Security Engineer · Terre Haute, Indiana

Cybersecurity portfolio for modern endpoint and identity defense.

Security Engineer with hands-on enterprise experience across identity security, endpoint defense, detection engineering, incident response, and security risk review. I turn live investigations into repeatable workflows, improve controls with measurable impact, and communicate findings clearly to technical and non-technical teams.

About

Security-minded, operations-aware, and focused on real controls.

I am Ryan Lopez-Dunn, a Security Engineer based in Terre Haute, Indiana. My work centers on protecting users, devices, and business systems through strong identity posture, endpoint visibility, and disciplined response practices.

Strong production experience with Microsoft Entra ID, Conditional Access, MFA, phishing-resistant authentication, Microsoft Defender XDR, Intune, Cisco Umbrella, KQL hunting, Qualys, PCI support, and vendor risk reviews.

My approach is practical and evidence-driven: identify the risk, improve the control, document the workflow, and make the next investigation faster.

Security Skills

Capabilities across endpoint, identity, detection, and risk.

Identity & Access

Entra ID, Conditional Access, MFA, Authentication Strength, FIDO2/passkeys, Windows Hello for Business, PIM, SSPR, account lifecycle and privilege review.

Endpoint & XDR

Microsoft Defender for Endpoint/XDR, device isolation, Live Response, ASR rules, endpoint hardening, alert validation, malware containment.

Detection & Hunting

KQL Advanced Hunting, custom detections, MITRE ATT&CK mapping, honeytokens, alert tuning, investigation documentation.

Cloud & Network Security

Cisco Umbrella, AD identity attribution, DNS-layer visibility, policy review, suspicious network activity analysis.

Risk, Compliance & Vendors

HECVAT, SOC 2 interpretation, PCI/Qualys support, vulnerability findings, security exceptions, vendor risk documentation.

User & IT Operations

Windows authentication troubleshooting, browser security settings, phishing triage, user communications, Teams remote support, ticket documentation.

Experience

Enterprise security operations, in production.

Security Engineer

Indiana State University, Office of Information Technology · Terre Haute, IN

Aug 2025 – Present

  • Engineer and support security controls across identity, endpoint, data, device, and application layers using Microsoft Defender, Entra ID, Conditional Access, Intune, and related Microsoft security tooling.
  • Investigate and contain security incidents involving phishing, malware, cryptomining activity, suspicious network behavior, and endpoint compromise indicators using Defender XDR, Advanced Hunting/KQL, endpoint isolation, and evidence-based timelines.
  • Support phishing-resistant MFA and stronger authentication coverage with FIDO2/passkeys, Windows Hello for Business, Authentication Strength, and Conditional Access policy testing/troubleshooting.
  • Created and tuned KQL-driven detections and repeatable investigation workflows mapped to MITRE ATT&CK, improving consistency across alert triage, escalation, and post-incident documentation.
  • Implemented Active Directory identity attribution into Cisco Umbrella workflows, improving investigation context and helping reduce response time by approximately 50%.
  • Support vulnerability management, PCI evidence, Qualys reporting, vendor security reviews, HECVAT/SOC 2 interpretation, and security exception analysis for university systems.

Information Technology Security Consultant

Indiana State University · Terre Haute, IN

Nov 2024 – Aug 2025

  • Supported day-to-day security operations by triaging alerts, reviewing suspicious sign-ins, documenting incidents, and coordinating remediation steps with technical teams and end users.
  • Assisted with Microsoft Defender for Endpoint configuration, endpoint hardening, alert investigation, device isolation decisions, and security baseline implementation.
  • Helped assess identity and access risks involving MFA, Conditional Access, Windows authentication, privileged access, shared accounts, and account ownership gaps.
  • Translated technical findings into clear ticket updates, recommendations, and risk explanations for stakeholders across security, infrastructure, help desk, and business teams.

Projects

Safe summaries of practical security work.

Endpoint Detection

Defender XDR Investigation Workflow

Designed repeatable triage steps covering alert validation, affected device review, evidence collection, containment, escalation points, and post-incident improvement.

Threat Hunting

Cryptomining Response

Hunted across DeviceProcessEvents and DeviceNetworkEvents, mapped activity to MITRE ATT&CK T1496, isolated endpoints, and created persistent detections to reduce recurrence.

DNS Security

Cisco Umbrella & Active Directory Integration

Implemented Active Directory identity attribution into Cisco Umbrella workflows, improving investigation context and helping reduce investigation time by approximately 50%.

Vendor Risk

Vendor & Identity Verification Research

Evaluated fraud and identity verification vendors, reviewed security/compliance implications, and documented implementation considerations for HR/student account workflows.

Risk & Compliance

PCI & Vulnerability Support

Assisted with Qualys PCI reporting, scan issue analysis, evidence collection, and security recommendations for payment-related infrastructure.

Consulting Brand

LD Identity Security

Developed a personal consulting brand concept focused on identity security, practical control maturity, and accessible security guidance.

Certifications

Professional development and security learning.

CompTIA Security+ ce Certification badge

CompTIA Security+

Earned January 2024

Current cybersecurity certification covering security operations, threats, architecture, risk, and incident response fundamentals.

CompTIA A+ ce Certification badge

CompTIA A+

Earned December 2024

IT support and endpoint troubleshooting certification covering hardware, operating systems, networking, and operational procedures.

Cybersecurity & Information Assurance

Professional Certificate, Ivy Tech Community College — cybersecurity and information assurance credential.

B.S. Cybercriminology In Progress

Indiana State University — coursework focus includes cybercrime analysis, digital investigations, digital risk, and information security.

SC-300 In Progress

Microsoft Identity and Access Administrator.

CySA+ In Progress

CompTIA Cybersecurity Analyst.

Tools & Platforms

  • Microsoft Entra ID
  • Conditional Access
  • Authentication Strength
  • Microsoft Defender XDR
  • Defender for Endpoint
  • Defender for Office 365
  • Intune
  • KQL
  • Microsoft Sentinel exposure
  • Cisco Umbrella
  • Qualys
  • Netwrix
  • Cloudflare
  • MITRE ATT&CK
  • HECVAT
  • SOC 2
  • PCI support
  • TeamDynamix ticketing

Resume

Need the concise version?

Download a PDF resume with experience, projects, and cybersecurity focus areas.

Download Resume

Contact

Let’s connect about security engineering work.