Context beats isolated scores.
Predictions become useful when they carry provenance, supporting evidence, and a clear relationship to operating cost.
About / Career narrative
I build applied machine learning systems with the instincts of a security practitioner: question the data, trace the evidence, anticipate failure, and design for the operator who has to act on the result.
My career in applied AI began with cybersecurity work. At Cisco Talos, I spent years analyzing large-scale security data, maintaining threat-intelligence databases, automating reporting, and developing approaches to improve phishing URL detection. The work made one pattern hard to ignore: analysts repeatedly faced classification problems that machine learning could help structure and scale.
That observation became a transition into data science and machine learning—not away from security, but deeper into it. I learned to treat features, labels, and evaluation as parts of an operational decision system. A model was useful only if it could survive changing adversary behavior, incomplete context, and the consequences of false positives.
At Cisco Learning & Development, I expanded that systems perspective into generative AI. I led a services team delivering a production retrieval-augmented generation assistant on AWS, built semantic search and knowledge-retrieval experiences, and used telemetry and feedback to improve the product. Related work in graph data models and metadata reinforced the same lesson: context and provenance shape quality.
Today, as a Senior Data Scientist at ThreatSTOP, I lead machine learning pipeline work for phishing detection in DNS traffic. The system combines character-level language features and multiple classifiers with WHOIS, DNS, VirusTotal, DGA, and anomaly signals. It is designed around real constraints such as shared API quotas, deduplication, model artifacts, and security-team workflows.
I want to keep specializing at the intersection of AI security and production applied AI—work where model quality, system reliability, and technical judgment all matter.
Technical philosophy
Predictions become useful when they carry provenance, supporting evidence, and a clear relationship to operating cost.
Quotas, latency, drift, missing fields, and analyst capacity are not deployment footnotes; they shape the right model and architecture.
Telemetry, investigation outcomes, data-quality signals, and user behavior create the loop that makes applied AI improve over time.
What I enjoy building
Systems that make complex evidence usable.
That includes security classifiers with layered context, recurring pipelines that turn noisy feeds into dependable inputs, and knowledge products that help people find grounded answers. I’m most engaged when the work crosses boundaries between modeling, data engineering, product behavior, and operations.
Current focus: phishing and DNS threat detection, AI security, production ML architecture, retrieval quality, and agent-accessible knowledge systems.
Skills overview
Selected systems
Explore detailed case studies covering the problem, architecture, operational constraints, evaluation, and lessons learned.
Portfolio assistant