About
I have spent more than twenty years in security, and the last fifteen of them building the products.
I started as an analyst. Air Force first, cryptographic and network communications, then two deployments, then the CERT at Schriever Air Force Base, where I was the person using a SIEM rather than the person selling one. After that I ran firewall operations and SOC teams at CACI, and led network defense and intrusion detection as the lead ArcSight engineer on missile defense at Davidson. In 2011 I spent a year at Accuvant designing and deploying SIEM for companies from small business up to the Fortune 100.
That is where the opinions on this site come from. I wired these things together for a living before I ever got to decide what they should do.
Then product. Product manager at LogRhythm from 2011, a company later acquired. Senior product manager at ForeScout from 2016, promoted to run the orchestration product line, where my products produced about a third of company revenue in the quarters leading into the IPO. Head of product at Anomali from 2018. Director of product management for Splunk's security business unit from 2020 to 2022, where I owned the Enterprise Security portfolio, Splunk ES, UEBA, Security Essentials, PCI and the rest, with ten product managers and a hundred and fifty engineers behind a four hundred and fifty million dollar business growing fifty percent a year. Back to Anomali as head of product at the end of 2022, where we took the company from a threat intelligence vendor to a SIEM and moved SIEM from under five percent of bookings to over thirty five, with recurring revenue going from fifty million to eighty five.
Today I am Chief Strategy Officer at PolySwarm.
CISSP, GCIA, GCIH, ArcSight ACTP, Snort CP.
How this site works
Every factual claim here is sourced to a vendor's own documentation, named and dated, so you can check it without trusting me. That is deliberate. The documentation is what both sides of an integration have to live with, and it is what you can verify for yourself.
The judgment is mine. What actually breaks, what it costs, what most people end up doing instead. That comes from doing this work, in product and on engagements I cannot always name. Where I am telling you what a document says, the page says so. Where I am telling you what I have seen, it says that instead.
Corrections go to the contact page, and how they are handled is on corrections. The full method, including what each verdict and each source label means, is on the method page.