Chicago, IL · Open to remote

Ali Alshaheen

I turn attacker behavior into detections that hold up in production, secure cloud identity at the hybrid seam, and automate the response work that shouldn't wait on a human.

IT Security Associate running security operations across five affiliated healthcare entities. Seven years across IT operations and security, specializing in detection and response in the Microsoft stack — Entra ID, Defender, and Sentinel.

Detection & response Entra ID Identity security PowerShell Security automation Incident response

About

I came into security from the operations side, and it shaped how I work. Five years running IT for a growing business meant administering the systems — cloud identity, endpoints, networks — that security teams later ask questions about. When an alert fires now, I already understand what sits underneath it.

Today I handle security operations for a healthcare revenue management company spanning five affiliated entities, each with its own domain and Microsoft 365 tenant. The work is alert triage and investigation, identity governance in Entra ID, endpoint security, and a steady stream of automation aimed at the processes where a missed manual step becomes a security gap. Working in a HIPAA-regulated environment means every control has to be documented as well as functional.

I'm deliberately specializing in detection and response engineering with a cloud and identity focus. Most of my learning goes into KQL, Sentinel architecture, and identity attack paths — and I write up what I figure out on my blog.

Experience

  1. IT Security Associate — Level 2

    Mar 2025 – Present

    Physicians Revenue Group, Inc. · Downers Grove, IL

    • Run day-to-day security operations across five affiliated healthcare entities, each with its own domain and Microsoft 365 tenant — alert triage, investigation, and remediation.
    • Own identity and access management in Microsoft 365 and Entra ID: user lifecycle, licensing, MFA enforcement, and password policy across every entity.
    • Automated employee offboarding end to end, wiring the ITSM platform through to Entra ID so account disablement, session revocation, and license reclamation happen the moment a ticket closes rather than by hand.
    • Built PowerShell automation for patch deployment and endpoint provisioning, shortening onboarding time and reducing the window where new machines sit unpatched.
    • Designed and built an internal asset management system in Flask and JavaScript, replacing spreadsheet tracking with real hardware lifecycle visibility.
    • Developed a Node.js webhook service that routes ticket events into team chat, cutting the lag between an incident being raised and someone acting on it.
    • Authored the IT security documentation and standard operating procedures the team works from, embedding security practice into everyday process.
  2. IT Systems Analyst

    Aug 2019 – Mar 2025

    Alshaheen Perfumes · Plainfield, IL

    • Ran recurring vulnerability assessments with Nessus, OpenVAS, and OWASP ZAP; triaged findings by severity, cleared false positives, and drove remediation to closure.
    • Performed network reconnaissance and traffic analysis using Nmap and Wireshark to map exposure and investigate anomalous activity.
    • Administered Azure AD (now Microsoft Entra ID), implementing MFA and tightening access controls across company accounts.
    • Applied NIST and OSSTMM guidance to move security practice from ad-hoc to documented and repeatable.
    • Automated recurring business and IT processes, eliminating 40+ hours of manual work per month along with the human error that came with it.

Selected work

Identity security automation In production

Automated employee offboarding pipeline

An offboarding ticket now triggers the full identity teardown automatically: the Entra ID account is disabled, active sessions are revoked, licenses are reclaimed, and the outcome is written back to the ticket as an audit trail. Closes the window where a departed employee still holds a valid token — the gap manual offboarding always leaves open.

n8nMicrosoft GraphEntra IDWebhooks
Incident response Resolved

Log4Shell alert investigation (CVE-2021-44228)

An endpoint security alert flagged possible Log4Shell exploitation. I wrote a PowerShell investigation script, deployed it through RMM to enumerate Java runtimes and Log4j artifacts, and established the host had neither — it was not exploitable. Traced the flagged source address to the network's own DNS gateway. Documented as detection of scanning traffic, not a compromise.

PowerShellEndpoint securityThreat analysisForensics
Endpoint security Deployed

Fleet-wide endpoint agent deployment

Silent install and upgrade tooling for endpoint protection across a distributed fleet, hardened through repeated real-world failure modes — partial installs, stale agents, and hosts where the installer ran without a user context. Turned an unreliable manual rollout into a repeatable one.

PowerShellRMMEndpoint hardening
Identity auditing Ongoing

Entra ID audit and investigation tooling

A growing PowerShell toolkit for identity questions the portal answers slowly or not at all: reconciling directory users against authoritative HR data, resolving Entra object IDs from Windows security events during local administrator group investigations, and reporting license and service plan state by stable GUID rather than fragile display names.

PowerShellMicrosoft GraphEntra IDEvent logs
Software engineering Shipped

Internal asset and logistics platforms

Two internal web applications built end to end: an asset management system in Flask for hardware lifecycle tracking, and a shipment tracking portal in Node.js and Express with JWT authentication, four-tier role-based access control, carrier API integration, and activity logging throughout — backed by a 200+ test suite. Security engineers who can read and write real applications make better decisions about them.

Node.jsExpressFlaskJWTRBAC
Detection engineering Ongoing

Detection engineering lab

A hybrid lab — on-premises Active Directory synced to Entra ID, endpoints reporting into Sentinel and Defender — used to run attack techniques, observe the telemetry they generate, and write detections against them. Every technique ends with a tested rule and a write-up on the blog.

Microsoft SentinelKQLAtomic Red TeamSysmonSigma

Technical skills

Identity & access

Microsoft Entra ID, Azure AD, Active Directory, hybrid identity, MFA, Conditional Access, Microsoft Graph, identity lifecycle and governance

Security operations

Microsoft Defender XDR, Microsoft Sentinel, KQL, SIEM triage and investigation, EDR operations, alert tuning, incident documentation

Automation & scripting

PowerShell, Python, JavaScript, n8n, REST and Graph APIs, Bash, webhook orchestration, SOAR patterns

Vulnerability & network

Nessus, OpenVAS, OWASP ZAP, Nmap, Wireshark, vulnerability triage and remediation, traffic analysis

Cloud & platform

Microsoft 365, Azure, Intune, AWS fundamentals, Windows Server, virtualization, endpoint management

Frameworks & process

MITRE ATT&CK, NIST CSF, OSSTMM, HIPAA-regulated operations, incident response lifecycle, OWASP Top 10, SOP authoring

Credentials

Master of Science

Cybersecurity & Information Assurance

Western Governors University

Bachelor of Science

Computer Science

University of Illinois Chicago

Certifications

CySA+CompTIA
PenTest+CompTIA
Security+CompTIA
Certified in CybersecurityISC2
Cloud PractitionerAWS

In progress

SC-200Security Operations Analyst
SC-300Identity & Access Administrator

Get in touch

Open to conversations about detection engineering, security operations, and cloud identity roles — remote preferred. Corrections on anything I've written are always welcome too.