Skip to content

$ whoami

Edward Griggs

Detection Engineering · Microsoft 365 Security · Identity, Compliance & Automation

// Open to SOC, Detection, SysAdmin, and AI roles — based in Yorktown, VA, open to relocation nationwide.

01 / about

about

Security+ certified practitioner running the entire IT and security function for a 50+ user federal GovCon contractor alongside one CTO. I investigate incidents in the Defender XDR queue with KQL Advanced Hunting and email forensics, run identity and endpoint security across Entra ID, Intune, Defender, and Purview, and maintain a Sigma detection-as-code pipeline with GitHub Actions CI.

I was the primary author of the SSP and POA&M, roughly 70% of the compliance program under NIST SP 800-171 and DFARS 252.204-7012, behind a perfect 110/110 SPRS score. The organization holds CMMC Level 1 today and is actively preparing for Level 2. I raised Microsoft Secure Score from 54.5% to 83.6% across 30+ endpoints and built automation returning an estimated 1,200+ staff-hours a year.

110/110
SPRS score
Perfect DoD NIST SP 800-171 self-assessment
54.5 → 83.6%
Microsoft Secure Score
+29 points across 30+ endpoints
1,200+
Staff-hours automated / yr
PowerShell, Power Automate, Graph, and AI
50+
Users supported
Federal GovCon CUI environment, two-person technical team
02 / skills

skills

Security Operationsscanning…
Defender XDR triage & responsePhishing investigationEmail forensics (headers, message trace, Threat Explorer)KQL Advanced HuntingEntra ID sign-in analysisEvidence handlingRunbooks & SOPs
Detection Engineeringscanning…
Sigma rule authoringDetection-as-code (Git + GitHub Actions CI)KQL for Sentinel and DefenderMITRE ATT&CK mappingFalse-positive analysis & tuning
Identity, Endpoint & Cloudscanning…
Entra IDConditional AccessMFARBAC/IAMLeast privilegeIntunePurview DLPExchange OnlineSharePointTeamsSecure ScoreEndpoint hardening
Automation & Engineeringscanning…
PowerShell (advanced)Microsoft Graph APIPower AutomatePythonREST APIsGit/GitHubLinux hardeningProcess designExecutive reporting
Governance & Compliancescanning…
NIST SP 800-171DFARS 252.204-7012FARCMMC (L1 today, L2 in prep)CUI handlingSSPPOA&MSPRSAccess reviewsAudit evidenceAI acceptable-use policy
Systems & Webscanning…
Windows administrationEndpoint lifecycleNext.jsReactTypeScriptTailwindWordPressVercel
03 / experience

experience

[Jul 2023 – Present]

Systems Administrator

@ Aalis Management Consulting · Alexandria, VA (Remote) · 50+ users, 30+ endpoints, CUI · two-person technical team with the CTO

Built the automation layer the company runs on: PowerShell, Microsoft Graph, and Power Automate systems for onboarding/offboarding and license lifecycle, security alert routing, compliance document generation, invoicing, and recurring status reporting. Estimated 1,200+ staff-hours returned annually.

Raised Microsoft Secure Score from 54.5% to 83.6% across 30+ endpoints through configuration remediation, Conditional Access and MFA enforcement, least-privilege access controls, and endpoint hardening.

Investigate phishing and security events in the Defender XDR incident queue using KQL Advanced Hunting, email header and message-trace forensics, and Entra ID sign-in logs; remediate affected mailboxes and identities and escalate to leadership.

Ran the investigation of a data-handling incident involving improper access to sensitive records — preserved audit-log evidence, reconstructed the timeline, scoped exposure, and delivered written findings to executives.

Primary author of the SSP and POA&M, producing roughly 70% of the compliance program under NIST SP 800-171 and DFARS 252.204-7012; co-led the self-assessment behind a 110/110 SPRS score and current CMMC Level 2 preparation.

Wrote and maintain 12+ policies, runbooks, and SOPs covering incident response, access control, onboarding/offboarding, audit readiness, and the company's AI acceptable-use policy — authored as the de facto owner of AI adoption. Brief executives directly on posture, risk, and remediation.

[Nov 2024 – Apr 2026]

IT & Security Support (Contract)

@ NewView Oklahoma · Oklahoma City, OK (Remote) · concurrent with the role above

Supported secure handling and closeout of 5,000+ federal contract records, roughly 500 per month, under FAR, DFARS, and records-retention requirements; conducted access reviews enforcing need-to-know access and audit readiness.

Configured Microsoft 365 security settings, MFA, SharePoint permissions, and certificate-based authentication; automated Excel document generation and reporting.

[Dec 2020 – Jul 2023]

IT Support

@ Planting Hope Global · Remote · sole IT resource for a distributed nonprofit

End-user support and account provisioning for a distributed workforce; administered WordPress hosting, SSL certificates, patching, backups, and RBAC.

Built the site in HTML/CSS and wrote the organization's first IT documentation and runbooks.

04 / projects

projects

Detection-as-Code Pipeline — Sigma, GitHub Actions, Sentinel & Defender

2026

Sigma rules in Git with a GitHub Actions CI pipeline that validates rule syntax and compiles to KQL for Microsoft Sentinel and Microsoft Defender on every commit. Rules cannot merge until validation passes. Four detections mapped to MITRE ATT&CK — password spray (T1110.003), brute force (T1110.001), impossible travel, and malicious inbox rule creation (T1098) — each documented with false-positive analysis and validation steps.

SigmaKQLGitHub ActionsMITRE ATT&CKMicrosoft SentinelMicrosoft DefenderCI/CD

Security Home Lab

Ongoing

Hardened Linux environment running key-based SSH only, a default-deny host firewall, Fail2ban, CrowdSec, and Tailscale overlay networking to remove public internet exposure. Analyze authentication logs against real scanner and brute-force traffic.

LinuxSSH hardeningUFWFail2banCrowdSecTailscaleZero Trust

Prompt Injection Security Research

2026

Authored and published "Hijacking the Prompt: A Survey of Prompt Injection Attacks, Detection, and Defense in Large Language Models" on ODU Digital Commons. Built a Python/Flask classifier matching 13 prompt injection signatures to a six-category taxonomy, validated by 83 passing pytest tests.

AI SecurityPythonResearch

Vault 7: Cybersecurity Training Game

2026

Browser-based training game teaching phishing awareness, password security, and defensive decision-making through mission-style scenarios. Led a four-person team as Team Lead and Lead Developer; selected as the winning project in the COVA CCI Design Cohort.

Security EducationGame

edwardgriggs.com

2026

This site. A modern-terminal portfolio with scroll-driven scanner bars and a log-line work history. Next.js, React, Tailwind, Framer Motion, deployed on Vercel.

Next.jsDesign
05 / certs

certs

Security

CompTIA Security+

CompTIA · SY0-701 · 2026
verifycertified
Security

Google Cybersecurity Professional Certificate V2

Google · 2025
AI

Google AI Professional Certificate

Google · 2025
AI

Generative AI Essentials for Cybersecurity

IBM · 2025
06 / case studies

case studies

07 / automation

automation

06 / education

education

B.S. in Cybersecurity
Old Dominion University · May 2026
B.A. in Studio Arts
The University of Virginia's College at Wise · 2019
07 / contact

contact

$ ./contact --where-to-find-me

Open to SOC, Detection, SysAdmin, and AI roles — based in Yorktown, VA, open to relocation nationwide. The fastest way to reach me is email or LinkedIn.

where to find me

edwardjgriggs@gmail.com