∑ SECURITY_PROTOCOLS | ∂ THREAT_VECTORS | λ ZERO_TRUST | ∏ IDENTITY_FIRST | ∇ DETECTION_ENG | ∅ ENDPOINT_TRUST | ≡ SANTA_FE_NM |
closeup of red circuit board
Security Engineer Photographer Santa Fe, NM

David
Mirch

Hardening systems by day.
Capturing desert light by dusk.
Proof-of-concepts that ship.

f(x) = SHA-256(threat_model) ∇ risk ≈ ∂(attack_surface)/∂t P(breach) → 0 as controls → ∞
13+
Yrs in Security
28K+
Endpoints Secured
42K
Exposures Captured
Iterations
01001000 01000101 00100000 ∙ SECURE ∙ CAPTURE ∙ ITERATE ∙
§01 — Case Studies scroll_to_reveal()
Security wireframe case study
CASE_STUDY_01
Zero Trust CERTIFICATE PKI 2024

ZERO TRUST
ENDPOINT
FRAMEWORK

Built and launched a certificate-based Zero Trust framework securing 7,000+ macOS, Windows, and Linux endpoints at Aurora. Device trust enforced via regular security posture evaluation.

7K+
Endpoints
3
OS Platforms
15+
Critical Apps
View Case Study
Kraken SOC automation case study
CASE_STUDY_02
SOC AUTOMATION PYTHON 2019

KRAKEN SOC
AUTOMATION

Custom Python automation service built at Millennium Management integrating 6+ security tools into a single layer. Eliminated manual ticket creation and cut phishing report volume by 60%.

60%
Phishing Reduced
6+
Tools Integrated
0
Manual Tickets
View Case Study
§02 — Process / Wireframes design.iterate(clarity=HIGH)
01
Phase_01

THREAT
MODELLING
+ PROOF
OF CONCEPT

Every solution starts with a two-page brief: problem statement, alternatives considered, and a minimal proof of concept to validate the approach before committing to full design.

02
Phase_02

DESIGN
DOCUMENT
+ ARCHITECTURE

A full design document follows: problem and solution in depth, architecture and network diagrams, security model, and a phased implementation timeline. Attack surface considered throughout.

APPROVE
03
Phase_03

IMPLEMENT
+ DOCUMENT
+ SHIP

Build, validate, and deploy. Outcomes captured as case studies: what was built, why it was built that way, and evidence it works at scale.

STATUS
DEPLOYED
§03 — Photography / LANDSCAPE & ASTRO shutter(milky_way)
Photo of milky way galaxy
MILKY WAY
EXPOSURES
Digital · Long Exposure · Rocky Mountain NP
landscape view of canyon in moab, ut
CANYON_SERIES
astrophotography long exposure over canyon rim
ASTRO_SERIES

Canyon photography in Moab, Utah — chasing light through red rock and slot canyons at golden hour. The same eye for depth and detail that maps an attack surface finds the hidden geometry in sandstone walls.

Astrophotography under ink-black desert skies — chasing the Milky Way core across canyon rims and mountain ridgelines. Long exposures that trade milliseconds for light-years, the same patience that waits for the perfect threat signal.

§04 — Skills Matrix
Zero Trust Architecture
Certificate PKI · BeyondCorp · Device Trust
Detection Engineering
SIEM · SOAR · 100+ Detections Built
Endpoint Security
macOS · Windows · Linux
λ
Identity & Access Management
Okta · FIDO2 · WebAuthn · OIDC
Go / Custom Tooling
Security Automation · Internal APIs · Reporting Tools
Vulnerability Management
Nessus · Risk Prioritization · Patch Tracking
Incident Response
Incident Command · Forensics · Runbooks
Photography
Digital · Landscape · Astrophotography

TWO LENSES.
ONE MIND.
SANTA FE.

Security engineer at Aurora building identity-first Zero Trust security at enterprise scale. Over a decade progressing from SOC analyst to architecting foundational security systems for 7,000+ endpoints.

Parallel practice as a landscape and astro photographer — the same methodical eye that spots a suspicious authentication event composes the perfect long exposure under a dark sky.

Every case study here is a proof of concept. Every photograph is a system study. Pattern, anomaly, light, shadow.

GCIA CISSP Splunk Architect
History & Context
2023 — Present
Senior Security Engineer
Aurora · Zero Trust & Identity
2022 — 2023
Security Engineer II
Ro · Detection Engineering & DLP
2021 — 2022
Senior Security Engineer
Slack · Vulnerability Management
2018 — 2020
Security Operations Analyst
Millennium Mgmt · SIEM & Automation
2015 — 2017
Security Investigator
Workday · Forensics & Detection Engineering
2013 — 2015
Lead Information Security Analyst
Hewlett-Packard · SOC & Security Automation
§06 — Contact handshake.init()

LET'S
BUILD
SOMETHING
UNBREAKABLE.

Security engagements, photography commissions, speaking — reach out from Santa Fe or anywhere on the network.