whoami

Kiante Nolen

Cybersecurity Professional focused on Cloud and AI Security Engineering

Security+ certified with hands-on experience across Linux and Windows environments, Python security automation, AWS cloud security, Active Directory IAM, and network forensics. I run a persistent multi-OS homelab across Kali, Parrot OS, Ubuntu, and Windows Server 2025 for continuous offensive and defensive practice.

Security+ (SY0-701)AWS Cloud Practitioner (in progress)18+ Security Tools Shipped

cat skills.json

Technical Skills

Programming & Scripting

  • Python (Advanced)
  • boto3
  • ldap3
  • reportlab
  • jinja2
  • PowerShell
  • Bash
  • Git

Cloud & AWS Security

  • EC2
  • S3
  • IAM
  • Cost Explorer
  • S3 misconfig detection
  • Security group analysis

IAM & Identity

  • Active Directory
  • LDAPS
  • RBAC
  • Group Policy
  • JML lifecycle
  • Privilege drift detection

Security Tools

  • Splunk (SPL)
  • Wazuh (EDR)
  • Wireshark
  • Nmap
  • Nessus
  • MITRE ATT&CK

Detection & Response

  • Threat detection
  • Log analysis
  • Brute-force detection
  • FIM (SHA-256)
  • IOC extraction
  • Incident response

Networking & Protocols

  • TCP/IP
  • DNS
  • DHCP
  • SSH
  • HTTP/HTTPS
  • Kerberos
  • CIDR
  • Port scanning

Validated by CompTIA Security+ ↗

  • Access Control
  • Cryptography
  • Cyber Forensics
  • Data Security
  • Disaster Recovery Planning
  • Firewall Configuration
  • Information Security Management
  • Malware Identification
  • Mobile Device Security
  • Network Security
  • Threat Detection
  • Threat Management

cat ai-skills.md

AI Tools & Skills

AI is part of how I build and document security work, and long term it is part of what I want to secure. Both sides start with knowing what these models actually do well.

Prompt Engineering

Iterative refinement, context management, and structured output generation for technical documentation and audit reporting.

AI-Assisted Automation

Workflow design and optimization with large language models, including AI-assisted Python development and debugging across the security tooling in these projects.

LLM Evaluation

Output quality assessment, bias identification, and response accuracy checks — treating model output as a claim to verify, not a result to trust.

Working Tools

Claude and ChatGPT, used as collaborative technical tools. Generated code is read, tested, and understood before it ships; the security findings in these labs are mine.

Certified: Google AI Essentials and Google Prompting Essentials, both completed April 2026 — see certifications.

ls ./projects

Projects

Six public repositories spanning cloud security, IAM, SIEM, EDR, and network forensics, including 18 production-ready Python security tools. Full source on GitHub.

AD IAM Auditor

2026

A modular Python tool that connects live to Active Directory via LDAPS and runs automated IAM security checks, generating timestamped audit reports.

  • Runs 4 automated checks: cross-department memberships, disabled accounts in active OUs, accounts with no groups, and 90+ day inactive accounts
  • Resolved 7 real technical blockers, including LDAP signing enforcement, LDAPS certificate binding, and Python 3.14's MD4 removal breaking NTLM auth (fixed via pycryptodome)
  • Generates professional PDF and HTML reports via reportlab and jinja2
  • Scanned 14 users against corp.local, surfacing 2 cross-department violations and 10 inactive accounts
PythonLDAPSActive Directoryreportlabjinja2
View on GitHub ↗

Active Directory IAM Lab

2026

A domain environment built from scratch to practice full identity lifecycle management and privilege auditing.

  • Deployed a Windows Server 2025 Domain Controller with 4 OUs and 3 RBAC security groups for domain corp.local
  • Provisioned 10 users via PowerShell and executed the full JML lifecycle: joiner, mover, and leaver
  • Ran a PowerShell access audit that caught cross-department privilege drift, documented with severity ratings and remediation steps
Windows ServerActive DirectoryPowerShellRBAC
View on GitHub ↗

Wireshark Network Traffic Analysis Lab

May 2026

Live packet capture and forensic analysis, including independent investigation of a real-world malware PCAP.

  • Applied 7 display filters to identify a 2,012-packet Nmap SYN scan, RST rejections, and plaintext HTTP exposure
  • Independently identified all 5 victim IOCs in a NetSupport Manager RAT PCAP via NBNS, Kerberos, and SAMR analysis
  • Produced a SOC-style incident report documenting C2 beaconing over TCP 443 with a full attack timeline
WiresharkPacket AnalysisMalware ForensicsMITRE ATT&CK
View on GitHub ↗

Splunk SIEM Lab

2026

SIEM deployment focused on SSH brute-force investigation, SPL query development, and incident documentation.

  • Ingested endpoint and authentication logs and hunted with SPL queries
  • Identified failed login patterns, off-hours authentication, and privilege escalation attempts
  • Documented findings in formal incident-report format
SplunkSPLSIEMThreat Hunting
View on GitHub ↗

Wazuh EDR Homelab

2026

An open-source EDR deployment across a multi-OS homelab for endpoint detection and compliance scanning.

  • Deployed a single-node Wazuh v4.7.5 stack (manager, indexer, dashboard, Filebeat) on Parrot OS with a Windows Server 2025 endpoint enrolled as agent 001
  • Simulated an NTLM brute force against the local Administrator account, generating 16 Rule 60122 alerts tagged to MITRE ATT&CK T1078 (Valid Accounts) and T1531 (Account Access Removal)
  • Triaged 796 collected events down to the failed-logon signal: status 0xc000006d, logon type 3 (network), 16 failures against 10 successes
  • CIS Windows Server 2025 Benchmark scan returned 126 passed / 261 failed for a 32% compliance score, exposing gaps in access control, audit policy, and service configuration
WazuhEDREndpoint SecurityCompliance
View on GitHub ↗

Python Security Automation Portfolio

2025 - Present

18+ production-ready security automation tools spanning cloud security, threat detection, and network reconnaissance.

  • S3 auditor with CRITICAL/HIGH/MEDIUM/LOW risk scoring targeting misconfigurations behind the Capital One breach
  • Concurrent TCP port scanner that covers 1,000 ports in 10 seconds, a 100x speedup over sequential scanning
  • 3-layer brute-force detector (velocity, distributed IPs, account enumeration) and SHA-256 file integrity monitoring
PythonAWSboto3Network ReconAutomation
View on GitHub ↗

cat certifications.yaml

Certifications & Training

CompTIA Security+ (SY0-701)Passed · Apr 2026
AWS Certified Cloud PractitionerIn Progress · Target Aug 2026
Google AI EssentialsCompleted · Apr 2026
Google Prompting EssentialsCompleted · Apr 2026
TryHackMe Pre-Security PathCompleted
TryHackMe Cyber Security PathIn Progress · 80%
Roadmap: CompTIA SecAI+ (CY0-001) · AWS Security Specialty · AWS Solutions Architect · AWS ML Specialty

tail -f experience.log

Experience

IT and Administrative Systems Specialist

Aug 2017 - Present

International Harvest Fellowship Ministries

  • Sole IT resource managing all networked PCs, AV equipment, and PA systems
  • Administer Google Workspace accounts, permissions, and domain settings for all staff

Freelance Web Developer and Digital Systems Consultant

Jul 2017 - Present

Independent, Arkansas and DFW Area

  • Design and maintain websites and digital infrastructure for small business clients
  • Resolved a critical Google Workspace/DNS misconfiguration for a logistics client, restoring full email functionality

Remote IT and Operations Coordinator

2020 - Present

Thrive Behavioral Health Services

  • Managed scheduling and records handling in a HIPAA-adjacent setting with strict access control
  • Maintained digital workflows for a remote-first clinical and administrative team

Pharmacy Technician and Machine Operator

Mar 2016 - Jul 2017

All Care Pharmacy

  • Sole operator of a beta Omnicell M5000 unit, trained directly by Omnicell systems engineers
  • Collaborated with the Omnicell engineering team to identify and resolve OS-level bugs during live deployment

uname -a

Homelab

A multi-OS environment I run continuously for offensive and defensive practice. Not one-off tutorials, but a persistent range I keep building on.

Kali LinuxParrot OSUbuntuWindows Server 2025

Splunk SIEM

Ingested endpoint and authentication logs, then hunted with SPL to surface failed-login patterns and privilege escalation attempts

Wazuh EDR

Wazuh manager on Parrot OS with a Windows Server 2025 endpoint enrolled as an agent, triaged failed-logon alerts and CIS benchmark findings

Attack/Defense Range

In Progress

Kali as attacker, Ubuntu as analyst, and Windows as victim, running full pentest and log-analysis cycles

Firewall & Log Practice

Security+ PBQ-style ACL configuration and threat-indicator identification

./contact --send

Get in Touch

Security+ certified cybersecurity professional seeking Security Analyst, SOC Analyst, and IT Support roles. Open to remote and hybrid positions nationwide. Long-term focus on Cloud and AI Security Engineering.