Skip to content
View Keelen-Carrera's full-sized avatar

Block or report Keelen-Carrera

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Keelen-Carrera/README.md

Banner

Hey, I'm Keelen Carrera

Security Engineer · DevSecOps & Detection Engineering

LinkedIn Portfolio Email


I'm a security-conscious software engineer with 5+ years of experience designing scalable backend systems, coordinating enterprise integrations, and hardening API endpoints. My focus is on strengthening system integrity through threat-aware architecture, workflow automation, and platform security improvement, with active work in detection engineering, secure SDLC, and cloud security.

Coming from a production engineering background gives me a unique angle on defensive security: I've been the one who built the systems that need defending. I understand where integration seams crack under load, where IAM gets sloppy, and how the operational pressure that ships code also creates the vulnerabilities I'm now learning to detect and remediate. Committed to building resilient, high-availability systems that reduce risk and protect mission-critical infrastructure.

Tech Stack

Security & Detection

Wazuh Sigma MITRE ATT&CK Atomic Red Team Burp Suite

Incident response · Log analysis · Vulnerability management · Risk assessment · Secure SDLC

Cloud & DevSecOps

AWS Docker Linux Git GitHub Actions

AWS services: EC2 · IAM · Elastic Beanstalk · DynamoDB

Languages

Python JavaScript TypeScript Java C# SQL

Frameworks & Frontend

Node.js React Angular Next.js

Databases

PostgreSQL MongoDB MSSQL


Featured Work

A three-VM blue-team lab built on Wazuh, with 5 custom Sigma detection rules mapped to MITRE ATT&CK techniques and validated against Atomic Red Team simulations. Detection coverage spans credential dumping, PowerShell abuse, and scheduled task persistence — each rule shipped with adversary context and hardening guidance.

Stack: Wazuh · Sigma · Atomic Red Team · MITRE ATT&CK / D3FEND · Ubuntu · Bash

API-based integration workflows between simulated enterprise systems, demonstrating secure API design at scale. JSON/XML transformation pipelines with input validation, error handling, and reusable transformation logic — patterns drawn from 13+ production integrations shipped at Aries Worldwide Logistics.

Stack: Mulesoft · REST APIs · JSON/XML · Secure-by-default API patterns

Backend services for inventory and supplier workflows built with a Dallas Software Developers cohort—RESTful APIs and real-time operational data processing, deployed in an Agile team environment.

Stack: Node.js · TypeScript · REST APIs · Cloud deployment


Let's Connect

Always open to conversations about detection engineering, DevSecOps practices, AWS security, or breaking into security from a software background. If you're hiring, building, or just want to compare notes:

Pinned Loading

  1. smart-kitchen-mgmt smart-kitchen-mgmt Public

    Forked from allaboutmike/smart-kitchen-mgmt

    DSD Cohort 2025 Project for team Deja and Mike

    TypeScript 1

  2. logistics-integration-portfolio logistics-integration-portfolio Public

    A collection of integration architecture patterns and data transformation examples inspired by real-world enterprise logistics system design.

  3. keelencarrera_portfolio keelencarrera_portfolio Public

    Portfolio built in 2026 - DevSecOps-Focused

    HTML

  4. SOC-Home-Lab-with-SIEM-Detection-Engineering SOC-Home-Lab-with-SIEM-Detection-Engineering Public

    A detailed lab guide for setting up a home SOC environment using free tools.

    1