Identity & Access
Entra ID, Conditional Access, MFA, Authentication Strength, FIDO2/passkeys, Windows Hello for Business, PIM, SSPR, account lifecycle and privilege review.
Security Engineer · Terre Haute, Indiana
Security Engineer with hands-on enterprise experience across identity security, endpoint defense, detection engineering, incident response, and security risk review. I turn live investigations into repeatable workflows, improve controls with measurable impact, and communicate findings clearly to technical and non-technical teams.
About
I am Ryan Lopez-Dunn, a Security Engineer based in Terre Haute, Indiana. My work centers on protecting users, devices, and business systems through strong identity posture, endpoint visibility, and disciplined response practices.
Strong production experience with Microsoft Entra ID, Conditional Access, MFA, phishing-resistant authentication, Microsoft Defender XDR, Intune, Cisco Umbrella, KQL hunting, Qualys, PCI support, and vendor risk reviews.
My approach is practical and evidence-driven: identify the risk, improve the control, document the workflow, and make the next investigation faster.
Security Skills
Entra ID, Conditional Access, MFA, Authentication Strength, FIDO2/passkeys, Windows Hello for Business, PIM, SSPR, account lifecycle and privilege review.
Microsoft Defender for Endpoint/XDR, device isolation, Live Response, ASR rules, endpoint hardening, alert validation, malware containment.
KQL Advanced Hunting, custom detections, MITRE ATT&CK mapping, honeytokens, alert tuning, investigation documentation.
Cisco Umbrella, AD identity attribution, DNS-layer visibility, policy review, suspicious network activity analysis.
HECVAT, SOC 2 interpretation, PCI/Qualys support, vulnerability findings, security exceptions, vendor risk documentation.
Windows authentication troubleshooting, browser security settings, phishing triage, user communications, Teams remote support, ticket documentation.
Experience
Projects
Endpoint Detection
Designed repeatable triage steps covering alert validation, affected device review, evidence collection, containment, escalation points, and post-incident improvement.
Threat Hunting
Hunted across DeviceProcessEvents and DeviceNetworkEvents, mapped activity to MITRE ATT&CK T1496, isolated endpoints, and created persistent detections to reduce recurrence.
DNS Security
Implemented Active Directory identity attribution into Cisco Umbrella workflows, improving investigation context and helping reduce investigation time by approximately 50%.
Vendor Risk
Evaluated fraud and identity verification vendors, reviewed security/compliance implications, and documented implementation considerations for HR/student account workflows.
Risk & Compliance
Assisted with Qualys PCI reporting, scan issue analysis, evidence collection, and security recommendations for payment-related infrastructure.
Consulting Brand
Developed a personal consulting brand concept focused on identity security, practical control maturity, and accessible security guidance.
Certifications
Earned January 2024
Current cybersecurity certification covering security operations, threats, architecture, risk, and incident response fundamentals.
Earned December 2024
IT support and endpoint troubleshooting certification covering hardware, operating systems, networking, and operational procedures.
Professional Certificate, Ivy Tech Community College — cybersecurity and information assurance credential.
Indiana State University — coursework focus includes cybercrime analysis, digital investigations, digital risk, and information security.
Microsoft Identity and Access Administrator.
CompTIA Cybersecurity Analyst.
Tools & Platforms
Resume
Download a PDF resume with experience, projects, and cybersecurity focus areas.
Contact