Security engineer · Austin, TX

I build identity, detection, and automation that hold up in production.

Seven years at a production SaaS company taking security from no formal controls to a working program: Okta and Entra ID across 150+ apps, Splunk and CrowdStrike detection and response, and Python/SOAR automation that removes the toil. U.S. Army infantry veteran.

Joe Whittle smiling on a rocky mountain summit, wearing a headlamp and a daypack.

About

You might be wondering about the domain. I was born Andrey Sergeevich in Ukraine. I was adopted, became Joseph Andrew Whittle, and grew up in South Carolina. Both names are mine, and this site carries the first one.

I served in the U.S. Army as an infantry team leader from 2015 to 2017. That's where I learned that the people and tools you depend on have to work when it matters. After the Army I started at FloSports in Austin on the IT side, studied networking at night, earned my CCNA, and moved from IT into systems engineering and then security.

Most of my work is identity and access, detection and response, and automation. I like turning a manual, error-prone process into something that runs on its own and leaves an audit trail. I finished a B.A.S. in Computer Systems Technology at Austin Community College in 2024.

When I'm not working I'm usually outside with my dog Sasha, a German Shepherd/Border Collie mix, or driving somewhere new. Since June 2025 that has added up to a road trip through all 48 contiguous states.

What I work on

Identity & access

Okta and Microsoft Entra ID, SSO and SCIM, RBAC, and joiner-mover-leaver workflows with least-privilege guardrails.

Detection & response

Splunk and Chronicle SIEM, CrowdStrike EDR, alert triage, detection tuning to cut false positives, and incident response runbooks.

Security automation

Python, SQL, SOAR playbooks, and API integrations for alert enrichment and response, plus log pipelines into the SIEM.

Cloud security

AWS IAM, CloudTrail, GuardDuty, and Security Hub. Least-privilege reviews and visibility into what's actually running.

Compliance foundations

CIS Controls (CIS 18) adoption from zero, SOC 2 alignment, GDPR/DSAR process design, and gap assessments with a phased plan.

Vulnerability management

CVSS-based prioritization and remediation tracking with engineering teams, focused on closing high-severity findings on SLA.

Credentials

  • CompTIA Security+
  • CompTIA Network+
  • CompTIA A+
  • AWS Certified Cloud Practitioner
  • Cisco CCNA
  • Okta Certified Administrator

Education: B.A.S., Computer Systems Technology, Austin Community College (2024).

Experience

  1. Current

    Information Security Engineer

    Healthcare technology company (contract)

  2. Oct 2025 – Jan 2026

    Security Automation Engineer (Contract)

    Arctiq

    Built and optimized SOAR playbooks integrated with Splunk and Chronicle SIEM, and connected Entra ID and EDR telemetry into Splunk and Chronicle across multi-tenant client environments.

  3. Mar 2018 – May 2025

    Security Engineer (2021–2025)

    FloSports · Austin, TX

    • Owned Okta and Entra ID identity and access across 150+ applications, including joiner-mover-leaver workflows.
    • Led detection and response with Splunk and CrowdStrike; tuned detections and cut MTTR by about 40%.
    • Built Python/SQL enrichment and response automation, saving about 20 hours a week of manual work.
    • Ran CVSS-based vulnerability remediation with a 98% SLA closure rate on high-severity findings.
    • Led CIS 18 adoption from no formal controls, and a cross-functional fix for a DSAR backlog (TrustArc automation).

    IT Systems Engineer (2020–2021) · IT Associate (2018–2020)

    Designed and deployed a 40,000 sq ft Cisco corporate and live-production network. Ran Windows/Linux systems, AD/Entra ID/Okta integration, and lifecycle for 500+ endpoints.

  4. 2015 – 2017

    Infantry Team Leader

    United States Army

    Led small teams in high-pressure operational environments.

Projects

AtlasIT

A multi-tenant compliance platform that replaces manual control audits with an automated pipeline: control mapping, evidence collection, and posture reporting for organizations without dedicated security staff.

Cloudflare Workers · Hono · D1 · React/TypeScript

A Whittle Wandering

A telemetry platform that ingests, normalizes, and maps vehicle data from a 48-state road trip: about 15,830 miles and 339 stops. Secrets live in a vault, ingestion is schema-validated, and logging is structured.

Cloudflare Workers · D1 · KV · R2 · React/Mapbox

More in Travel ↓

Travel · A Whittle Wandering

Since June 1, 2025, Sasha and I have been working through the lower 48: about 15,830 miles and 339 stops so far. A Whittle Wandering is the trip's home: the route map, the stats, and the stories.

Visit A Whittle Wandering →

The "Currently in" card at the top only ever shows a city from at least a day ago. It never shows anything more precise, and never home.

Upcoming trips

2027 · about 4 months

Backpacking Europe

Portugal → Spain → Ireland → Scotland → England → France → Italy → Germany → Czechia → Poland → Hungary → Serbia → Bosnia & Herzegovina → Montenegro → Albania, with a hike in almost every country. Dates to be decided.

Contact

The best way to reach me is email.

howdy@andreysergeevich.me