Detection Engineering · Security Operations · Federal

John
Althausen

I build the detection logic for a federal DOE environment in Oak Ridge, Tennessee — signature and behavioural rules across Elastic, Splunk, and CrowdStrike Falcon — and I am the on-call engineer who responds when they fire. Alongside that: Juniper network security, certificate-based access control, and Entrust PKI.

Loudon, Tennessee HSPD-12 PIV Credential CompTIA Security+
John Althausen
01

About

I started in IT support — imaging workstations, troubleshooting hardware, walking users through problems. That foundation taught me how systems break, which turns out to be most of what detection engineering is. Four roles later I author the detection content for a federal environment: web application attack signatures in Splunk, identity and endpoint-control alerting in Elastic, and custom indicators of attack in CrowdStrike Falcon.

The part I care most about is coverage assurance — knowing when the security stack itself has quietly stopped seeing. A sensor in reduced-functionality mode, a cloned agent reporting under a duplicate ID, a credentialed scanner failing authentication after a password roll: none of those raise an alarm on their own, and all of them mean you are blind somewhere. A good portion of my rule library exists to catch exactly that.

I also run Tracivex, an independent software company building privacy-first, on-device network analysis tools for Apple platforms.

02

Experience

Jun 2024 — Present
Current
Security Operations Center Analyst
Edgewater Federal Solutions, Inc. — DOE Office of Scientific and Technical Information — Oak Ridge, TN

Author of the detection content for the environment, across three platforms, mapped to MITRE ATT&CK.

Detection Engineering
  • Built web application attack detection in Splunk against Apache access logs, covering eight signature families: SQL injection, cross-site scripting, path traversal and local file inclusion, remote code execution including Log4j JNDI strings, server-side template injection, deserialisation exploits, scanner user agents, and hidden-endpoint probing
  • Developed behavioural abuse detection on requests per second, average payload size, and error rate to identify volumetric scrapers, slow-hang sessions, high-error scanners, and resource exhaustion
  • Engineered a tuned allowlist of approved crawler ranges and individual hosts, surfaced in-dashboard as approved traffic, so legitimate customers are never caught by the rules
  • Built detection alerts covering account creation and deletion, group modification, break-glass usage, disablement, password change, AppLocker events, local account creation, repeated authentication failure, and firewall-blocked internal traffic
  • Wrote CrowdStrike custom IOAs for anomalous LOLBin parent processes, temp-directory execution with user mismatch, privileged account lateral movement, Linux shell history tampering, and removable media or mobile device connection to government-furnished equipment
  • Built coverage-assurance detection for the security stack's own failure modes — duplicate agent IDs from VM cloning, Falcon sensor reduced-functionality mode and version drift, log ingestion failure and volume drop, and credentialed scanner authentication failure after password rotation
  • Designed analyst dashboards filterable by time range, application domain, IP or subnet, user agent, and download volume, with an analyst-level toggle controlling client-to-subnet aggregation
Incident Response
  • 24/7 on-call responder for all external-facing production web applications, with no rotation or secondary escalation
  • Detect, analyse, contain, and remediate application-layer attacks and availability incidents — typically restoring service before the federal customer or management is aware, keeping the environment on internally-detected rather than externally-reported incidents
Network Security Engineering
  • Upgraded the Juniper EX2300 access switch fleet from JunOS 18 to JunOS 24, closing several LTS generations of accumulated exposure on live production infrastructure
  • Supported a core network refresh delivering an approximately 40× throughput increase and establishing a post-quantum resistant cryptographic foundation
  • Implemented switch-port network access control using RSA and smartcard certificate-based authentication
  • Configure port security, VLAN tagging, and segmentation; deployed zero trust frameworks and security baselines across IoT device populations
Identity & PKI
  • Entrust encryption administrator — backend S/MIME configuration and certificate publication for encrypted email in Microsoft Outlook
  • Administer Entra ID user provisioning and role-based access for SIEM platforms; maintain identity alerting across hybrid on-premises Active Directory and cloud identity
Vulnerability Management
  • Operate Tenable Nessus for scheduled credentialed scanning, with dashboards surfacing remediation priorities to system owners
Elastic Splunk CrowdStrike Cortex XDR Nessus MITRE ATT&CK Juniper JunOS 802.1X Entrust PKI Zero Trust
Jul 2023 — Jun 2024
Help Desk Support
Edgewater Federal Solutions, Inc. — On-site
  • Resolved hardware and software issues across a federal user base via the Alloy ticketing system, with written guidance for self-resolution
  • Created and deployed standardised Windows images and maintained patch currency across the desktop fleet
  • Managed Proofpoint email security and smartcard authentication systems
  • Administered the Adobe software suite — licensing, updates, troubleshooting
  • Mentored incoming interns and staff on imaging, security protocols, and networking fundamentals
Proofpoint Smart Cards Windows Imaging Alloy Adobe Admin
May — Jun 2023
Information Science Specialist — Archivist Support / Help Desk
Edgewater Federal Solutions, Inc. — Oak Ridge, TN
  • Supported archival operations alongside help desk functions and user issue resolution
Feb — Apr 2023
IT Support Specialist Intern
Edgewater Federal Solutions, Inc. — Tennessee
  • Hands-on IT support including hardware troubleshooting and system imaging
03

Skills

Detection & SIEM

  • Splunk (SPL)
  • Elastic / ELK Stack
  • CrowdStrike Falcon custom IOAs
  • Palo Alto Cortex XDR
  • MITRE ATT&CK mapping
  • Dashboard engineering

Endpoint & Threat

  • EDR administration
  • LOLBin & living-off-the-land detection
  • Lateral movement detection
  • Insider threat & removable media
  • Sensor health & coverage assurance
  • Threat hunting

Network

  • Juniper JunOS (EX2300)
  • Ubiquiti
  • VLAN segmentation & port security
  • 802.1X certificate-based NAC
  • Zero trust architecture
  • IoT security baselines

Identity & PKI

  • Entrust certificate administration
  • S/MIME email encryption
  • Active Directory
  • Entra ID provisioning & RBAC
  • Smartcard authentication
  • HSPD-12 / PIV

Analysis & Forensics

  • Tenable Nessus
  • Wireshark
  • tcpdump
  • NetworkMiner
  • Nmap
  • Packet analysis & network forensics

Systems & Infrastructure

  • Windows Server administration
  • Image creation & deployment
  • Proofpoint email security
  • Linux
  • Swift / macOS development
  • Media sanitisation & data destruction
04

Certifications

Training

Course completions rather than proctored certifications — listed separately so the distinction is clear.

05

Education

2021 — Present
Roane State Community College
Cyber Defense and Networking Administration
Coursework: Cisco CCNA, Windows Server network security, network vulnerability analysis, digital forensics, penetration testing, network defense, Linux LPIC-I, programming I & II
2018 — 2020
Mt. San Antonio College
Network and System Administration
National Cyber League Competition — top-ranked in class