JAKOB // SENTINEL WORKSPACE jberentsen-prod UPTIME
Security Engineer · Healthcare

Security for systems
that can't go down.

I'm a security engineer who secures the technology a hospital runs on — endpoints, identity, network, and the SIEM that watches it all. Full-stack defensive coverage, proven in an environment where downtime isn't an option. This page is that work, monitored live.

● LEAD II SUMMIT PACIFIC // FLOOR MONITOR 72 BPM
STATUSNOMINAL
SYSTEMS6 DOMAINS
SHIFTNIGHT
ALERTS0 CRIT
BEGIN ROUNDS
01

Security, end to end

The same coverage a security program needs — endpoint, identity, network, detection, vulnerability management, and governance — each one real work I own in production. Green is holding. Amber is active.

SecurityCoverage· custom table READY

  

6 domains returned

DETECTION & RESPONSEMONITORING

SIEM & Log Correlation

Microsoft Sentinel · KQL · multi-source audits

Run audits that correlate logs across Horizon event data, Imprivata, badge systems, and FortiAnalyzer, and write KQL to surface what matters in Sentinel. Pulling a clean signal out of scattered sources is the core of the work.

SOCKQLlog analysis
VULNERABILITY MGMTREMEDIATED

Vulnerability Management

Rapid7 · AD CS · Qualys VMDR

Researched and implemented mitigations for Rapid7 penetration-test findings and eliminated critical Active Directory Certificate Services vulnerabilities — measurably improving the security posture of the environment.

remediationAD CS
IDENTITY & ACCESSAUTOMATED

Identity & Access Management

Active Directory · Galaxy access control

Built role-based provisioning tying badge and system access to AD security groups: new hires get the right access automatically, terminated accounts lose it the instant they're offboarded. Identity lifecycle that enforces itself.

IAMRBACautomation
GOVERNANCEAUDITED

Audit & Investigations

Microsoft Purview · eDiscovery · M365

Audit accounts and access through Microsoft Purview and participate in internal investigations — defensible collection and review handled cleanly, the part of security that has to hold up under scrutiny.

complianceinvestigations
ENDPOINTHARDENED

Endpoint Security

10ZiG thin clients · GE MAC 7 · medical devices

Standardize and harden 10ZiG endpoint templates so every deployed device is secure and consistent, and lock down medical devices — Technician-ID auth, idle lockouts, and compensating-control documentation where they can't meet the standard natively.

hardeningdevice security
NETWORKHA PAIR

Network Security

FortiGate 100F HA · FortiAnalyzer · Azure

Own the firewall HA pair and edge, pull forensic detail from FortiAnalyzer, and work across Azure and M365 daily. Turning "the network is slow" into an actual diagnosis is a security skill before it's a networking one.

firewallcloudtriage
02

Service record

The same floor, walked longer. A pattern of taking senior-scope work without waiting for the title to catch up.

EmploymentEvent· custom table READY

  

5 events · ordered desc

JUL 2025 — PRESENT
Clinical Systems Specialist
Summit Pacific Medical Center · Elma, WA
Administer and secure clinical-based technology for a critical-access hospital: device hardening, change control, identity and access systems, vulnerability remediation, and the internal tooling that didn't exist yet. Liaison between technical teams and clinical staff.
OCT 2024 — JUL 2025
IT System Coordinator
Summit Pacific Medical Center
Same building, earlier chapter. Built out Mindray telemetry and Vocera, remediated Rapid7 and AD CS findings, and designed the AD-to-Galaxy badge integration that auto-provisions new hires and revokes terminated access by security group.
JAN 2023 — NOV 2024
IT Lead Technician & Security Specialist
Twin Harbor Technology Solutions
Ran SIEM and email security, firewall installs, and Fortinet switch/AP deployments across clients. Built risk assessments and incident response plans and drove PCI DSS compliance.
APR 2024 — OCT 2024
Cybersecurity Support Engineer · Intern
Log(N) Pacific
Hardened Azure with Private Link, NSGs, and Defender for Cloud against NIST 800-53, PCI DSS, and HIPAA/HITRUST, and wrote KQL to power new Sentinel dashboards.
IN PROGRESS
M.S. Cybersecurity & Information Assurance
Western Governors University · on a B.S. in Computer Science
Formalizing on paper what the day job already proves in practice.
03

Credentials & loadout

Certifications and the working toolset. Amber items are in progress.

Certification· custom table READY

  

12 rows · grouped by status

DEGREE
B.S. Computer Science
DEGREE
M.S. Cybersecurity
CERT
CompTIA Security+
CERT
CompTIA Network+
CERT
CompTIA Project+
CERT
ITIL 4 Foundations
CERT
Digital Forensics (EC-Council)
CERT
Qualys VMDR
SECURITY
Sentinel · KQL · NIST 800-53
CLINICAL
Mindray · Vocera · Galaxy
NETWORK
Fortinet · Active Directory
BUILD
Python · Java · SQL · PowerShell
04

Things I've built

Shipped code, not just coursework. Each one links to the repository.

RepoActivity· custom table READY

  

5 repos · sorted by category

05

Live threat intel

This pulls the real CISA Known Exploited Vulnerabilities catalog — the authoritative "patch this first" list of CVEs under active exploitation. It's the feed I'd actually watch in a vuln-management role, live from CISA's catalog. Filter by ransomware association below.

CONNECTING CISA // KNOWN EXPLOITED VULNERABILITIES CATALOG
// SOURCE QUERY
externaldata(cveID:string, vendor:string, product:string, dateAdded:datetime, ransomware:string) [@"https://www.cisa.gov/.../known_exploited_vulnerabilities.json"] | where dateAdded > ago(90d) | where ransomware in ("Known","Unknown") | order by dateAdded desc
Fetching live catalog from CISA…

06

Where I add value

I'm targeting security operations, ISSO, and vulnerability-management roles. Here's what I bring that a narrower candidate can't.

DETECTION

SOC & Detection

Hands-on Sentinel and KQL, correlating logs across Horizon, Imprivata, badge systems, and FortiAnalyzer. I've done real multi-source audits, not lab exercises.

VULN MGMT

Vulnerability Management

Rapid7 and Qualys findings worked end to end — including eliminating critical AD CS vulnerabilities. I close findings, not just report them.

GRC / ISSO

Governance & Audit

IAM, Purview audits, investigations, HIPAA, and change control. The breadth ISSO work actually demands — and I've operated across all of it in production.

DIFFERENTIATOR

Healthcare & OT Depth

I secure medical devices and clinical systems most security teams treat as a black box. That domain context is a hard-to-hire edge, and I live in it daily.