DETECTION ENGINEERING & SECURITY AUTOMATION[ UNITED STATES / 2026 ]

BLAYQEFORBES.

AKA / 0x5erotonin

I turn complex threats into
clear signals. And action.

Explore my workTHREAT HUNTING
CLOUD SECURITY
SECURITY SOFTWARE

THE EXPERIENCE BEHIND THE WORK

Different industries. One security mindset.

CURRENTLY AT CREYOSExplore the journey

01 / THE MINDSET

Curiosity is the starting point.
Making things safer is the goal.

Built on curiosity.
Driven by defense.

I’m Blayqe, a security engineer with 7+ years across IT and cybersecurity. I work at the intersection of detection engineering, threat hunting, and automation—finding the signal, understanding the threat, and building a better response.

At Creyos, I build cloud security controls, device management, and automated detections. My experience spans financial services and healthcare, from enterprise incident response at Capital One to vulnerability management and GRC at Novant Health.

7+

Years across IT & security

FOUNDATIONS BUILT SINCE 2019
100+

Weekly Splunk queries

THREAT INVESTIGATIONS / CAPITAL ONE
1,000+

Vulnerabilities remediated

IN COLLABORATION WITH GRC / NOVANT

02 / SELECTED WORK

Security, in practice.

Explore GitHub
ANALYST INSTINCT. ENGINEER MINDSET.0x5erotonin / BF

03 / THE JOURNEY

Real environments.
Real responsibility.

2019 — PRESENT
CURRENT ROLEFEB 2025 — PRESENT

Creyos

Security Engineer

Building security into the way a company operates.

  • Implemented company-wide device management, from development through rollout.
  • Authored cloud risk management policies and disaster recovery strategies.
  • Built automations for cloud permission monitoring, privilege escalation, and denial-of-service detection.
Cloud securityMDMAutomation
FEB 2023 — FEB 2025

Capital One

SOC Analyst · Cyber Threat Analyst

Investigating threats across cloud, identity, endpoint, and network environments.

  • Executed 100+ weekly Splunk queries; investigated phishing, malware, AWS CloudTrail activity, and identity threats across Okta, Entra ID, and Google Workspace.
  • Developed security tools in PowerShell, Python, and C++; automated enrichment and response with XSOAR and CI/CD pipelines.
  • Led complex incident response, investigated nation-state and APT activity, and delivered executive threat intelligence briefings.
  • Performed security code reviews and PCAP analysis, and designed DFIR capture-the-flag exercises for the Blue Team.
SplunkXSOARThreat huntingIncident response
MAR 2022 — FEB 2023

Novant Health

Risk Analyst · Governance, Risk & Compliance

Connecting technical risk with practical remediation.

  • Supported 2,500+ incident tickets and remediated 1,000+ vulnerabilities with GRC teams.
  • Assessed Windows and Linux environments with Tenable, prioritized critical remediation, and supported SOC 2 and HIPAA compliance.
  • Processed 500+ monthly vendor access requests, enforced least privilege through Active Directory, and used KQL for security investigations and tabletop exercises.
Vulnerability managementIAMGRCKQL

THE FOUNDATION / IT OPERATIONS & SUPPORT

AUG 2020 — MAR 2022

Zelis

Service Desk Analyst

Supported users across eight locations; introduced 100+ processes, procedures, and documentation for a new service desk. Recognized for “Best Customer Service.”

JAN 2020 — MAY 2020

WellStar Atlanta Medical Center

Service Desk Analyst

Resolved desktop, laptop, mobile, hardware, and network issues; documented incidents and supported users across phone, chat, and email.

AUG 2019 — DEC 2019

Yancey Power Systems

IT Help Desk Technician

Austell, Georgia

MAY 2019 — AUG 2019

Fulton County Government

IT Field Technician Intern

Greater Atlanta Area

04 / THE TOOLKIT

Tools change.
The mindset compounds.

Across cloud, code, and operations.
Always learning. Always building.

[ 01 ]

Detection & response

  • Splunk Enterprise Security
  • Splunk ITSI
  • Security Onion
  • CrowdStrike
  • SentinelOne
  • Exabeam
  • XSOAR
  • Proofpoint
  • Sysmon
  • Netskope
[ 02 ]

Cloud & identity

  • AWS · CloudTrail
  • Azure · Entra ID
  • Google Cloud
  • Okta
  • Google Workspace
  • Active Directory
  • Docker
  • Kubernetes
  • Linux
[ 03 ]

Build & automate

  • Python
  • PowerShell
  • Bash
  • C++
  • Rust
  • Git
  • Terraform
  • Jenkins
  • Puppet
  • KQL
[ 04 ]

Risk & resilience

  • NIST
  • HIPAA
  • FISMA
  • SOC 2
  • Qualys
  • Tenable
  • Threat modeling
  • Vulnerability management
  • Disaster recovery

Education

Western Governors University

Bachelor’s degree

Cybersecurity & Information Assurance

West Georgia Technical College

Associate’s degree

Information Technology

Credentials & training

  • Splunk Certified Cybersecurity Defense Analyst
  • CCSKCertificate of Cloud Security Knowledge
  • SEC504Hacker Tools, Techniques, and Incident Handling
  • PCI Compliance
05 / BEYOND THE ALERTS

Still curious.
Even off the clock.

I’m exploring AI implementations for security services and writing about the things I build. Away from security, ask me about health and football.

Read my writing on Medium