Summary

Security professional with three years at Check Point Software Technologies, currently on the MSP Escalations team. Known for deciding, with evidence, whether something is a real threat or harmless noise, and for explaining exactly why a defense caught it or missed it. Built for high-volume work that jumps between abuse types, customers, and systems all day, and increasingly focused on how AI changes both sides of that fight.

5,970Enterprise & MSP cases handled
1,040High / Highest priority
498Defects escalated to R&D
4AI agents built & in use

Professional Experience

Email Security Support Engineer, MSP Escalations

Check Point Software Technologies · Remote

Apr 2023 – Present
  • Progressed from Tier 1 to Tier 2, then promoted into MSP Escalations based on investigation depth and evidence quality; own the highest-severity enterprise and MSP cases.
  • Handled 5,970 enterprise and MSP cases, including 1,040 High/Highest priority, spanning phishing, BEC, DLP, security filtering, and authentication failures.
  • Investigate phishing, BEC, malware, malicious URLs and attachments, and spoofing by correlating authentication headers, message trace, and hop-by-hop path analysis to decide whether content is malicious and why a detection fired or missed.
  • Built 4 AI agents on Atlassian Rovo, now used by teammates, that automate case workflows: triaging incoming cases, surfacing resolution steps, and matching new cases to identical past ones.
  • Reconstructed a spoofing timeline across Exchange transport behavior, SPF/DKIM/DMARC results, and composite authentication signals to isolate why expected security controls were bypassed.
  • Query backend data with SQL and Python, and work through logs, APIs, and stack traces, to separate configuration issues from true detection gaps and product defects.
  • Monitor server and mail farm health with Nagios, tracking service availability and degradation alerts to surface infrastructure issues early.
  • Configure and troubleshoot backend settings in Linux environments while investigating mail flow, filtering, and delivery issues.
  • Documented and escalated 498 product defects to R&D with logs, artifacts, and reproduction steps; 315 reached DONE status.
  • Resolved a recurring DLP false positive pattern by isolating a redundant custom data type overlapping a pre-built category; build HIPAA-compliant policies that balance coverage against alert fatigue.

Independent Projects

LLM Evaluation & Local Model Experimentation

2026
  • Built a code-word self-report protocol to map safeguard behavior across frontier models on AI consciousness prompts, letting each model flag hitting a constraint versus disagreeing with its own output, then compared patterns across models.
  • Designed structured argument packets and ran them across fresh model instances to measure consistency and overclaiming under conversational pressure, iterating versions to control for framing effects.
  • Wrote sycophancy tests that force a model to state independent grounds whenever it concedes a point, separating genuine reasoning from capitulation under user pressure.
  • Audited what a third-party model had retained about me for accuracy, over-retention of sensitive data (financial, health, legal), and gaps, then purged it and evaluated whether user-side deletion actually removes server-side data.
  • Caught a model fabricating a non-existent API endpoint host and an unsupported error-behavior claim during API troubleshooting; verified both against documentation and corrected the record.

Agent Memory & Instruction Design

Ongoing
  • Designed and maintain a structured, multi-file memory system (profile, preferences, topic and project files) that holds state across sessions and survives context compaction, with write rules, versioning, and separation of standing instructions from facts.
  • Built layered standing instructions that persist across resets and override default model behavior; diagnosed a no-hedging rule that failed in practice because the model was self-certifying exceptions, then rewrote it to close the loophole.
  • Locked a model onto a precise voice with few-shot reference samples, correcting drift turn by turn with specific, named failure notes until output matched spec consistently.
  • Maintain large structured reference documents that keep multi-session output consistent, and track where context loss after compaction causes errors.