Career

Experience

Sixteen years of web security work — from frontline hosting support to leading malware research at scale.

  1. Security Engineer III

    Sep 2024Present

    GoDaddy / Sucuri — Remote

    • Lead advanced threat detection, vulnerability management, and incident response for websites and infrastructure across GoDaddy's hosting portfolio.
    • Personally resolve a high volume of malware-classification cases — the large majority requiring one or more original detection signatures, each representing a distinct sample, campaign, or infrastructure pattern investigated.
    • Reverse-engineer newly discovered malware samples and develop technical detection signatures (PHP, JavaScript, regex) integrated into automated scanning tools; among the most active contributors org-wide to the team's core detection codebase.
    • Design and build CI/CD-style automation — GitHub workflows that trigger AWS Lambda functions to QA-test every new signature in the cloud before it ships to analysts and deploys across the scanner network, which checks both customer file systems and live public content for malware.
    • Train AI agents to draft signatures for straightforward malware, freeing analyst time for novel and complex threats, and maintain and modernize legacy internal tooling that had fallen out of use.
    • Publish original threat research to the GoDaddy and Sucuri security blogs, translating technical findings into guidance for website owners and the security community.
    • Mentor junior analysts on malware triage and signature development to bolster overall team expertise.
  2. Security Engineer II

    Jun 2024Sep 2024

    GoDaddy / Sucuri — Remote

    • Handled forensic investigation of escalated security incidents during a short, fast-tracked stretch in the technical ladder — tracing attack vectors through log data and building the mitigation steps to close them.
    • Authored detection signatures in regex, PHP, and JavaScript, and wrote up technical findings for the internal knowledge base and the public blog.
    • Worked closely with engineering and incident-response counterparts to tighten classification and escalation processes, ahead of moving into the Engineer III role three months later.
  3. Technical Security II

    Dec 2018Jun 2024

    GoDaddy / Sucuri — Remote

    • Decoded and analyzed malware samples submitted by the wider analyst team, correlating indicators and behavior to produce regex/PHP/JS signatures used to detect and remediate infections at scale.
    • Investigated complex, novel infection chains — including fake plugins, PHP web shells, and JavaScript skimmers (Magecart-style) — and documented findings in published Labs Notes and blog posts.
    • Tracked emerging evasion techniques as they surfaced in the wild — cookie-triggered backdoors, payloads hidden inside non-executable .txt and .log files — and shipped detection for them before they became widespread.
    • Built detection coverage that scaled cleanup across large volumes of compromised WordPress and Magento websites, turning one-off fixes into signatures that caught the same campaign wherever it resurfaced.
    • Became the team's go-to for escalated, hard-to-classify cases over five and a half years in the role — from decoding other analysts' samples early on to shaping how the team classified and wrote up new threats.
  4. Supervisor / Team Lead

    Dec 2017Dec 2018

    GoDaddy / Sucuri — Remote

    • Led a team of security analysts handling malware investigation and remediation for client websites, reviewing case quality and clearing escalations to keep resolution times inside SLA.
    • Ran regular 1:1s and team meetings, coordinated schedules and time off, and trained new analysts on malware triage and cleanup.
    • Served as the team's escalation point for the most complex or high-profile infections, stepping in directly when a case needed deeper investigation.
  5. Security Analyst

    Apr 2017Dec 2018

    GoDaddy / Sucuri — Remote

    • Investigated and remediated malware infections on compromised client websites, tracing each one back to its root cause rather than just clearing the visible symptoms.
    • Repaired the functional damage malware left behind — corrupted files, broken plugins, defaced pages — and advised clients directly on hardening steps to prevent reinfection.
    • Coordinated with blacklist and safe-browsing providers to get cleaned sites delisted and traffic flowing again.
  6. Security Analyst

    Sep 2014Dec 2018

    Sucuri Inc. (prior to GoDaddy acquisition)

    • Cleaned malware from compromised websites and resolved the downstream damage infections left behind — broken functionality, altered configs, blacklisting.
    • Flagged previously unseen malware, phishing kits, and spam injections uncovered during manual review to the wider team for deeper investigation and signature development, feeding the detection pipeline from the front line.
  7. Security Administrator

    Sep 2011Aug 2014

    HostGator — Houston, Texas

    • Investigated malware and phishing attacks reported by hosting clients, tracing attack vectors through server and access logs and closing the gaps that let them in.
    • Monitored servers for spam abuse, traced outgoing spam back to its source account, shut it down, and secured the account against reinfection.
    • Worked directly with clients to explain what happened in plain language and guide them through remediation and blacklist removal.
  8. Jr. Administrator

    Sep 2010Sep 2011

    HostGator — Houston, Texas

    • Supported a global hosting customer base — often on phone and live chat at the same time — on everything from DNS propagation and domain transfers to control-panel navigation and CMS setup.
    • Turned frustrated, sometimes irate customers into satisfied ones by translating technical fixes into plain language for non-technical site owners.
    • Built the troubleshooting instincts — DNS, hosting infrastructure, CMS internals — that carried directly into the security work that followed.

Languages

Languages