Senior Cyber Threat Intelligence Analyst · Applied AI Builder

Find what hides. Make the next move count.

Threat intelligence built for decisions that cannot wait. Deep- and dark-web research, digital-risk investigations, and AI-enabled systems reveal exposure earlier and turn scattered signals into action.

HundredsAnalyst hours returned
2High-stakes CTI environments
PublishedCrowdStrike research
4Open-source security builds

SEE EARLIER × DECIDE FASTER × BUILD LEVERAGE

Security teams do not need more noise. They need the signal that changes the decision.

Experience across financial services and frontline threat intelligence has shaped a practical view of risk: the most valuable signal is often outside the perimeter, incomplete, and already moving. The work connects deep- and dark-web activity, identity exposure, phishing infrastructure, ransomware, and third-party risk to the decisions leaders actually face.

That intelligence becomes more valuable when it scales. Analyst automation, open-source security tools, distributed Ray/K3s infrastructure, and local AI systems turn repeated manual work into durable capability. Results are tested in the lab, applied in real workflows, and shared in plain language.

01

Expose the blind spot

Find the external signals conventional monitoring misses.

02

Turn signal into judgment

Separate evidence from assumptions, state confidence, and make the decision easier.

03

Build the advantage

Automate repeatable work so skilled people stay focused on the problems that need them.

Experience in practice

Frontline intelligence across a global cybersecurity leader and one of Canada’s largest financial institutions.

2024 — NOW
CrowdStrike

Senior Threat Intelligence Analyst

Investigates threats developing across the deep and dark web, digital-risk surfaces, identity exposure, and adversary infrastructure. Builds analyst automations that return hundreds of hours, strengthens repeatable workflows, and mentors new talent so intelligence scales beyond one analyst.

  • Hundreds of hours returned
  • Scalable analyst workflows
  • Talent development
2021 — 2024
Royal Bank of Canada

Threat Intelligence Analyst → Senior

Built third-party breach policy, ran deep- and dark-web monitoring, investigated ransomware and phishing ecosystems, and supported compromised-data retrieval. Connected outside-the-perimeter risk to repeatable tracking and response across the bank.

  • Third-party breach policy
  • Deep- and dark-web monitoring
  • Ransomware response

Research built to be used

Read all on LIGMA.BLOG ↗

OPEN-SOURCE BUILDS

When a workflow repeats, it becomes a tool.

SELECT CONVERSATIONS

Bring the problem that does not fit neatly in a ticket.

The strongest conversations start with an exposed asset, a weak signal, an intelligence process that will not scale, or a security decision missing evidence. If that sounds familiar, the channel is open.