About me

I’m Matthew. I took the scenic route to security — spent years in other industries before landing in IT support, then moved into security ops when things finally clicked. I’ve always been driven by the same thing: automating the tedious stuff so I can actually think about what matters.

These days I’m a Senior Information Security Officer. Most weeks I’m monitoring and responding to alerts across Microsoft Sentinel, EDR/XDR, and everything in between — endpoint, email, identity, cloud telemetry. I run incidents from triage through root cause and remediation, and I own the controls that make it all work: Entra ID and Active Directory for identity, endpoint and email security, and whatever we need to stay aligned to SOC 2, ISO 27001, and NIST.

The part that actually excites me is making security repeatable. I’ve built our Cloudflare Zero Trust access as code in Terraform, scripted Microsoft Intune configuration in PowerShell, migrated production onto a self-managed RKE2 cluster with Flux GitOps, and created an AI-assisted support pipeline (Claude + Hermes) to take the routine tier-1 work off the team’s plate. I’d rather ship a control you can review in a pull request than watch someone click through a portal.

Outside work I’m always building something — running a homelab, working through security and Linux labs. I learn by doing and believe in spaced repetition to make things stick. This blog is part of that: writing things down forces me to actually understand them, and publishing keeps me honest.

I hold CompTIA Security+ and I’m an Associate of ISC2.

If any of that overlaps with what you’re working on, reach out on LinkedIn or GitHub.