Skip to main content
Résumé

Edward Griggs

Security Operations & Detection Engineering

Security operations practitioner running the full IT and security function for a federal contractor handling CUI, as one half of a two-person technical team with the CTO. I triage and remediate incidents in Microsoft Defender XDR using KQL Advanced Hunting, and I maintain a Sigma detection-as-code pipeline with GitHub Actions CI mapped to MITRE ATT&CK.

I was the primary author of the SSP and POA&M, roughly 70% of the compliance program, behind a perfect 110/110 SPRS score. The organization holds CMMC Level 1 today and is preparing for Level 2. I raised Microsoft Secure Score from 54.5% to 83.6% across 30+ endpoints and returned an estimated 1,200+ staff-hours a year through PowerShell, Microsoft Graph API, and Power Automate.

Based in

Yorktown, VA. Open to relocation nationwide.

Open to

  • Security operations
  • Detection engineering
  • SOC analysis
  • Incident response

Measured outcomes, not responsibilities.

Every figure here comes from work I owned end to end at Aalis Management Consulting and NewView Oklahoma.

110/110
SPRS scorePerfect DoD NIST SP 800-171 self-assessment
54.5 → 83.6%
Microsoft Secure Score+29 points across 30+ endpoints
1,200+
Staff-hours automated per yearPowerShell, Power Automate, Graph, and AI
50+
Users supportedFederal contractor handling CUI, two-person technical team

Selected work.

Detection engineering, Microsoft security hardening, and published AI security research.

Detection as code

Sigma, GitHub Actions, KQL, Sentinel, and Defender

CI validates Sigma rule syntax and compiles it to KQL for Microsoft Sentinel and Defender on every commit, and nothing merges until it passes. Each rule ships beside its false-positive analysis and validation steps.

Four detections mapped to MITRE ATT&CK: password spray (T1110.003), brute force (T1110.001), malicious inbox rule creation (T1098), and impossible travel.

Author and maintainer.

Source
Sigma
Compile
KQL
Deploy
Sentinel

Microsoft 365 hardening

Microsoft Secure Score: 54.5% → 83.6%

+29 pts across 30+ endpoints.

  1. Audited all 30+ endpoints against Microsoft Secure Score recommendations, categorizing findings by severity and effort.
  2. Enabled and configured Conditional Access policies to block legacy authentication protocols and enforce MFA for all admin accounts.
  3. Deployed security baselines through Intune across all managed endpoints, hardening OS configurations to match NIST SP 800-171 controls.
  4. Remediated Defender for Endpoint alert configurations, enabling EDR, attack surface reduction rules, and automated investigation.
  5. Implemented Purview DLP policies for email and SharePoint to prevent CUI exfiltration.
  6. Tracked and documented every configuration change as SPRS control evidence for the SSP.
Secure Score
54.5%83.6%

Additional projects

Ongoing

Security Home Lab: Hardened Linux & Detection Testing

A live sensor against real scanner and brute-force traffic, used to validate detections and practice incident response workflows.

Production automations

Executive Assistant: Daily CEO Brief

Parallel fan-out across 7 email folders, projected fields, HTML digest. Replaced a sequential 1.1 MB version.

Invoice Automation: Email Drafter (v3)

Resolves invoice PDF + MSR + Hours Report, creates an unsent draft via Graph. No Mail.Send, so a human always reviews.

MSR Automation: Monthly Status Reports

Intake → Aggregator → MissingNudge. Three flows, a shared SharePoint data model, and a config-driven approval chain.

Offer Letter: HR Generator

Event-triggered: selects 1 of 8 Word templates, populates fields, runs an approval loop, converts to PDF. Draft-only, no auto-send.

IT Intake: Single Front Door

Microsoft Form → SharePoint list → Teams notification → daily digest. Security concerns force-escalate to Urgent.

A career built by taking ownership, then widening the security boundary.

  1. Systems Administrator

    Aalis Management Consulting · Alexandria, VA · Jul 2023 to Present

    One half of a two-person technical team with the CTO, with no tier above and no MSP behind the role. Promoted from Help Desk after three months.

    Selected outcomes

    • Triage and investigate phishing and security incidents in the Microsoft Defender XDR queue using KQL Advanced Hunting, email header and message-trace forensics, and Entra ID sign-in logs; remediate affected mailboxes and identities, document findings, and escalate to leadership.
    • Led the investigation of a data-handling incident involving improper access to sensitive records: preserved audit-log evidence, reconstructed the timeline, scoped exposure, and delivered written findings to executives.
    • Raised Microsoft Secure Score from 54.5% to 83.6% across 30+ endpoints through configuration remediation, Conditional Access and MFA enforcement, least-privilege access controls, and endpoint hardening.
    • Primary author of the SSP and POA&M, producing roughly 70% of the compliance program under NIST SP 800-171 and DFARS 252.204-7012; co-led the self-assessment behind a 110/110 SPRS score and current CMMC Level 2 preparation.
    • Entra ID
    • Intune
    • Defender
    • Purview
    • Exchange Online
    • SharePoint
    • Built the automation layer the company runs on with PowerShell, Microsoft Graph API, and Power Automate: onboarding and offboarding, license lifecycle, security alert routing, compliance document generation, invoicing, and recurring status reporting. Estimated 1,200+ staff-hours returned annually.
    • Authored and maintain 12+ policies, runbooks, and SOPs covering incident response, access control, onboarding and offboarding, and audit readiness, including the company's AI acceptable-use policy as the de facto owner of AI adoption.
    • Brief executives directly on security posture, risk, and remediation status, translating technical findings into decisions for a non-technical leadership team.

    Additional tools: Teams · Microsoft Graph · PowerShell · Power Automate · KQL · Sigma · MITRE ATT&CK · NIST SP 800-171 · CMMC

  2. Contract Closeout Specialist (Contract)

    NewView Oklahoma · Oklahoma City, OK (Remote) · Nov 2024 to Apr 2026

    Federal contract closeout in a CUI environment, concurrent with the role above.

    Selected outcomes

    • Closed out 5,000+ federal contract records at a sustained rate of roughly 500 per month, verifying documentation completeness and disposition under FAR, DFARS, and federal records-retention requirements.
    • Handled contract documentation marked as Controlled Unclassified Information, applying need-to-know access, marking, and retention requirements throughout the closeout lifecycle.
    • Administered SharePoint permissions for contract document libraries, aligning site and folder-level access to least privilege and need-to-know.
    • SharePoint
    • CUI handling
    • FAR
    • DFARS
    • Automated Excel-based document generation and recurring reporting, removing manual preparation effort from the closeout workflow.
    • Provided technical support to staff on account, access, and application issues alongside the primary closeout workload.

    Additional tools: Records retention · Excel automation

  3. IT Support

    Planting Hope Global · Remote · Dec 2020 to Jul 2023

    Sole IT resource for a fully distributed nonprofit, with no internal team or vendor behind the role.

    Selected outcomes

    • Served as the primary IT resource for a distributed nonprofit workforce, providing account provisioning, password resets, troubleshooting, and remote support.
    • Managed WordPress hosting, SSL certificates, website updates, patching, backups, and access controls to maintain security and operational continuity.
    • Implemented role-based access controls and security best practices to protect organizational and donor information.
    • WordPress
    • SSL/TLS
    • RBAC
    • Remote support
    • Authored IT documentation, user guides, and runbooks supporting onboarding, troubleshooting, and business continuity.

    Additional tools: Runbooks

Security depth, systems breadth, and credentials you can verify.

Security Operations

Detect, triage, and respond to threats against a live federal environment.

Detection Engineering

Ship detection logic as reviewed, tested code rather than one-off SIEM queries.

Microsoft 365 & Identity

Own the identity plane and the platforms that run on top of it.

Automation & Scripting

Remove recurring manual work and give the hours back to the business.

Environment under management

Identity

Entra ID
Directory, MFA, RBAC, and Conditional Access for the tenant.

Endpoint

Intune
Endpoint management and security baselines across 30+ devices.
Defender
EDR, attack surface reduction, and automated investigation.

Data & compliance

Purview
DLP policies protecting CUI across email and SharePoint.
Exchange Online
Mail flow, transport rules, and phishing investigation.
SharePoint
14 sites under governance, plus an 11-page staff intranet.
Teams
Collaboration governance and automated operational alerting.

Automation

Microsoft Graph
The API surface every automation in the environment runs through.
PowerShell
Provisioning, reporting, and remediation at tenant scale.

Security Operations

Microsoft Defender XDR triage · KQL Advanced Hunting · Phishing investigation · Email forensics (headers, message trace, Threat Explorer) · Entra ID sign-in analysis · Incident response lifecycle · Threat hunting · Log analysis · Evidence preservation · Runbooks and SOPs

Detection Engineering

Sigma rule authoring · KQL for Sentinel and Defender · Detection-as-code (Git, GitHub Actions CI) · MITRE ATT&CK mapping · False-positive analysis and tuning · Detection validation and testing

Microsoft 365 & Identity

Entra ID · Exchange Online · SharePoint · Teams · Intune · Defender · Purview · Microsoft Graph API · Active Directory · MFA · SSO · RBAC · Conditional Access · DLP

Compliance & Governance

NIST SP 800-171 · CMMC Level 2 · SSP · POA&M · SPRS · RMF · CUI · FAR · DFARS 252.204-7012 · Audit evidence · Policy & SOPs

Automation & Scripting

PowerShell · Python · Power Automate · Microsoft Graph API · REST APIs · SQL · Excel automation · AI automation

Systems & Web

Windows administration · Endpoint lifecycle · Next.js · React · TypeScript · Tailwind · WordPress · Vercel · Git/GitHub

AI & Security Research

Prompt injection research · Attack taxonomy design · Detection classifier development · Python/Flask · pytest · Published research

Verified credentials

Education

  • 2019

    Bachelor of Arts in Fine Art

    The University of Virginia’s College at Wise

Hiring for security operations or detection engineering? Let's talk.

I am targeting security roles where Microsoft systems ownership and automation are leverage, not separate lanes. The fastest way to reach me is email.