Murfreesboro, TN
Ricky Tipler
Security Engineer
Security Engineer with 5+ years protecting enterprise environments in healthcare and government — SIEM engineering, threat hunting, and cloud security.
- 5+
- Years Experience
- 6
- Certifications
- 21,000+
- Endpoints Secured
- 30,000+
- Employees & Patients Protected
01 — About
Defense across healthcare and government.
Security Engineer with 5+ years defending enterprise environments across healthcare and government. I work across SIEM engineering, endpoint detection and response, threat hunting, vulnerability management, and cloud security — currently focused on SIEM engineering, EDR operations, and AWS security.
Holder of the AWS Security Specialty, CASP+, and several other cloud/security certifications. Outside of work I build hands-on cloud security projects (Terraform on AWS), write up what I learn, and I'm currently building a Chrome extension focused on phishing detection.
02 — Experience
Where I've operated.
-
Cybersecurity Specialist
Security specialist at the largest operator of senior housing in the U.S., protecting 30,000+ employees and patients — detecting threats, managing access, and securing critical healthcare systems across enterprise security tooling.
- Engineered SIEM detection pipelines: onboarded new log sources and rewrote alert logic for broader threat coverage and a significant reduction in false positives.
- Deployed and validated EDR across 21,000+ endpoints, auditing agent health, telemetry ingestion, and detection gaps for full device visibility.
- Conducted threat hunting using a threat intelligence platform to surface active IOCs and threat-actor TTPs, pivoting intel into SIEM and EDR to catch compromise before alerts fired.
- Integrated vulnerability scanning into server onboarding — critical/high findings must be remediated before production deployment.
- Spearheaded SOAR adoption to orchestrate response actions (IP blocking, account suspension, endpoint isolation), compressing containment time.
- Automated repetitive security validation and asset review with PowerShell, cutting manual effort by 75%.
- Managed the lifecycle of 850+ SSL/TLS certificates using certificate management tooling to prevent outages from expired certs.
-
Information Security Administrator
Secured computer systems across 11 state correctional facilities — access controls, endpoint hardening, and incident response, keeping inmate computer use within approved boundaries.
- Led end-to-end design and deployment of a secured, inmate-operated call center: hardware procurement, network placement, firewall rules, and GPO security baselines across 300+ endpoints.
- Led full insider-threat investigations from detection through resolution, analyzing access logs and unauthorized activity — resulting in tightened access controls and a policy change to prevent recurrence.
- Built PowerShell automation for security compliance checks across endpoints, cutting manual validation time and keeping systems audit-ready.
03 — Projects
Shipping log
Hands-on builds — expand an entry for the full breakdown.
-
A Chrome extension that detects phishing sites in real time by analyzing URLs, domain patterns, and page content, protecting users from credential theft and social engineering before they engage with a malicious page.
- Dynamic risk-scoring engine rates visited sites on a 0–100 threat scale, shown as a color-coded badge in the toolbar.
- AI prompt safety warning system intercepts input to AI chatbots and flags sensitive data (passwords, PII, confidential info) before submission, reducing accidental data exposure through AI tools.
-
A fully private serverless API on AWS, built entirely with Terraform. API Gateway triggers a Lambda function in private subnets, which reaches an RDS MySQL instance in isolated database subnets — nothing in the data path is publicly exposed.
- Database credentials stored in Secrets Manager, encrypted with a customer-managed KMS key.
- Security groups restrict traffic so only the Lambda function can reach the database.
- Full environment — VPC, public/private/database subnets across multiple AZs, NAT gateway, IAM roles — deployed repeatably from code.
- Includes a detailed architecture and implementation writeup in the repository.
04 — Tools & Stack
Tools I've worked with
Security platforms and technologies I've used across enterprise environments and hands-on projects — listed by category, not tied to any single employer.
SIEM
EDR
SOAR
Threat Intelligence
Vulnerability Management
Certificate Management
Cloud Platforms
Infrastructure as Code
Scripting & Automation
PAM
Email Security
Data Security
Firewall / Network Security
05 — Certifications
Validated credentials
Each badge links to my Credly profile.
- AWS AWS Certified Security – Specialty View on Credly →
- AWS AWS Certified Solutions Architect – Associate View on Credly →
- CompTIA Advanced Security Practitioner (CASP+) View on Credly →
- CompTIA PenTest+ View on Credly →
- CompTIA Cloud+ View on Credly →
- HashiCorp Terraform Associate View on Credly →
Education
B.A. — Computer Information Systems
Thomas Edison State University
07 — Contact
Let's connect.
Open to security engineering conversations, collaborations, and interesting problems.
- Email Reveal email
- GitHub github.com/rickytip
- LinkedIn linkedin.com/in/ricky-tipler
- Location Murfreesboro, TN