Compare commits

..

4 Commits

Author SHA1 Message Date
3705c50040 Add tailored resumes for two AI roles
- Enterprise-AI-Automation-Engineer: hands-on IC, full-stack (Flask/Python
  + JS) build framing, balanced AI/security hybrid
- Director-of-AI-Solutions-Architecture: strategy + architecture + leadership
  tilt; surfaces solution architecture, roadmaps, build-vs-buy, RAG on vector DBs

Both 2 pages; only claims skills confirmed by the user.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 11:47:31 -05:00
ff3adfc438 Refocus resume as Principal Security Engineer; tighten to 2 pages
- Reposition summary and skills toward hands-on AI + automation (IC track);
  lead skills with AI/ML Engineering, demote leadership
- Condense summary to lead with a hard metric (47% of 3,500 weekly tickets)
- Fold NWTF role into Earlier Experience to fit 2 pages
- Add build_resume.sh: regenerate docx, render PDF via OnlyOffice x2t,
  and enforce a hard 3-page maximum
- Fix timezone off-by-one in work dates and cert/award years

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 11:19:56 -05:00
57d3796785 Update resume PDF with TopBuild role and Director tailoring
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 21:45:47 -05:00
c24f40e4f7 Add TopBuild Principal Security Engineer role; tailor for Director, Detection Engineering & Threat Hunting
- Add TopBuild Corp (Mar 2026-present): SOAR app build, user activity tracker, quarantine automation, team mentorship
- Close Confidential contractor role at 2026-03
- Reframe headline/summary toward detection engineering, threat hunting, leadership
- Add Google SecOps, CrowdStrike, ReliaQuest, Abnormal, Threat Hunting, Custom SOAR to skills

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 21:45:06 -05:00
9 changed files with 602 additions and 80 deletions

View File

@@ -0,0 +1,229 @@
{
"$schema": "https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json",
"basics": {
"name": "Phillip Tarrant",
"label": "AI Solutions Architect & Technical Leader | Enterprise AI Strategy, Cloud Architecture & Automation",
"email": "ptarrant@gmail.com",
"phone": "(706) 294-6733",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber",
"summary": "Senior technical leader with 20+ years designing and delivering enterprise AI, automation, and data architectures — translating business problems into scalable, secure AI solutions from strategy through production. Leads architecture decisions across LLM platforms (Anthropic, OpenAI, AWS Bedrock), RAG systems on vector databases, agentic workflows, cloud infrastructure (AWS, Azure), APIs, and data pipelines. Architected AI automation that auto-closed 47% of 3,500 weekly tickets with zero human touch; led a 17-person engineering/DFIR/Red Team org and mentors engineers on AI architecture best practices.",
"location": {
"city": "Morrison",
"region": "TN",
"countryCode": "US"
},
"profiles": [
{
"network": "LinkedIn",
"username": "phillip-tarrant-cyber",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber"
}
]
},
"work": [
{
"name": "TopBuild Corp",
"position": "Principal Engineer — AI Architecture & Automation",
"location": "Remote",
"startDate": "2026-03",
"summary": "Own technical direction and architecture for the enterprise AI and automation program — from strategy and solution design through production delivery.",
"highlights": [
"Architected and built a production full-stack platform (Flask/Python REST APIs, JavaScript frontend) with 20+ integrations across Microsoft 365, CrowdStrike, Google SecOps, and ReliaQuest",
"Design reusable automation frameworks and intelligent agent workflows as shared platform capabilities; advise leadership on build-vs-buy decisions for AI tools and infrastructure",
"Set architecture standards, secure-coding, and CI/CD practices; author technical documentation, system diagrams, and data-flow designs",
"Own AI development and data/logging architecture across the enterprise security program",
"Mentor engineers on AI architecture best practices and guide proofs-of-concept from concept to production"
]
},
{
"name": "Confidential (Contract)",
"position": "Senior Architecture & Automation Consultant",
"location": "Remote",
"startDate": "2025-01",
"endDate": "2026-03",
"summary": "Delivered cloud/application architecture, automation, and technical advisory for defense, fintech, and MSSP clients across multiple environments.",
"highlights": [
"Designed secure cloud and application architectures and led architecture reviews across multiple enterprise tenants",
"Built automation and API-driven integrations that streamlined vulnerability management and reporting for one of the largest US fintech clients",
"Advised on compliance and secure-by-design practices (NIST 800-53, PCI-DSS, HIPAA, GDPR)"
]
},
{
"name": "Compuquip Cybersecurity",
"position": "Director of Automation — prior: SOC Director → SOC Technical Manager",
"location": "Tampa/Doral, Florida",
"startDate": "2021-01",
"endDate": "2024-12",
"summary": "Set and led AI technical strategy and architecture for a regulated MSSP — owning all AI development from discovery through production and adoption.",
"highlights": [
"Architected AI-powered automation (Python, AWS Lambda, LLMs) that processed 3,500 tickets weekly and auto-closed 47% with no human involvement",
"Designed RAG systems on vector databases, LLM triage pipelines, and agentic workflows as reusable platform capabilities that accelerated every downstream initiative",
"Built against LLM APIs (Anthropic, OpenAI) and AWS Bedrock; established AI governance — model evaluation, output validation, guardrails, and security controls",
"Translated business requirements into technical roadmaps with business leaders and led build-vs-buy decisions for AI tooling",
"Grew the client base from 16 to 52 and improved margin from 18% to 52% while leading a 17-person engineering, Red Team, and DFIR org"
]
},
{
"name": "Travel Syndication Technology (TST)",
"position": "Sr. Security Architect",
"location": "Alpharetta, Georgia",
"startDate": "2020-04",
"endDate": "2021-01",
"summary": "Owned enterprise security architecture, automation tooling, and compliance across the organization.",
"highlights": [
"Owned security architecture and built custom automation and detection tooling",
"Steered the organization through PCI and NIST 800-series audits; saved $10,000+ through vendor negotiations"
]
},
{
"name": "Intercontinental Exchange",
"position": "Cyber Security Engineer → Senior Cyber Security Engineer",
"location": "Marietta, Georgia",
"startDate": "2018-08",
"endDate": "2020-04",
"summary": "Incident Response/Digital Forensics lead, promoted to the Architecture and Automation Team.",
"highlights": [
"Designed security data pipelines and automated triage tooling on the Architecture & Automation team",
"Led critical multi-server incident investigations across three teams and mentored junior analysts"
]
},
{
"name": "Earlier Experience",
"position": "IT Leadership & Systems Administration Roles",
"startDate": "1999-01",
"endDate": "2018-08",
"summary": "Progressive IT and technical leadership roles, including Technical Services Manager at the National Wild Turkey Federation — led 8 technicians and developers supporting 300+ staff, saved $50,000+/year migrating 3rd-party tools in-house, and owned web/network/application architecture."
}
],
"education": [
{
"institution": "Virginia College",
"area": "Network Administration",
"studyType": "Associate",
"startDate": "2014",
"endDate": "2016",
"score": "4.0",
"courses": []
}
],
"certificates": [
{
"name": "GWAPT - Web Application Penetration Tester",
"issuer": "GIAC",
"date": "2020-01-01"
},
{
"name": "GCFA - Forensic Analyst",
"issuer": "GIAC",
"date": "2019-01-01"
},
{
"name": "GCIH - Incident Handler",
"issuer": "GIAC",
"date": "2018-01-01"
}
],
"awards": [
{
"title": "Lethal Forensicator Coin Winner",
"awarder": "SANS/GIAC",
"date": "2019-01-01",
"summary": "SANS Challenge Coin for excellence in digital forensics"
}
],
"skills": [
{
"name": "AI/ML Architecture & Engineering",
"level": "Expert",
"keywords": [
"AI Solution Architecture",
"LLM Platforms (Anthropic, OpenAI, AWS Bedrock)",
"RAG Systems",
"Vector Databases",
"Agentic AI & Agent Workflows",
"Prompt Engineering",
"AI Guardrails & Governance",
"Model Evaluation"
]
},
{
"name": "Cloud & Data Architecture",
"level": "Expert",
"keywords": [
"AWS (Bedrock, Lambda)",
"Azure",
"Oracle Cloud",
"Serverless",
"Data Pipelines",
"SQL / Databases",
"System Integration",
"Cloud-Native Deployment"
]
},
{
"name": "Architecture & Technical Strategy",
"level": "Expert",
"keywords": [
"Solution Architecture",
"Technical Roadmaps",
"Build-vs-Buy Evaluation",
"Architecture Reviews",
"System & Data-Flow Design",
"Technical Documentation",
"Proof-of-Concept to Production"
]
},
{
"name": "Software Engineering",
"level": "Advanced",
"keywords": [
"Python",
"Flask",
"REST API Design",
"JavaScript",
"CI/CD",
"Docker",
"Kubernetes",
"Git",
"PowerShell",
"Bash"
]
},
{
"name": "Security & Compliance",
"level": "Expert",
"keywords": [
"Enterprise Security",
"Secure Architecture",
"Authentication & Access Control",
"SIEM/SOAR",
"NIST 800-53",
"PCI-DSS",
"HIPAA",
"GDPR"
]
},
{
"name": "Leadership & Collaboration",
"level": "Expert",
"keywords": [
"Technical Leadership",
"Team Leadership (17+ reports)",
"Engineer & Architect Mentorship",
"Cross-Functional Partnership",
"Stakeholder Management"
]
}
],
"languages": [
{
"language": "English",
"fluency": "Native speaker"
}
],
"meta": {
"theme": "elegant",
"version": "v1.0.0",
"lastModified": "2026-07-06"
}
}

View File

@@ -0,0 +1,225 @@
{
"$schema": "https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json",
"basics": {
"name": "Phillip Tarrant",
"label": "Principal AI Engineer | Enterprise Automation & Applied AI | Security-Grade Reliability",
"email": "ptarrant@gmail.com",
"phone": "(706) 294-6733",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber",
"summary": "Principal engineer with 20+ years shipping production software and applied-AI automation end to end — Flask/Python backends, REST APIs and integrations, JavaScript frontends, and cloud-native CI/CD. Partners directly with business and technical stakeholders to turn manual processes into scalable AI solutions: built agentic LLM automation that auto-closed 47% of 3,500 weekly tickets with zero human touch. Designs reusable automation frameworks, RAG platforms, and intelligent agent workflows — with enterprise security, authentication, and reliability built in from the start.",
"location": {
"city": "Morrison",
"region": "TN",
"countryCode": "US"
},
"profiles": [
{
"network": "LinkedIn",
"username": "phillip-tarrant-cyber",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber"
}
]
},
"work": [
{
"name": "TopBuild Corp",
"position": "Principal Engineer — AI Automation & Security",
"location": "Remote",
"startDate": "2026-03",
"summary": "Lead engineer owning AI development, automation platforms, and data architecture for the enterprise program; design and ship production applications and set technical direction for the team.",
"highlights": [
"Designed and built a production full-stack web application end to end — Flask/Python REST API backend with a JavaScript frontend — delivering 20+ automated actions and integrations across Microsoft 365, CrowdStrike, Google SecOps, and ReliaQuest",
"Architected reusable automation frameworks and intelligent agent workflows as shared platform capabilities that unify data, reporting, and response across enterprise systems",
"Built a cross-source telemetry correlation tool that accelerates investigation and triage for engineers and business stakeholders",
"Own enterprise automation, AI development, and data/logging architecture; set secure-coding, CI/CD, and responsible-AI usage standards",
"Mentor engineers and advise leadership on engineering best practices and AI investment"
]
},
{
"name": "Confidential (Contract)",
"position": "Senior Engineering & Automation Consultant",
"location": "Remote",
"startDate": "2025-01",
"endDate": "2026-03",
"summary": "Delivered hands-on engineering, automation, and secure architecture for defense, fintech, and MSSP clients across multiple cloud environments.",
"highlights": [
"Built automation and API integrations that streamlined vulnerability management and reporting workflows for one of the largest US fintech clients",
"Designed secure application and cloud architectures across multiple enterprise tenants",
"Advised on compliance and secure-by-design practices (NIST 800-53, PCI-DSS, HIPAA, GDPR)"
]
},
{
"name": "Compuquip Cybersecurity",
"position": "Director of Automation (Technical IC) — prior: SOC Technical Manager → SOC Director",
"location": "Tampa/Doral, Florida",
"startDate": "2021-01",
"endDate": "2024-12",
"summary": "Hands-on technical leader owning all AI development and automation for a secure, regulated MSSP — from solution discovery through development, deployment, and adoption.",
"highlights": [
"Owned all AI development — designed and shipped AI-powered automation in Python, AWS Lambda, and LLMs that processed 3,500 tickets weekly and auto-closed 47% with no human involvement",
"Built agentic AI workflows, RAG-based knowledge systems, and LLM triage pipelines as reusable platform capabilities that accelerated every downstream initiative",
"Designed prompt-engineering frameworks and AI guardrails ensuring safe, accurate, auditable outputs in production",
"Established AI governance — model evaluation, output validation, and security controls — and drove AI adoption through training and knowledge sharing across teams",
"Partnered with business leaders to identify automation opportunities and measure impact; grew the client base from 16 to 52 and margin from 18% to 52% while leading a 17-person engineering, Red Team, and DFIR org"
]
},
{
"name": "Travel Syndication Technology (TST)",
"position": "Sr. Security Architect",
"location": "Alpharetta, Georgia",
"startDate": "2020-04",
"endDate": "2021-01",
"summary": "Owned security architecture, automation tooling, and compliance across the organization.",
"highlights": [
"Built custom tooling and automation for infrastructure testing and detection engineering",
"Steered the organization through PCI and NIST 800-series audits; saved $10,000+ through vendor negotiations"
]
},
{
"name": "Intercontinental Exchange",
"position": "Cyber Security Engineer → Senior Cyber Security Engineer",
"location": "Marietta, Georgia",
"startDate": "2018-08",
"endDate": "2020-04",
"summary": "Incident Response/Digital Forensics lead, promoted to the Architecture and Automation Team.",
"highlights": [
"Designed security data pipelines and automated SOC triage tooling on the Architecture & Automation team",
"Led critical multi-server incident investigations across three teams and mentored junior analysts"
]
},
{
"name": "Earlier Experience",
"position": "IT Leadership & Systems Administration Roles",
"startDate": "1999-01",
"endDate": "2018-08",
"summary": "Progressive IT and technical leadership roles, including Technical Services Manager at the National Wild Turkey Federation — led 8 technicians and developers supporting 300+ staff, saved $50,000+/year migrating 3rd-party tools in-house, and owned web/network/application security."
}
],
"education": [
{
"institution": "Virginia College",
"area": "Network Administration",
"studyType": "Associate",
"startDate": "2014",
"endDate": "2016",
"score": "4.0",
"courses": []
}
],
"certificates": [
{
"name": "GWAPT - Web Application Penetration Tester",
"issuer": "GIAC",
"date": "2020-01-01"
},
{
"name": "GCFA - Forensic Analyst",
"issuer": "GIAC",
"date": "2019-01-01"
},
{
"name": "GCIH - Incident Handler",
"issuer": "GIAC",
"date": "2018-01-01"
}
],
"awards": [
{
"title": "Lethal Forensicator Coin Winner",
"awarder": "SANS/GIAC",
"date": "2019-01-01",
"summary": "SANS Challenge Coin for excellence in digital forensics"
}
],
"skills": [
{
"name": "AI/ML Engineering & Automation",
"level": "Expert",
"keywords": [
"AI Application Development",
"Agentic AI & Agent Workflows",
"LLM Integration",
"RAG Systems",
"Prompt Engineering",
"AI Guardrails & Governance",
"Model Evaluation",
"AWS Bedrock",
"AWS Lambda",
"Reusable Automation Frameworks"
]
},
{
"name": "Software Engineering & Full-Stack",
"level": "Expert",
"keywords": [
"Python",
"Flask",
"REST API Design",
"JavaScript",
"HTML/CSS",
"Frontend Development",
"System Integration",
"CI/CD",
"Docker",
"Kubernetes",
"Git",
"PowerShell",
"Bash"
]
},
{
"name": "Cloud, Data & Infrastructure",
"level": "Advanced",
"keywords": [
"AWS (Lambda, Bedrock)",
"Azure",
"Oracle Cloud",
"Serverless",
"Cloud-Native Deployment",
"Data Pipelines",
"Linux/UNIX",
"Windows Server",
"Active Directory"
]
},
{
"name": "Enterprise Security & Reliability",
"level": "Expert",
"keywords": [
"Enterprise Security",
"Authentication & Access Control",
"Secure Architecture",
"SIEM/SOAR (Sentinel, Splunk, Google SecOps)",
"Detection Engineering",
"DFIR",
"NIST 800-53",
"PCI-DSS",
"HIPAA",
"GDPR"
]
},
{
"name": "Leadership & Collaboration",
"level": "Expert",
"keywords": [
"Technical Leadership",
"Engineer Mentorship",
"Cross-Functional Partnership",
"Stakeholder Management",
"AI Adoption & Enablement",
"Team Leadership (17+ reports)"
]
}
],
"languages": [
{
"language": "English",
"fluency": "Native speaker"
}
],
"meta": {
"theme": "elegant",
"version": "v1.0.0",
"lastModified": "2026-07-06"
}
}

Binary file not shown.

Binary file not shown.

58
build_resume.sh Executable file
View File

@@ -0,0 +1,58 @@
#!/usr/bin/env bash
# Build the resume: regenerate the .docx from resume.json, render a .pdf via
# OnlyOffice's headless x2t converter, and ENFORCE a hard 3-page maximum.
# Exits non-zero (and deletes the stale PDF) if the render exceeds MAX_PAGES.
set -euo pipefail
cd "$(dirname "$0")"
MAX_PAGES=3
DOCX="Phillip_Tarrant_Resume_$(date +%Y).docx"
PDF="Phillip_Tarrant_Resume_$(date +%Y).pdf"
OO=/opt/onlyoffice/desktopeditors
X2T="$OO/converter/x2t"
# Font cache generated by the OnlyOffice desktop app (x2t needs it; the bundled
# converter ships without one and crashes otherwise).
FONTS="$HOME/.local/share/onlyoffice/desktopeditors/data/fonts"
# --- 1. Generate the .docx from resume.json ---
node generate_resume.js
# --- 2. Render .docx -> .pdf via x2t ---
if [[ ! -x "$X2T" ]]; then
echo "ERROR: OnlyOffice x2t not found at $X2T — cannot render/verify pages." >&2
exit 3
fi
if [[ ! -f "$FONTS/AllFonts.js" ]]; then
echo "ERROR: OnlyOffice font cache missing at $FONTS/AllFonts.js." >&2
echo " Open the OnlyOffice desktop app once to generate it, then re-run." >&2
exit 3
fi
TMP="$(mktemp -d)"
trap 'rm -rf "$TMP"' EXIT
cat > "$TMP/conv.xml" <<XML
<?xml version="1.0" encoding="utf-8"?>
<TaskQueueDataConvert xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema">
<m_sFileFrom>$PWD/$DOCX</m_sFileFrom>
<m_sFileTo>$PWD/$PDF</m_sFileTo>
<m_nFormatTo>513</m_nFormatTo>
<m_sFontDir>$FONTS</m_sFontDir>
<m_sAllFontsPath>$FONTS/AllFonts.js</m_sAllFontsPath>
<m_sThemeDir>$OO/editors/sdkjs/slide/themes</m_sThemeDir>
<m_sTempDir>$TMP</m_sTempDir>
</TaskQueueDataConvert>
XML
( cd "$OO/converter" && LD_LIBRARY_PATH="$OO/converter:$OO" "$X2T" "$TMP/conv.xml" )
# --- 3. Enforce the page limit ---
PAGES="$(pdfinfo "$PDF" | awk '/^Pages:/ {print $2}')"
echo "Rendered $PDF$PAGES page(s)."
if (( PAGES > MAX_PAGES )); then
echo "ERROR: resume is $PAGES pages, exceeds the $MAX_PAGES-page limit. Trim content." >&2
rm -f "$PDF"
exit 1
fi
echo "OK: within the $MAX_PAGES-page limit. Built $DOCX and $PDF."

View File

@@ -1,7 +1,7 @@
const fs = require('fs'); const fs = require('fs');
const { const {
Document, Packer, Paragraph, TextRun, AlignmentType, Document, Packer, Paragraph, TextRun, AlignmentType,
HeadingLevel, LevelFormat, ExternalHyperlink, BorderStyle HeadingLevel, LevelFormat, ExternalHyperlink, BorderStyle, PageBreak
} = require('docx'); } = require('docx');
// ============================================ // ============================================
@@ -21,7 +21,7 @@ const resumeData = JSON.parse(fs.readFileSync(INPUT_FILE, 'utf8'));
function createBulletParagraph(text, reference) { function createBulletParagraph(text, reference) {
return new Paragraph({ return new Paragraph({
numbering: { reference: reference, level: 0 }, numbering: { reference: reference, level: 0 },
spacing: { after: 60 }, spacing: { after: 40 },
children: [new TextRun({ text: text, size: 22, font: "Arial" })] children: [new TextRun({ text: text, size: 22, font: "Arial" })]
}); });
} }
@@ -29,7 +29,9 @@ function createBulletParagraph(text, reference) {
// Format date from YYYY-MM to "Mon YYYY" // Format date from YYYY-MM to "Mon YYYY"
function formatDate(dateStr) { function formatDate(dateStr) {
if (!dateStr) return ''; if (!dateStr) return '';
const date = new Date(dateStr + '-01'); // Build from explicit parts so the date is local-time (avoids UTC-parse month shift)
const [year, month] = dateStr.split('-').map(Number);
const date = new Date(year, (month || 1) - 1, 1);
return date.toLocaleDateString('en-US', { month: 'short', year: 'numeric' }); return date.toLocaleDateString('en-US', { month: 'short', year: 'numeric' });
} }
@@ -109,7 +111,7 @@ children.push(new Paragraph({
// --- CAREER EXPERIENCE SECTION --- // --- CAREER EXPERIENCE SECTION ---
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { before: 120, after: 200 }, spacing: { before: 80, after: 120 },
children: [new TextRun({ children: [new TextRun({
text: "Career Experience", text: "Career Experience",
bold: true, bold: true,
@@ -128,7 +130,7 @@ resumeData.work.forEach((job, index) => {
// Job title and company // Job title and company
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { before: 160, after: 60 }, spacing: { before: 120, after: 40 },
children: [ children: [
new TextRun({ new TextRun({
text: job.position, text: job.position,
@@ -153,7 +155,7 @@ resumeData.work.forEach((job, index) => {
// Job summary // Job summary
if (job.summary) { if (job.summary) {
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { after: 100 }, spacing: { after: 60 },
children: [new TextRun({ children: [new TextRun({
text: job.summary, text: job.summary,
size: 22, size: 22,
@@ -170,12 +172,12 @@ resumeData.work.forEach((job, index) => {
} }
// Spacing after each job // Spacing after each job
children.push(new Paragraph({ spacing: { after: 120 }, children: [] })); children.push(new Paragraph({ spacing: { after: 60 }, children: [] }));
}); });
// --- EDUCATION, CERTIFICATIONS, AND AWARDS SECTION --- // --- EDUCATION, CERTIFICATIONS, AND AWARDS SECTION ---
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { before: 200, after: 160 }, spacing: { before: 120, after: 100 },
children: [new TextRun({ children: [new TextRun({
text: "Education, Certifications, and Awards", text: "Education, Certifications, and Awards",
bold: true, bold: true,
@@ -187,7 +189,7 @@ children.push(new Paragraph({
// Certificates // Certificates
if (resumeData.certificates) { if (resumeData.certificates) {
resumeData.certificates.forEach(cert => { resumeData.certificates.forEach(cert => {
const year = cert.date ? new Date(cert.date).getFullYear() : ''; const year = cert.date ? cert.date.slice(0, 4) : '';
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { after: 60 }, spacing: { after: 60 },
children: [ children: [
@@ -215,7 +217,7 @@ if (resumeData.certificates) {
// Awards // Awards
if (resumeData.awards) { if (resumeData.awards) {
resumeData.awards.forEach(award => { resumeData.awards.forEach(award => {
const year = award.date ? new Date(award.date).getFullYear() : ''; const year = award.date ? award.date.slice(0, 4) : '';
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { after: 60 }, spacing: { after: 60 },
children: [ children: [
@@ -294,7 +296,7 @@ if (resumeData.education) {
// --- TECHNICAL SKILLS SECTION --- // --- TECHNICAL SKILLS SECTION ---
children.push(new Paragraph({ children.push(new Paragraph({
spacing: { before: 200, after: 160 }, spacing: { before: 120, after: 100 },
children: [new TextRun({ children: [new TextRun({
text: "Technical Skills", text: "Technical Skills",
bold: true, bold: true,

View File

@@ -2,11 +2,11 @@
"$schema": "https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json", "$schema": "https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json",
"basics": { "basics": {
"name": "Phillip Tarrant", "name": "Phillip Tarrant",
"label": "Cybersecurity Director | AI & Automation Leader", "label": "Principal Security Engineer | Security Automation & AI Engineering",
"email": "ptarrant@gmail.com", "email": "ptarrant@gmail.com",
"phone": "(706) 294-6733", "phone": "(706) 294-6733",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber", "url": "https://www.linkedin.com/in/phillip-tarrant-cyber",
"summary": "Accomplished and analytical professional with 20+ years of experience in cybersecurity, server infrastructures, and data-center operations. Proven expertise in Cyber Operations, digital forensics, penetration testing, information system management, malware reversing, threat detection, and threat hunting with and without AI integration. Proactive leader with a proven record of managing multiple large teams and leading the charge to complete project goals. Managed MSSP operations for 50+ large business clients encompassing over 150,000 assets and 1 million+ users. Experienced AI leader with expertise in prompt engineering, LLM integration, AI security and guardrails, and deploying AI solutions in secure, regulated environments.", "summary": "Principal-level security engineer with 20+ years building detection and AI-driven automation across MSSP and enterprise environments. Ships production tooling end to end — custom SOAR platforms and LLM triage pipelines; built automation that closed 47% of 3,500 weekly tickets with no human touch. Deep DFIR and threat-hunting roots, now focused on applied AI security.",
"location": { "location": {
"city": "Morrison", "city": "Morrison",
"region": "TN", "region": "TN",
@@ -21,17 +21,32 @@
] ]
}, },
"work": [ "work": [
{
"name": "TopBuild Corp",
"position": "Principal Security Engineer",
"location": "Remote",
"startDate": "2026-03",
"summary": "Lead engineer owning security automation, AI development, and SIEM/logging strategy for the enterprise security program; build detection engineering and threat hunting tooling while setting technical direction for the team.",
"highlights": [
"Architected and built a custom SOAR web application from the ground up — 20+ automated response actions unifying detection, reporting, and response across Microsoft 365, CrowdStrike, Google SecOps, and ReliaQuest",
"Engineered a 'user activity tracker' that correlates enterprise telemetry to accelerate incident triage and proactive threat hunting",
"Automated end-to-end quarantine email release across Microsoft 365 and Abnormal, cutting analyst response time on phishing and malicious mail",
"Own enterprise security automation, AI development, and SIEM/logging architecture across the security program",
"Set secure-coding and cybersecurity-forward AI usage standards; mentor engineers and advise leadership on detection engineering investments"
]
},
{ {
"name": "Confidential", "name": "Confidential",
"position": "Senior Information Security Consultant", "position": "Senior Information Security Consultant",
"location": "Remote", "location": "Remote",
"startDate": "2025-01", "startDate": "2025-01",
"summary": "Contract consulting role providing cybersecurity leadership and technical expertise.", "endDate": "2026-03",
"summary": "Contract consulting role delivering hands-on security engineering, SOC operations, and vulnerability management for defense, fintech, and MSSP clients.",
"highlights": [ "highlights": [
"Managing SOC operations for US Defense Space market supplier across multiple Microsoft tenants", "Ran SOC operations for a US Defense Space market supplier across multiple Microsoft tenants",
"Managed Vulnerability Management Program for one of the largest fintech clients in the US using Qualys", "Managed the Vulnerability Management Program for one of the largest US fintech clients using Qualys",
"Director role at MSSP restructuring SOC flow and training SOC staff", "Restructured SOC workflow and trained analysts at an MSSP",
"Designing secure architectures and providing compliance guidance (HIPAA, PCI-DSS, GDPR, NIST 800-53)" "Designed secure architectures and provided compliance guidance (HIPAA, PCI-DSS, GDPR, NIST 800-53)"
] ]
}, },
{ {
@@ -40,15 +55,14 @@
"location": "Tampa/Doral, Florida", "location": "Tampa/Doral, Florida",
"startDate": "2021-01", "startDate": "2021-01",
"endDate": "2024-12", "endDate": "2024-12",
"summary": "Progressive leadership roles managing SOC operations, Red Team, AI development, and security automation for MSSP clients.", "summary": "Progressive technical and leadership roles culminating in Director of Automation, owning AI development and security automation for MSSP clients.",
"highlights": [ "highlights": [
"Grew SOC client base from 16 to 52 customers; improved profitability from 18% to 52% margin", "Built automation handling 3,500 tickets weekly, closing 47% without human involvement",
"Built automation handling 3,500 tickets weekly with 47% closed without human involvement", "Owned all AI development in a secure MSSP environment — AI-powered security automation using Python, AWS Lambda, LLMs, and SOAR platforms",
"Managed team of 17 direct reports across SOC, Red Team, and DFIR engagements", "Designed prompt engineering frameworks and AI guardrails ensuring safe, accurate, auditable AI outputs in production security workflows",
"Oversaw all AI development in a secure MSSP environment, building AI-powered security automation using Python, AWS Lambda, LLMs, and SOAR platforms",
"Designed and implemented prompt engineering frameworks and AI guardrails to ensure safe, accurate, and auditable AI outputs in production security workflows",
"Built RAG-based knowledge systems and LLM-driven triage pipelines for automated threat classification and analyst augmentation", "Built RAG-based knowledge systems and LLM-driven triage pipelines for automated threat classification and analyst augmentation",
"Established AI governance policies including model evaluation, output validation, and security controls for LLM deployments" "Established AI governance including model evaluation, output validation, and security controls for LLM deployments",
"Grew SOC client base from 16 to 52 customers and improved margin from 18% to 52% while leading a 17-person SOC, Red Team, and DFIR org"
] ]
}, },
{ {
@@ -57,10 +71,10 @@
"location": "Alpharetta, Georgia", "location": "Alpharetta, Georgia",
"startDate": "2020-04", "startDate": "2020-04",
"endDate": "2021-01", "endDate": "2021-01",
"summary": "Responsible for security architecture, training programs, and compliance across the organization.", "summary": "Owned security architecture, detection tooling, and compliance across the organization.",
"highlights": [ "highlights": [
"Steered organization through PCI and NIST 800 series audits", "Steered the organization through PCI and NIST 800 series audits",
"Created custom tools to automate attacks against infrastructure and design detections", "Built custom tools to automate attacks against infrastructure and engineer matching detections",
"Saved $10,000+ through effective vendor/supplier negotiations" "Saved $10,000+ through effective vendor/supplier negotiations"
] ]
}, },
@@ -70,32 +84,19 @@
"location": "Marietta, Georgia", "location": "Marietta, Georgia",
"startDate": "2018-08", "startDate": "2018-08",
"endDate": "2020-04", "endDate": "2020-04",
"summary": "Incident Response/Digital Forensics lead, promoted to Architecture and Automation Team.", "summary": "Incident Response/Digital Forensics lead, promoted to the Architecture and Automation Team.",
"highlights": [ "highlights": [
"Lead investigator on critical incidents; managed multi-server compromise investigations across three teams", "Lead investigator on critical incidents; ran multi-server compromise investigations across three teams",
"Led Malware Analysis in sandboxed environments; mentored junior analysts", "Led malware analysis in sandboxed environments and mentored junior analysts",
"Designed security data flow pipelines and automated SOC triage tools" "Designed security data flow pipelines and automated SOC triage tooling"
]
},
{
"name": "The National Wild Turkey Federation",
"position": "Technical Services Manager",
"location": "Edgefield, South Carolina",
"startDate": "2015-10",
"endDate": "2018-08",
"summary": "Managed IT team supporting 300+ staff members with focus on infrastructure and security.",
"highlights": [
"Managed team of 8 technicians and developers supporting 300+ staff members",
"Migrated 3rd party tools to in-house solutions saving $50,000+ yearly",
"Managed security of entire web presence including network and application code"
] ]
}, },
{ {
"name": "Earlier Experience", "name": "Earlier Experience",
"position": "IT & Systems Administration Roles", "position": "IT Leadership & Systems Administration Roles",
"startDate": "1999-01", "startDate": "1999-01",
"endDate": "2015-01", "endDate": "2018-08",
"summary": "Progressive IT roles including Network/Server Administrator at NWTF, System Administrator at Morgan Thermal Ceramics, IT Coordinator at Briarwood Academy, and Technical Support at Sitel Group." "summary": "Progressive IT and technical leadership roles, including Technical Services Manager at the National Wild Turkey Federation — led 8 technicians and developers supporting 300+ staff, saved $50,000+/year migrating 3rd-party tools in-house, and owned web/network/application security. Earlier: Network/Server Administrator at NWTF, System Administrator at Morgan Thermal Ceramics, IT Coordinator at Briarwood Academy, and Technical Support at Sitel Group."
} }
], ],
"education": [ "education": [
@@ -135,6 +136,23 @@
} }
], ],
"skills": [ "skills": [
{
"name": "AI/ML Engineering & Automation",
"level": "Expert",
"keywords": [
"LLM Integration",
"RAG Systems",
"Prompt Engineering",
"Agentic AI",
"AI Security & Guardrails",
"AI Governance",
"Model Evaluation",
"AWS Bedrock",
"AWS Lambda",
"Python Automation",
"Custom SOAR Development"
]
},
{ {
"name": "Security Operations, SIEM & SOAR", "name": "Security Operations, SIEM & SOAR",
"level": "Expert", "level": "Expert",
@@ -142,6 +160,9 @@
"Splunk", "Splunk",
"ELK Stack", "ELK Stack",
"Microsoft Sentinel/Defender", "Microsoft Sentinel/Defender",
"Google SecOps (Chronicle)",
"CrowdStrike",
"ReliaQuest",
"Sentinel One", "Sentinel One",
"Rapid7 IDR", "Rapid7 IDR",
"Swimlane", "Swimlane",
@@ -151,51 +172,38 @@
] ]
}, },
{ {
"name": "Threat Detection, DFIR & Red Team", "name": "Detection Engineering, DFIR & Red Team",
"level": "Expert", "level": "Expert",
"keywords": [ "keywords": [
"Detection Engineering",
"Threat Hunting",
"Malware Analysis",
"Incident Response",
"Volatility",
"Darktrace", "Darktrace",
"Tanium", "Tanium",
"Vectra", "Vectra",
"FireEye", "FireEye",
"Volatility", "Abnormal Security",
"Malware Analysis",
"Incident Response",
"Detection Engineering",
"Metasploit", "Metasploit",
"Purple Team" "Purple Team"
] ]
}, },
{
"name": "AI/ML & Automation",
"level": "Expert",
"keywords": [
"AWS Bedrock",
"LLMs",
"RAG",
"Prompt Engineering",
"AI Security & Guardrails",
"AI Governance",
"Agentic AI",
"Model Evaluation",
"Python Automation"
]
},
{ {
"name": "Cloud, Infrastructure & Programming", "name": "Cloud, Infrastructure & Programming",
"level": "Advanced", "level": "Advanced",
"keywords": [ "keywords": [
"Python",
"PowerShell",
"Bash",
"AWS", "AWS",
"Azure", "Azure",
"Oracle Cloud", "Oracle Cloud",
"Windows Server",
"Linux/UNIX",
"Active Directory",
"Docker", "Docker",
"Kubernetes", "Kubernetes",
"Python", "Windows Server",
"PowerShell", "Linux/UNIX",
"Bash" "Active Directory"
] ]
}, },
{ {
@@ -210,14 +218,14 @@
] ]
}, },
{ {
"name": "Leadership & Management", "name": "Leadership & Mentorship",
"level": "Expert", "level": "Expert",
"keywords": [ "keywords": [
"Team Leadership (17+ reports)", "Technical Leadership",
"Engineer Mentorship",
"MSSP Operations", "MSSP Operations",
"Budget Management", "Team Leadership (17+ reports)",
"Vendor Negotiations", "Vendor Negotiations"
"Training & Mentorship"
] ]
} }
], ],
@@ -230,6 +238,6 @@
"meta": { "meta": {
"theme": "elegant", "theme": "elegant",
"version": "v1.0.0", "version": "v1.0.0",
"lastModified": "2025-12-08" "lastModified": "2026-07-06"
} }
} }