Detection Engineering · Security Operations · Federal
John
Althausen
I build the detection logic for a federal DOE environment in Oak Ridge, Tennessee — signature and behavioural rules across Elastic, Splunk, and CrowdStrike Falcon — and I am the on-call engineer who responds when they fire. Alongside that: Juniper network security, certificate-based access control, and Entrust PKI.
About
I started in IT support — imaging workstations, troubleshooting hardware, walking users through problems. That foundation taught me how systems break, which turns out to be most of what detection engineering is. Four roles later I author the detection content for a federal environment: web application attack signatures in Splunk, identity and endpoint-control alerting in Elastic, and custom indicators of attack in CrowdStrike Falcon.
The part I care most about is coverage assurance — knowing when the security stack itself has quietly stopped seeing. A sensor in reduced-functionality mode, a cloned agent reporting under a duplicate ID, a credentialed scanner failing authentication after a password roll: none of those raise an alarm on their own, and all of them mean you are blind somewhere. A good portion of my rule library exists to catch exactly that.
I also run Tracivex, an independent software company building privacy-first, on-device network analysis tools for Apple platforms.
Experience
Author of the detection content for the environment, across three platforms, mapped to MITRE ATT&CK.
- Built web application attack detection in Splunk against Apache access logs, covering eight signature families: SQL injection, cross-site scripting, path traversal and local file inclusion, remote code execution including Log4j JNDI strings, server-side template injection, deserialisation exploits, scanner user agents, and hidden-endpoint probing
- Developed behavioural abuse detection on requests per second, average payload size, and error rate to identify volumetric scrapers, slow-hang sessions, high-error scanners, and resource exhaustion
- Engineered a tuned allowlist of approved crawler ranges and individual hosts, surfaced in-dashboard as approved traffic, so legitimate customers are never caught by the rules
- Built detection alerts covering account creation and deletion, group modification, break-glass usage, disablement, password change, AppLocker events, local account creation, repeated authentication failure, and firewall-blocked internal traffic
- Wrote CrowdStrike custom IOAs for anomalous LOLBin parent processes, temp-directory execution with user mismatch, privileged account lateral movement, Linux shell history tampering, and removable media or mobile device connection to government-furnished equipment
- Built coverage-assurance detection for the security stack's own failure modes — duplicate agent IDs from VM cloning, Falcon sensor reduced-functionality mode and version drift, log ingestion failure and volume drop, and credentialed scanner authentication failure after password rotation
- Designed analyst dashboards filterable by time range, application domain, IP or subnet, user agent, and download volume, with an analyst-level toggle controlling client-to-subnet aggregation
- 24/7 on-call responder for all external-facing production web applications, with no rotation or secondary escalation
- Detect, analyse, contain, and remediate application-layer attacks and availability incidents — typically restoring service before the federal customer or management is aware, keeping the environment on internally-detected rather than externally-reported incidents
- Upgraded the Juniper EX2300 access switch fleet from JunOS 18 to JunOS 24, closing several LTS generations of accumulated exposure on live production infrastructure
- Supported a core network refresh delivering an approximately 40× throughput increase and establishing a post-quantum resistant cryptographic foundation
- Implemented switch-port network access control using RSA and smartcard certificate-based authentication
- Configure port security, VLAN tagging, and segmentation; deployed zero trust frameworks and security baselines across IoT device populations
- Entrust encryption administrator — backend S/MIME configuration and certificate publication for encrypted email in Microsoft Outlook
- Administer Entra ID user provisioning and role-based access for SIEM platforms; maintain identity alerting across hybrid on-premises Active Directory and cloud identity
- Operate Tenable Nessus for scheduled credentialed scanning, with dashboards surfacing remediation priorities to system owners
- Resolved hardware and software issues across a federal user base via the Alloy ticketing system, with written guidance for self-resolution
- Created and deployed standardised Windows images and maintained patch currency across the desktop fleet
- Managed Proofpoint email security and smartcard authentication systems
- Administered the Adobe software suite — licensing, updates, troubleshooting
- Mentored incoming interns and staff on imaging, security protocols, and networking fundamentals
- Supported archival operations alongside help desk functions and user issue resolution
- Hands-on IT support including hardware troubleshooting and system imaging
Skills
Detection & SIEM
- Splunk (SPL)
- Elastic / ELK Stack
- CrowdStrike Falcon custom IOAs
- Palo Alto Cortex XDR
- MITRE ATT&CK mapping
- Dashboard engineering
Endpoint & Threat
- EDR administration
- LOLBin & living-off-the-land detection
- Lateral movement detection
- Insider threat & removable media
- Sensor health & coverage assurance
- Threat hunting
Network
- Juniper JunOS (EX2300)
- Ubiquiti
- VLAN segmentation & port security
- 802.1X certificate-based NAC
- Zero trust architecture
- IoT security baselines
Identity & PKI
- Entrust certificate administration
- S/MIME email encryption
- Active Directory
- Entra ID provisioning & RBAC
- Smartcard authentication
- HSPD-12 / PIV
Analysis & Forensics
- Tenable Nessus
- Wireshark
- tcpdump
- NetworkMiner
- Nmap
- Packet analysis & network forensics
Systems & Infrastructure
- Windows Server administration
- Image creation & deployment
- Proofpoint email security
- Linux
- Swift / macOS development
- Media sanitisation & data destruction
Certifications
-
CompTIA Security+CompTIA — ID: 2RN4BB6RM2E11ZKTJul 2024 — Jul 2027
-
TestOut Security ProTestOut CorporationMay 2022
-
TestOut Network ProTestOut CorporationDec 2021
-
TestOut PC ProTestOut CorporationDec 2022
-
National Cyber League — Individual GameCyber SkylineNov 2020
Training
Course completions rather than proctored certifications — listed separately so the distinction is clear.
-
Palo Alto Networks Cybersecurity FundamentalsLinkedIn LearningOct 2024
-
Threat Hunting Essential TrainingLinkedIn LearningOct 2024