$ whoami

Braeden R.
Santos

// Senior Security Engineer  ·  Network Defense  ·  Microsegmentation

I secure enterprise infrastructure at scale — specializing in Zero Trust architecture, Guardicore microsegmentation, and threat hunting. Based in New Bedford, Massachusetts. Currently deepening my certifications and building toward a cybersecurity leadership role.

Braeden R. Santos

About

Senior Technical Support Engineer and Hunt Analyst with hands-on expertise in microsegmentation, network security, and enterprise threat response. I spend my days in the weeds of real production environments — analyzing traffic, tuning policies, and responding to escalations that require both depth and speed.

Outside of work, I run a home lab on my MacBook Pro M5 Pro 48 GB using UTM — pfSense, Windows Server, Wazuh, and intentionally vulnerable targets — to stay sharp and experiment with techniques I can’t run in production. It’s where the real learning happens.

Long-term, I’m moving toward leadership in cybersecurity — building the technical credibility and strategic thinking to run customer success and security programs at scale.

5+
Years in Security
ZT
Zero Trust Focus
Lab
Active Home Lab
Always Leveling

Skills & Certifications

Network Security
Microsegmentation Zero Trust pfSense Firewall Policy IDS/IPS Network Flow Analysis VLANs
Threat Operations
Threat Hunting Wazuh / SIEM Log Analysis Incident Response IOC Identification MITRE ATT&CK
Infrastructure & Tools
Proxmox Windows Server Linux Active Directory Guardicore Virtualization
Certifications
CompTIA Security+ SY0-701
IN PROGRESS
CISSP
NEXT

Projects

01
Mac UTM Security Home Lab

Full enterprise-grade home lab running on MacBook Pro M5 Pro with 48 GB RAM using UTM. Segmented network with pfSense routing, isolated attack/defense zones, and Wazuh as the central SIEM — mirrors real production security architecture.

UTM pfSense Wazuh Windows Server Metasploitable 2
02
Zero Trust Microsegmentation Design

Modeled and implemented microsegmentation policy frameworks based on real-world Guardicore deployments. Includes traffic flow mapping, policy ring design, and rollout strategy for hybrid enterprise environments.

Guardicore Zero Trust Policy Design Network Flow
03
Wazuh Threat Detection Tuning

Built and tuned custom Wazuh detection rules against common attack patterns — lateral movement, credential dumping, and persistence mechanisms — tested against Metasploitable 2 in an isolated lab environment.

Wazuh SIEM Detection Engineering MITRE ATT&CK
04
Security+ Study Framework

Structured self-study system combining Professor Messer’s video course, Sybex guide, and GoodNotes on iPad — with dedicated lab exercises mapped to exam domains. Exam target: June 8, 2026.

CompTIA Security+ SY0-701 Home Lab Active Study

Writing

Posts are published periodically. No newsletter. No filler.

Contact

Open to conversations about security architecture, Zero Trust strategy, leadership roles in cybersecurity, or anything interesting at the intersection of network defense and people.