Files
resume/resume.json
Phillip Tarrant c24f40e4f7 Add TopBuild Principal Security Engineer role; tailor for Director, Detection Engineering & Threat Hunting
- Add TopBuild Corp (Mar 2026-present): SOAR app build, user activity tracker, quarantine automation, team mentorship
- Close Confidential contractor role at 2026-03
- Reframe headline/summary toward detection engineering, threat hunting, leadership
- Add Google SecOps, CrowdStrike, ReliaQuest, Abnormal, Threat Hunting, Custom SOAR to skills

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 21:45:06 -05:00

257 lines
9.8 KiB
JSON

{
"$schema": "https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json",
"basics": {
"name": "Phillip Tarrant",
"label": "Director, Detection Engineering & Threat Hunting | Security Automation & AI Leader",
"email": "ptarrant@gmail.com",
"phone": "(706) 294-6733",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber",
"summary": "Security leader with 20+ years of experience building and leading detection engineering, threat hunting, and SOC operations across MSSP and enterprise environments. Proven director-level track record managing multiple large teams, restructuring SOC workflows, and scaling detection and response programs. Deep technical foundation in digital forensics, malware reversing, incident response, and threat hunting with and without AI integration. Led MSSP operations for 50+ business clients encompassing 150,000+ assets and 1 million+ users. Experienced AI and automation leader with expertise in SOAR engineering, prompt engineering, LLM integration, AI security and guardrails, and deploying AI-driven detection solutions in secure, regulated environments.",
"location": {
"city": "Morrison",
"region": "TN",
"countryCode": "US"
},
"profiles": [
{
"network": "LinkedIn",
"username": "phillip-tarrant-cyber",
"url": "https://www.linkedin.com/in/phillip-tarrant-cyber"
}
]
},
"work": [
{
"name": "TopBuild Corp",
"position": "Principal Security Engineer",
"location": "Remote",
"startDate": "2026-03",
"summary": "Lead engineer owning security automation, AI development, and SIEM/logging strategy for the enterprise security program; drive detection engineering, threat hunting tooling, and analyst enablement while advising leadership on strategic security investments.",
"highlights": [
"Own enterprise security automation, AI development, and SIEM/logging strategy across the security program",
"Architected and built a custom SOAR web application from the ground up — 20+ automated response actions unifying detection, reporting, and response across Microsoft 365, CrowdStrike, Google SecOps, and ReliaQuest data sources",
"Engineered a 'user activity tracker' that accelerates incident triage and proactive threat hunting across enterprise telemetry",
"Automated end-to-end quarantine email release across Microsoft 365 and Abnormal, cutting analyst response time on phishing and malicious mail",
"Mentor 2 junior engineers on a lean 5-person security team in secure coding and cybersecurity-forward AI usage; advise senior leadership on strategic detection engineering and security investments"
]
},
{
"name": "Confidential",
"position": "Senior Information Security Consultant",
"location": "Remote",
"startDate": "2025-01",
"endDate": "2026-03",
"summary": "Contract consulting role providing cybersecurity leadership and technical expertise.",
"highlights": [
"Managing SOC operations for US Defense Space market supplier across multiple Microsoft tenants",
"Managed Vulnerability Management Program for one of the largest fintech clients in the US using Qualys",
"Director role at MSSP restructuring SOC flow and training SOC staff",
"Designing secure architectures and providing compliance guidance (HIPAA, PCI-DSS, GDPR, NIST 800-53)"
]
},
{
"name": "Compuquip Cybersecurity",
"position": "SOC Technical Manager → SOC Director → Director of Automation",
"location": "Tampa/Doral, Florida",
"startDate": "2021-01",
"endDate": "2024-12",
"summary": "Progressive leadership roles managing SOC operations, Red Team, AI development, and security automation for MSSP clients.",
"highlights": [
"Grew SOC client base from 16 to 52 customers; improved profitability from 18% to 52% margin",
"Built automation handling 3,500 tickets weekly with 47% closed without human involvement",
"Managed team of 17 direct reports across SOC, Red Team, and DFIR engagements",
"Oversaw all AI development in a secure MSSP environment, building AI-powered security automation using Python, AWS Lambda, LLMs, and SOAR platforms",
"Designed and implemented prompt engineering frameworks and AI guardrails to ensure safe, accurate, and auditable AI outputs in production security workflows",
"Built RAG-based knowledge systems and LLM-driven triage pipelines for automated threat classification and analyst augmentation",
"Established AI governance policies including model evaluation, output validation, and security controls for LLM deployments"
]
},
{
"name": "Travel Syndication Technology (TST)",
"position": "Sr. Cyber Security Architect",
"location": "Alpharetta, Georgia",
"startDate": "2020-04",
"endDate": "2021-01",
"summary": "Responsible for security architecture, training programs, and compliance across the organization.",
"highlights": [
"Steered organization through PCI and NIST 800 series audits",
"Created custom tools to automate attacks against infrastructure and design detections",
"Saved $10,000+ through effective vendor/supplier negotiations"
]
},
{
"name": "Intercontinental Exchange",
"position": "Cyber Security Engineer → Senior Cyber Security Engineer",
"location": "Marietta, Georgia",
"startDate": "2018-08",
"endDate": "2020-04",
"summary": "Incident Response/Digital Forensics lead, promoted to Architecture and Automation Team.",
"highlights": [
"Lead investigator on critical incidents; managed multi-server compromise investigations across three teams",
"Led Malware Analysis in sandboxed environments; mentored junior analysts",
"Designed security data flow pipelines and automated SOC triage tools"
]
},
{
"name": "The National Wild Turkey Federation",
"position": "Technical Services Manager",
"location": "Edgefield, South Carolina",
"startDate": "2015-10",
"endDate": "2018-08",
"summary": "Managed IT team supporting 300+ staff members with focus on infrastructure and security.",
"highlights": [
"Managed team of 8 technicians and developers supporting 300+ staff members",
"Migrated 3rd party tools to in-house solutions saving $50,000+ yearly",
"Managed security of entire web presence including network and application code"
]
},
{
"name": "Earlier Experience",
"position": "IT & Systems Administration Roles",
"startDate": "1999-01",
"endDate": "2015-01",
"summary": "Progressive IT roles including Network/Server Administrator at NWTF, System Administrator at Morgan Thermal Ceramics, IT Coordinator at Briarwood Academy, and Technical Support at Sitel Group."
}
],
"education": [
{
"institution": "Virginia College",
"area": "Network Administration",
"studyType": "Associate",
"startDate": "2014",
"endDate": "2016",
"score": "4.0",
"courses": []
}
],
"certificates": [
{
"name": "GWAPT - Web Application Penetration Tester",
"issuer": "GIAC",
"date": "2020-01-01"
},
{
"name": "GCFA - Forensic Analyst",
"issuer": "GIAC",
"date": "2019-01-01"
},
{
"name": "GCIH - Incident Handler",
"issuer": "GIAC",
"date": "2018-01-01"
}
],
"awards": [
{
"title": "Lethal Forensicator Coin Winner",
"awarder": "SANS/GIAC",
"date": "2019-01-01",
"summary": "SANS Challenge Coin for excellence in digital forensics"
}
],
"skills": [
{
"name": "Security Operations, SIEM & SOAR",
"level": "Expert",
"keywords": [
"Splunk",
"ELK Stack",
"Microsoft Sentinel/Defender",
"Google SecOps (Chronicle)",
"CrowdStrike",
"ReliaQuest",
"Sentinel One",
"Rapid7 IDR",
"Swimlane",
"D3 SOAR",
"Torq",
"Custom SOAR Development",
"Playbook Development"
]
},
{
"name": "Threat Detection, DFIR & Red Team",
"level": "Expert",
"keywords": [
"Darktrace",
"Tanium",
"Vectra",
"FireEye",
"Volatility",
"Malware Analysis",
"Incident Response",
"Detection Engineering",
"Threat Hunting",
"Abnormal Security",
"Metasploit",
"Purple Team"
]
},
{
"name": "AI/ML & Automation",
"level": "Expert",
"keywords": [
"AWS Bedrock",
"LLMs",
"RAG",
"Prompt Engineering",
"AI Security & Guardrails",
"AI Governance",
"Agentic AI",
"Model Evaluation",
"Python Automation"
]
},
{
"name": "Cloud, Infrastructure & Programming",
"level": "Advanced",
"keywords": [
"AWS",
"Azure",
"Oracle Cloud",
"Windows Server",
"Linux/UNIX",
"Active Directory",
"Docker",
"Kubernetes",
"Python",
"PowerShell",
"Bash"
]
},
{
"name": "Compliance & Frameworks",
"level": "Advanced",
"keywords": [
"NIST 800-53",
"PCI-DSS",
"HIPAA",
"GDPR",
"CIS Benchmarks"
]
},
{
"name": "Leadership & Management",
"level": "Expert",
"keywords": [
"Team Leadership (17+ reports)",
"MSSP Operations",
"Budget Management",
"Vendor Negotiations",
"Training & Mentorship"
]
}
],
"languages": [
{
"language": "English",
"fluency": "Native speaker"
}
],
"meta": {
"theme": "elegant",
"version": "v1.0.0",
"lastModified": "2026-06-23"
}
}