Ctrl+` · terminal
decrypting the signal_

Andrew Acevedo

Cybersecurity Engineer · Enterprise Defense & Cloud
Hardening systems. Decrypting intent.

Cybersecurity engineer in enterprise defense and cloud — turning noisy, obfuscated signals into actionable intelligence. Seven-plus years in IT infrastructure, three-plus dedicated to security, now applying cloud and generative AI to enterprise defense.

prompt-guard — llm injection risk linter

owasp llm top-10 mapping

About

$ whoami

I look at security as a system, not a stack of tools. Seven-plus years in IT infrastructure, three-plus in security — and I've seen how a single misconfigured policy can snowball across an entire fleet. I've protected environments with over 1,000 endpoints and engineered policy across next-gen hardware firewalls.

I'm curious about how systems fit together — the infrastructure that runs an organization and the threats that target it. The map keeps growing: cloud architecture, and the generative and agentic AI now entering the enterprise, aren't a pivot — they're the next layer of the system I already secure. I'm interested in the workflows and automation agentic AI will bring, and in building those systems to be genuinely useful while building in the safeguards to catch abuse and alert when something's off. I don't just fix what's broken — I want to understand why it broke and make the whole system more resilient.

Experience

$ cat experience.log

Cybersecurity Engineer

Volunteers of America — Greater New York · Jul 2023 — Present

Lead endpoint protection for 1,000+ devices — owning EDR, vulnerability management, and threat-intelligence correlation across enterprise and cloud. Spearheaded an AI-driven email-security deployment and turned firewall telemetry into network-segmentation decisions.

Technical Support Engineer II

Systems Administrator
Volunteers of America — Greater New York · Jan 2023 — Jun 2023

Performed system administration duties — managing endpoint security to deploy VPN and enforce policy, configuring SSO with SAML and conditional access, automating user management and reporting, and maintaining Windows server infrastructure and Active Directory. Provided advanced technical support and mentored junior team members.

Technical Support Engineer I

IT Support / Junior Sys Admin
Volunteers of America — Greater New York · Oct 2021 — Dec 2022

Owned end-to-end support across Windows, macOS, iOS, and Android while taking on growing systems administration — managing OS updates, application deployments, and SSO administration as subject-matter expert for a leading mobile device management solution.

Microsoft 365 Technical Support Specialist

Zones, LLC · Apr 2021 — Aug 2021

Expert support for Microsoft 365, resolving complex customer issues and managing installation, configuration, and user/license provisioning across platforms. Documented work in a ticketing system and escalated product bugs.

Information Technology Technician

Nert Consultants · Jun 2019 — Sep 2020

IT support for NYC clients — deployment and maintenance of Windows and Office 365 environments, Active Directory / Azure AD administration, SOHO network setup, and end-user training.

Building Toward

$ compile --future

AI is already making decisions inside organizations, and those decisions need security frameworks that don't fully exist yet. I'm building toward that intersection: cloud-native defenses that secure AI systems, plus using AI to make security operations faster.

The goal isn't replacing human judgment — it's giving analysts better tools to spot what actually matters. Secure AI, and AI that makes everything else more secure.

The hard problems are the ones agentic AI introduces: how an agent's shared knowledge gets scoped so it only knows what it needs to; how it authenticates and holds credentials without becoming a standing risk; how you isolate agents by domain so one compromise doesn't become a system-wide one; and how you securely instruct and constrain an agent once it's acting on its own. These are the same questions I've been asking about infrastructure for years — now applied to systems that can act on their own.

Skills

$ cat skills.txt
Endpoint SecurityCloud SecurityIdentity & Access ManagementNetwork SecuritySIEM & Threat DetectionIncident ResponseSecurity AutomationVulnerability ManagementThreat IntelligenceSecurity GovernanceScripting & AutomationRisk Frameworks
familiar with
FortinetOktaCrowdStrike FalconCarbon BlackMicrosoft DefenderAzure AD / EntraWorkspace ONEBox ShieldIntunePythonJavaScriptPowerShellMITRE ATT&CKNIST CSFCIS Benchmarks

Certifications

$ cat credentials.txt
CrowdStrike Falcon ResponderBlue Team Level 2 (BTL2)CrowdStrike Falcon AdministratorCompTIA CySA+Cisco CCNACompTIA Security+CompTIA Network+CompTIA A+
previously held
Fortinet NSE 4Microsoft Azure Administrator AssociateAWS Solutions Architect Associate

Contact

$ openssl s_client -connect andrew:443