Murfreesboro, TN
Ricky Tipler
Security Engineer
Security Engineer with 5+ years protecting enterprise environments in healthcare and government — SIEM engineering, threat hunting, and cloud security.
- 5+
- Years Experience
- 6
- Certifications
- 40+
- Detection Rules
01 — About
Defense across healthcare and government.
Security Engineer with 5+ years defending enterprise environments across healthcare and government. I work across SIEM engineering, endpoint detection and response, threat hunting, vulnerability management, and cloud security — currently focused on SIEM engineering, EDR operations, and AWS security.
Holder of the AWS Security Specialty, CASP+, and several other cloud/security certifications. Outside of work I build hands-on cloud security projects (Terraform on AWS), write detection content, and ship tools like PageShield — a Chrome extension for phishing detection and AI prompt safety.
02 — Experience
Where I've operated.
-
Cybersecurity Specialist
Security specialist supporting enterprise healthcare environments — detection engineering, endpoint defense, threat hunting, and response operations across SIEM, EDR, and related tooling.
- Engineered SIEM detection pipelines and tuned alert logic to expand coverage and reduce false positives.
- Deployed and validated EDR, and conducted threat hunts that pivoted intel into SIEM and EDR.
- Integrated vulnerability scanning into server onboarding and built SOAR playbooks for faster containment.
- Automated security validation with PowerShell and managed enterprise SSL/TLS certificate lifecycles.
-
Information Security Administrator
Secured systems across state correctional facilities — access controls, endpoint hardening, and incident response.
- Designed and deployed a secured inmate-operated call center, including network placement, firewall rules, and GPO security baselines.
- Led insider-threat investigations from detection through resolution, tightening access controls afterward.
- Built PowerShell automation for security compliance checks across endpoints.
03 — Projects
Shipping log
Hands-on builds — expand an entry for the full breakdown.
-
A Chrome extension that detects phishing sites in real time by analyzing URLs, domain patterns, and page content, protecting users from credential theft and social engineering before they engage with a malicious page.
- Dynamic risk-scoring engine rates visited sites on a 0–100 threat scale, shown as a color-coded badge in the toolbar.
- AI prompt safety warning system intercepts input to AI chatbots and flags sensitive data (passwords, PII, confidential info) before submission, reducing accidental data exposure through AI tools.
-
A detection engineering portfolio of 40+ Sigma rules developed through SOC Labs challenges. Covers persistence, privilege escalation, credential access, and related techniques across Linux, Windows, and cloud — with MITRE ATT&CK mapping and SIEM-ready detection logic.
- Rules organized by platform and attack technique for reuse in detection engineering workflows.
- Mapped to MITRE ATT&CK so detections stay tied to adversary behavior, not just log noise.
- Written for SIEM ingestion — portable Sigma content that can be adapted to enterprise detection stacks.
-
A fully private serverless API on AWS, built entirely with Terraform. API Gateway triggers a Lambda function in private subnets, which reaches an RDS MySQL instance in isolated database subnets — nothing in the data path is publicly exposed.
- Database credentials stored in Secrets Manager, encrypted with a customer-managed KMS key.
- Security groups restrict traffic so only the Lambda function can reach the database.
- Full environment — VPC, public/private/database subnets across multiple AZs, NAT gateway, IAM roles — deployed repeatably from code.
- Includes a detailed architecture and implementation writeup in the repository.
04 — Tools & Stack
Tools I've worked with
Security platforms and technologies I've used across enterprise environments and hands-on projects — listed by category, not tied to any single employer.
SIEM
EDR
SOAR
Threat Intelligence
Vulnerability Management
Certificate Management
Cloud Platforms
Infrastructure as Code
Scripting & Automation
PAM
Email Security
Data Security
Firewall / Network Security
05 — Certifications
Validated credentials
Each badge links to my Credly profile.
- AWS AWS Certified Security – Specialty View on Credly →
- AWS AWS Certified Solutions Architect – Associate View on Credly →
- CompTIA Advanced Security Practitioner (CASP+) View on Credly →
- CompTIA PenTest+ View on Credly →
- CompTIA Cloud+ View on Credly →
- HashiCorp Terraform Associate View on Credly →
Education
B.A. — Computer Information Systems
Thomas Edison State University
07 — Contact
Let's connect.
Open to security engineering conversations, collaborations, and interesting problems.
- Email Reveal email
- GitHub github.com/rickytip
- LinkedIn linkedin.com/in/ricky-tipler
- Location Murfreesboro, TN