Brad Nelson personal email
- Valid
- Valid
Brad Nelson phone numbers
Highly skilled cyber security professional with over 18 years of experience serving a variety of public and private entities. Brad has been the Advanced Adversarial Defense/Threat Hunting technical lead and primary contributor at 2 large financial institutions over the past 7 years performing large scale Advanced Analytics leveraging Data Science, Machine Learning, Python API scripting, Splunk-Fu, Full Packet Capture, Statistical & Behavioral Analysis technologies as well as creating a home-grown Threat Hunting Automation Platform. Previous roles in various critical infrastructure sectors include insider threat monitoring of classified government networks and Security Architecture Lead for both the Department of Homeland Security and Federal Deposit Insurance Corporation. Prior to his time contracting in DC, Brad served two years as an Information Security Architect with a Fortune 200 utility responsible for enterprise strategic planning, policy development, business unit consulting, technological evaluations, and methodology development. With foundational experiences as both a Security Operations Center Analyst for an MSSP serving the financial sector and a Technology Infrastructure Consultant with a global front-runner in systems integration, Brad demonstrates the industry breadth, technical depth, and organizational acumen of a technology leader.
-
Senior Security EngineerAmazon Jun 2021 - PresentSeattle, Wa, Us -
Vice President, Cyber Security Research Strategist (Threat Hunting Automation Lead)Wells Fargo Jul 2018 - May 2021San Francisco, California, UsAdvanced Analytics & Threat Hunting Automation Technical Lead -
Cyber Security Research Strategist (Threat Hunting Automation Lead)Wells Fargo Apr 2018 - Jul 2018San Francisco, California, UsAdvanced Analytics & Threat Hunting Automation Technical Lead -
Advanced Analytics & Threat Hunting Automation LeadWells Fargo Aug 2017 - Apr 2018San Francisco, California, Us -
Threat HunterCiti Feb 2014 - Jul 2017New York, New York, Us• Full-time threat hunter as a member of the Advanced Cyber Defense team primarily focused on full network capture threat analysis via NetWitness and Splunk.• NetWitness SME responsible for developing Citi’s content baseline (160+ Parsers, 300+ Application Rules, 40 Threat Feeds), network and asset inventories, all custom content creation, Splunk integration (App & API), and SOC training.• Developed a custom hunting engine to automate the analysis of 2 billion sessions per day for activity from 400,000 employees and 200 million customers spanning 3 continents. Automation architecture leverages NetWitness REST API, Splunk statistical and behavioral analysis capabilities, Elasticsearch clusters, pre and post-processing scripts, proxy logs, EPO logs, and API integration with various free and commercial 3rd party tools.• Developed custom content to augment traditional security product detection shortcomings with a focus on Citi specific threats, vulnerabilities, and detection gaps: DGA detection, DNS exfiltration, covert data exfiltration, credit card leakage prevention, malware beaconing, employee data exfiltration, phishing domain detection, phishing VBA macro analysis, PE analysis, and domain registration interrogation.• Session Speaker at RSA Charge 2016: “Threat Hunting: Filling in the Gaps”• Develop rules, reports, alerts, and ad-hoc queries to detect the presence of insider threats, targeted campaigns, and advanced TTPs.• Responsible for developing advanced threat use cases for implementation by the content delivery team, formulating threat detection frameworks, and hunting for threat and fraud IOCs.• Develop rules in RSA Web Threat Detection (SilverTail) to analyze online banking web sessions for instances of fraud, customer credential abuse, and other suspicious account activity. -
Principal Solutions Architect (Contractor)U.S. Department Of Homeland Security Apr 2013 - Feb 2014Washington, Dc, Us• Functioned in two simultaneous roles: (1) Responsible for building the security division for a small IT integrator and (2) leading a team of security engineers to secure TSA’s classified network.• Responsible for establishing the organization's overall cyber security direction and strategy, evaluating and developing end-to-end solutions and methodologies to enhance the company’s cyber security service offerings, and maintaining expert knowledge of the evolving federal IT landscape.• Leveraging balanced scorecard, PEST analysis and corporate planning frameworks, delivered a 4 dimensional strategic analysis including the development of a federal legislative and technological landscape study, industry/competitor matrices, internal capability SWOT analysis, and customer budget evaluation. This four-month effort produced 5 formal documents spanning over 100 pages in information for evaluation by the C-level suite.• Responsible for leading an insider threat focused mission with tasks including business requirements mapping, use case development, threat analysis development, and system administration for a classified environment within DHS. -
Security Engineering LeadFederal Deposit Insurance Corporation (Fdic) Oct 2012 - Apr 2013Washington, Dc, Us• Security engineering team lead responsible for contract staff management, technical oversight, and governance of customer's security technology portfolio.• Proposal development, project management, solution engineering, and client liaison.• Design and deployment of ArcSight 6.0c (CORR) solution, advanced ArcSight content development, shell scripting, OS hardening (CIS benchmark), and capability expansion. Advanced content included advanced persistent threat detection, rogue device discovery, and anomalous activity determination. -
Lead Information Security Architect (Contractor)U.S. Department Of Homeland Security May 2009 - May 2012Washington, Dc, Us• Selected as RSA Security Conference 2011 (world’s largest security conference) Session Speaker on SIEM implementation best practices and content evolution.• Selected as ArcSight Protect 2010 Session Speaker on best practices in SIEM architecture and deployment.• Entrusted as technical lead over staff of 10 responsible for green field enterprise scale deployment of multiple security technologies (including Identity & Access Management, Database Activity Monitoring, Operating System hardening, Strong (multi-factor) Authentication, SOA Security, Remote Access, and SIEM solutions).• Project management, client briefings, executive presentations, budgeting, and integration of security engineering portfolio into the enterprise.• Appointed as a founding member of the ArcSight Federal User Board alongside prominent leaders in the federal security community.• Responsible for developing and managing security engineering roadmap, architecture, deployment strategies, use case development, business requirements mapping, threat analysis content, client demos, FISMA compliance reporting, release/project management, interoperability, SDLC deliverables, and expansion & management of engineering team. -
Information Security ArchitectSouthern Company May 2007 - May 2009Atlanta, Ga, Us• Selected from over 3000 submissions as a Session Speaker at RSA Conference 2009 (world’s largest security conference) on advancements in SIEM architecture and correlation logic.• Appointed to Georgia Tech’s GTISC Advisory board alongside leaders in the Fortune 500 and security community. Engaged in weekly meetings with doctoral candidates to discuss research regarding industry best practices and emerging threats.• Engineered and successfully implemented a large scale enterprise SIEM delivering alerting, reporting, log aggregation, event correlation, and retention for over 2,000 systems and 30,000 users at an event rate of 1+ billion events per week.• Laddered top 10% (exceeds expectations) amongst senior team members in 3 consecutive performance reviews.• Developed executive business cases, performed product evaluation/selection, and successfully implemented an enterprise mobile encryption strategy for laptops, mobile phones, and removable media.• Architected and successfully deployed company’s first honeynet solution for < $1k.• Consulted on Critical Infrastructure Protection (CIP) security and regulatory compliance initiatives regarding high value power plants. -
Soc Security AnalystJack Henry & Associates Sep 2005 - May 2007Monett, Missouri, Us• Obtained 4 certifications within first 6 months of employment resulting in out of cycle promotion.• Lead several strategic initiatives including building mobile VPN implementation methodologies, creating client advisories, firewall maintenance and auditing, and DLP offerings.• Formulated SIEM threat logic and reporting for management based on events from over 2000 devices. -
It ConsultantAccenture Oct 2002 - Sep 2005Dublin 2, Ie• Received patent for flow design architecture, which automated the processing of customer service orders for AT&T POTS service.• Received numerous promotions for results-based achievements above and beyond job description. Laddered #1 out of recruiting class for 3 consecutive reviews.• Led team of 7 in following tasks: ensuring application integrity (14 HP UNIX servers/ 4 NT servers, top 20 critical application), monitoring application processes, release management coordination, troubleshooting, architectural reviews, and served as configuration control board meeting lead.
Brad Nelson Education Details
-
University Of Georgia - Terry College Of BusinessManagement Information Systems
Frequently Asked Questions about Brad Nelson
What company does Brad Nelson work for?
Brad Nelson works for Amazon
What is Brad Nelson's role at the current company?
Brad Nelson's current role is Senior Security Engineer at Amazon.
What is Brad Nelson's email address?
Brad Nelson's email address is hv****@****aol.com
What is Brad Nelson's direct phone number?
Brad Nelson's direct phone number is +141054*****
What schools did Brad Nelson attend?
Brad Nelson attended University Of Georgia - Terry College Of Business.
Free Chrome Extension
Find emails, phones & company data instantly
Aero Online
Your AI prospecting assistant
Select data to include:
0 records × $0.02 per record
Download 750 million emails and 100 million phone numbers
Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.
Start your free trial