more than 20,000 computer systems globally in support of General Motors.
  • Lead Deployment Engineer, Software Distribution team
  • Lead remote application and operating system deployment projects using HP OpenView Configuration Manager (Radia).
  • Troubleshoot and remediate any deployment issues. Solve problems with the least amount of down time to the customer.
  • Direct HP OpenView Configuration Manager best deployment practices.
  • Streamline troubleshooting and remediation processes.
  • Windows Desktop Engineer, Client Engineering team
  • Design, engineer, build and configure new Windows XP Professional and x64 Edition standardized operating system image for global distribution.
  • Design and implement Vbscript solutions for application installations, system driver updates, and community specific desktop settings.
  • Design Altiris Rapid Install and Radia packages as required.
  • Develop and document processes for Altiris Deployment Server and HP OpenView Configuration Manager.
  • Professional Accomplishments
  • Promoted to Lead Deployment Engineer from Windows Desktop Engineer for major global deployment project.
  • Developed training programs and troubleshooting guides for technicians to be used during the global deployment of new Windows based operating system images using HP OpenView Configuration Management.
  • Identified and developed global solution that saved General Motors $100,000, helped meet service level agreements and decreased the amount of lost user productivity during operating system deployments by 5%.
  • Developed a standardized desktop image for the OnStar call centers where they previously used eight separate images. This has so far yielded a 20% increase in efficiency and an overall yearly savings of $75,000.
Operating System DeploymentApplication DistributionTroubleshootingDeployment Engineering

Compucom

Field Engineer

Mar 2002Jan 2007 · 4 yrs 10 mos

  • Provided day to day first, second and third level desktop support to 1,000 clients at the General Motors Pontiac Structural Lab as well as the Warren Electrical and Structural Engineering labs.
  • Installed, troubleshoot and repair hardware, software, and peripheral equipment, and data connectivity issues with desktops and laptops running Windows XP Professional in a Windows Server 2003 infrastructure.
  • Installed and supported company standard software applications as needed. Designed and deployed standardized Windows XP Professional operating system images to multiple Compaq and Hewlett Packard desktops and laptops using Drive Image.
  • Maintained and supported Window Server 2003 Active Directory organizational unit, computer and user accounts in an enterprise environment.
  • Created MSI software packages using Radia and InstallShield AdminStudio for Active Directory distribution. Manage day to day data disaster recovery operations using Vertis BackupExec.
  • Ensured daily McAfee VirusScan Enterprise anti-virus security updates were available to all clients. Educated team mates on more efficient processes to improve downtime for users.
  • Professional Accomplishments
  • Prevented an unneeded $50,000 expense to General Motors from an implemented solution and achieved an “Extra Mile” award from the Pontiac Structural Labs.
  • A further annual savings of $55,000 was achieved by developing Windows Server 2003 Active Directory group policies for multiple site project involving client test equipment checkout kiosks.

Bpi information systems

Field Engineer

Jul 2001Feb 2002 · 7 mos

  • Provided onsite maintenance and support for various Intel based computers at University of Michigan Hospital.
  • Provided onsite maintenance and support for various HP printers.
  • Deploy new operating systems and application to mission critical computer systems.
  • Vital role in hospital wide system refresh project which two months earlier than expected.
  • Recognized for outstanding quality of customer service during first quarter in the position.

Education

ITT Technical Institute

Associates — Electronics Engineering Technology

Jan 1993Jan 1995

Stackforce found 100+ more professionals with Threat Research & Detection Engineering

Explore similar profiles based on matching skills and experience