Threat Hunter | Cyber Intrusion Analyst | SOC Operations | Cloud Security | AI-Assisted Security Operations
Active Top Secret/SCI Clearance
I'm a cybersecurity professional with 8+ years of experience supporting Department of Defense and federal cybersecurity operations.
My background includes:
- Security Operations Center operations
- Threat hunting
- Incident response
- Malware analysis
- Detection engineering
- Threat intelligence
- Cloud security
- Kubernetes security
- DevSecOps
- Microsoft Entra ID
- Identity and Access Management
- Zero Trust architecture
- Risk Management Framework
- DISA STIG governance
I enjoy building enterprise-scale cybersecurity projects that demonstrate practical security operations, malware analysis, cloud security engineering, Infrastructure as Code, DevSecOps, AI-assisted security operations, Kubernetes security, risk governance, and Zero Trust architecture.
My recent work includes building an AI-assisted threat-hunting workflow that combines Microsoft Foundry, Microsoft Sentinel, Microsoft Defender XDR, Kusto Query Language, STIX 2.1, YARA, malware-analysis knowledge, and human-reviewed investigation guidance.
The project includes an authorized RemcosRAT static-analysis case study, imported threat intelligence, behavioral watchlists, practical KQL hunting content, a custom YARA rule, and evidence-based investigation documentation.
- 🛡️ Active Top Secret/SCI Clearance
- 🏅 Top 1% on Hack The Box Academy
- 🎯 662 Hack The Box targets compromised
- 📚 Completed 6 Hack The Box Academy learning paths
- 🤖 Built 10+ enterprise cybersecurity and AI security projects
- 🔍 Developed malware-analysis, threat-hunting, and detection-engineering case studies
- ☁️ Built security platforms across AWS, Microsoft Azure, Kubernetes, and OpenShift
- Security Operations Center Operations
- Threat Hunting
- Cyber Intrusion Analysis
- Incident Response
- Detection Engineering
- Malware Analysis
- Static Malware Analysis
- Threat Intelligence
- Behavioral Threat Hunting
- Microsoft Sentinel
- Microsoft Defender XDR
- Splunk Enterprise
- YARA Detection Development
- KQL Threat Hunting
- Cloud Security
- Kubernetes Security
- DevSecOps
- Microsoft Entra ID
- Active Directory
- Identity and Access Management
- Infrastructure as Code
- AWS Security
- Zero Trust Architecture
- Risk Management Framework
- DISA STIG Governance
- AI-Assisted Security Operations
- Security Automation
- Security Operations Center Operations
- Alert Triage and Investigation
- Threat Hunting
- Incident Response
- Cyber Intrusion Analysis
- Detection Engineering
- Malware Analysis
- Static Malware Analysis
- Threat Intelligence Analysis
- IOC Extraction and Validation
- Behavioral Analysis
- Security Reporting
- Case Documentation
- Audit-Ready Evidence
- Microsoft Sentinel
- Microsoft Defender XDR
- Splunk Enterprise
- Trellix EDR
- Cisco Firepower Management Center
- Zeek
- Suricata
- Falco
- Trivy
- Process Monitor
- VirusTotal
- MalwareBazaar
- YARA
- Sigma
- Kusto Query Language
- STIX 2.1
- MITRE ATT&CK
- Indicators of Compromise
- Behavioral Watchlists
- Threat-Intelligence Import and Validation
- File, Process, and Network Hunting
- Detection Rule Validation
- Amazon Web Services
- Microsoft Azure
- Microsoft Entra ID
- AWS Identity and Access Management
- AWS IAM Identity Center
- Azure Role-Based Access Control
- Cloud Security Monitoring
- Cloud Identity Governance
- Cloud Security Architecture
- Kubernetes
- Amazon Elastic Kubernetes Service
- Red Hat OpenShift
- Docker
- Helm
- Amazon Elastic Container Registry
- Amazon Elastic Container Service
- AWS Fargate
- Kubernetes Runtime Security
- GitHub Actions
- GitOps
- Continuous Integration and Continuous Delivery
- Terraform
- AWS CloudFormation
- AWS Cloud Development Kit
- Infrastructure as Code
- Security Scanning
- Automated Policy Validation
- Secrets Management
- Deployment Governance
- Python
- PowerShell
- Bash
- Kusto Query Language
- Git
- GitHub
- Linux
- Windows
- Visual Studio Code
- Windows Subsystem for Linux
- NIST Risk Management Framework
- DISA Security Technical Implementation Guides
- Zero Trust Architecture
- Identity and Access Management
- Role-Based Access Control
- Least Privilege
- Security Control Validation
- Continuous Monitoring
- Risk Reporting
- Security Compliance Support
| Project | Description |
|---|---|
| 🛡️ Microsoft Zero Trust, RMF & DISA STIG Architecture | Executive-focused security architecture combining Zero Trust, NIST RMF, DISA STIG governance, risk reporting, incident response, and continuous monitoring. |
| 🤖 AI-Powered Threat Detection Platform | AI-assisted Kubernetes threat detection, SOAR automation, MITRE ATT&CK mapping, cloud security analytics, and continuous monitoring. |
| ☁️ Enterprise Multi-Cloud CI/CD Platform | GitHub Actions, Docker, Terraform, OpenID Connect authentication, AWS CodePipeline, Infrastructure as Code, and automated deployments across AWS and Azure. |
| 🤖 GitHub AI Agent | AI-powered GitHub workflow automation with governance, human approvals, CI/CD integration, and security validation. |
| 🧠 AI Threat Hunt Agent with Microsoft Foundry and Sentinel | AI-assisted SOC and threat-hunting platform integrating Microsoft Foundry, Microsoft Sentinel, Microsoft Defender XDR, KQL, STIX 2.1, YARA, behavioral watchlists, malware-analysis knowledge, and human-reviewed investigation workflows. |
| 🚀 Enterprise OpenShift DevSecOps Platform | OpenShift Pipelines, static and dynamic application security testing, Trivy, GitOps, Kubernetes security, and Python automation. |
| 🎯 Enterprise Threat Hunting Platform | MITRE ATT&CK, Sigma, YARA, threat intelligence, detection engineering, Splunk hunting, and repeatable SOC investigation workflows. |
| ☸️ Enterprise Amazon EKS Security Platform | Amazon EKS, Falco, Infrastructure as Code, Kubernetes runtime security, threat detection, and continuous monitoring. |
| 🔐 AWS Zero Trust Architecture | AWS IAM, role-based access control, least privilege, identity federation, network segmentation, and Zero Trust cloud architecture. |
This project demonstrates how AI can support Security Operations Center analysts while preserving human control over investigation and incident decisions.
The platform combines:
- Microsoft Foundry
- Microsoft Sentinel
- Microsoft Defender XDR
- Azure AI Search
- Kusto Query Language
- STIX 2.1 threat intelligence
- YARA detection engineering
- Behavioral watchlists
- Malware-analysis knowledge
- Human-reviewed investigation workflows
- Verified the authorized malware-analysis sample using MalwareBazaar and VirusTotal
- Analyzed an obfuscated Visual Basic Script and PowerShell loader
- Identified self-copying, environment-variable staging, WMI, and hidden PowerShell behavior
- Extracted and documented file, network, process, and behavioral artifacts
- Developed and validated a custom YARA detection rule
- Created Microsoft Sentinel KQL queries for hash, network, process, and threat-intelligence hunting
- Built a STIX 2.1 intelligence bundle and Sentinel import file
- Imported SHA-256, SHA-1, MD5, domain, and URL indicators into Microsoft Sentinel
- Created a behavioral watchlist containing investigation artifacts
- Documented evidence boundaries to avoid unsupported compromise claims
- Maintained human analyst review before containment or escalation
The project separates static-analysis findings, imported intelligence, behavioral clues, and confirmed security activity. A YARA match, imported indicator, or KQL result is treated as an investigation lead rather than automatic proof of compromise.
| Repository | Link |
|---|---|
| Microsoft Zero Trust, RMF & DISA STIG Architecture | https://github.com/jbanday808/microsoft-zero-trust-rmf |
| AI-Powered Threat Detection Platform | https://github.com/jbanday808/ai-powered-threat-detection-platform |
| Enterprise Multi-Cloud CI/CD Platform | https://github.com/jbanday808/multi-cloud-cicd |
| GitHub AI Agent | https://github.com/jbanday808/github-ai-agent |
| AI Threat Hunt Agent with Microsoft Foundry and Sentinel | https://github.com/jbanday808/ai-threat-hunt-agent-foundry |
| Enterprise OpenShift DevSecOps Platform | https://github.com/jbanday808/python-openshift-cicd |
| Enterprise Threat Hunting Platform | https://github.com/jbanday808/Enterprise-Threat-Hunting |
| Enterprise Amazon EKS Security Platform | https://github.com/jbanday808/enterprise-eks-security-platform |
| AWS Zero Trust Architecture | https://github.com/jbanday808/aws-zero-trust-architecture |
- Microsoft Entra ID Identity Governance
- Okta Identity and Access Management
- AWS Identity and Access Management
- AWS IAM Identity Center
- Enterprise Identity, Credential, and Access Management Platform
- Hybrid Active Directory and Microsoft Entra ID
- Zero Trust Identity Architecture
- Detection Engineering with Sigma, YARA, and Suricata
- Microsoft Sentinel Detection Engineering
- Malware Analysis and YARA Detection Development
- AI-Assisted SOC and Threat-Hunting Workflows
- Cloud Security Automation
- Security Orchestration and Automated Response
- Kubernetes Threat Detection and Runtime Security
- Certified Ethical Hacker
- Certified Network Defense Architect
- CompTIA Security+
- ITIL 4 Foundation
I'm interested in opportunities involving:
- Security Operations Center Operations
- Threat Hunting
- Cyber Intrusion Analysis
- Incident Response
- Detection Engineering
- Malware Analysis
- Threat Intelligence
- Microsoft Sentinel
- Microsoft Defender XDR
- Splunk
- Cloud Security
- DevSecOps
- Platform Security
- Kubernetes Security
- Microsoft Entra ID
- Identity and Access Management
- Cloud IAM
- Security Automation
- AI for Cybersecurity
- Risk Management Framework
- Zero Trust Architecture
- DISA STIG Governance
I am especially interested in roles where I can combine hands-on security operations with detection improvement, threat hunting, incident response, cloud security, and analyst development.
My approach emphasizes:
- Evidence-based investigations
- Clear escalation criteria
- Repeatable threat-hunting processes
- Actionable detection content
- High-quality incident documentation
- Human validation of AI-assisted findings
- Continuous improvement across SOC operations
-
LinkedIn:
https://www.linkedin.com/in/james-allen-morta-banday-62a391128/ -
GitHub:
https://github.com/jbanday808 -
Email:
[email protected]
James Banday
Threat Hunter | Senior Cyber Defense Analyst | SOC Operations | Cloud Security | AI-Assisted Security Operations

