Endpoint Security
Microsoft Defender for Endpoint investigation, endpoint hardening, alert triage, and response workflow support.
Security Engineer · Terre Haute, Indiana
I help strengthen security operations through practical endpoint defense, identity controls, incident response workflows, and risk-aware vendor reviews.
About
I am Ryan Lopez-Dunn, a Security Engineer based in Terre Haute, Indiana. My work centers on protecting users, devices, and business systems through strong identity posture, endpoint visibility, and disciplined response practices.
I bring hands-on experience with Microsoft Defender for Endpoint, Entra ID, Conditional Access, MFA and phishing-resistant authentication, Cisco Umbrella, KQL hunting, incident response, endpoint security, identity security, vendor and security risk reviews, and PCI support.
My approach is practical and evidence-driven: identify the risk, improve the control, document the workflow, and make the next investigation faster.
Security Skills
Microsoft Defender for Endpoint investigation, endpoint hardening, alert triage, and response workflow support.
Entra ID, Conditional Access, MFA strategy, phishing-resistant authentication, and account protection practices.
KQL hunting, detection review, suspicious activity analysis, and repeatable investigation documentation.
Alert validation, containment coordination, timeline development, evidence gathering, and post-incident improvement.
Cisco Umbrella identity attribution support, DNS-layer visibility, and policy-centered investigation support.
Vendor and security risk reviews, control mapping, PCI support, and security-focused business analysis.
Projects
Endpoint Detection
Designed a repeatable investigation workflow for Defender alerts, including triage steps, evidence review, escalation points, and documentation habits.
Identity Controls
Supported security improvements around Entra ID Conditional Access policies, MFA expectations, and stronger authentication coverage.
DNS Security
Helped improve visibility into user and device attribution for Cisco Umbrella activity to support clearer investigation and policy review.
Vendor Risk
Researched identity verification vendors with attention to security posture, business fit, control expectations, and implementation considerations.
Consulting Brand
Developed a personal consulting brand concept focused on identity security, practical control maturity, and accessible security guidance.
Certifications
Add active cybersecurity certifications here as they are earned or renewed.
Recommended space for Microsoft security, identity, compliance, or endpoint-focused credentials.
Use this section for labs, training, coursework, and professional security development.
Resume
Download a PDF resume with experience, projects, and cybersecurity focus areas.
Contact