Through hands-on work with email security, incident response, and security architecture, I simplify complex tech so others don’t have to worry.
I combine methodical analysis with creativity and curiosity, especially when it comes to weird logs and gardening metaphors.
I started my career behind a camera.
Today, I spend my days hunting through logs, investigating incidents, building detections, and explaining to people why clicking that attachment was, in fact, a bad idea.
Cybersecurity wasn't a planned career path. It started as curiosity, turned into a hobby, became an obsession, and eventually somehow led me to a Blue Team Lead role.
Along the way, I've worked with everything from Microsoft Defender, Trend Vision One, Cybereason, QRadar, Wazuh, Stellar Cyber, Cisco ESA, Check Point Email Security, FortiMail, Trellix Email Security, FortiDeceptor, and T-Pot to various SIEM, EDR, SOAR, and email security platforms. The technology changes, but the challenge remains the same: figure out what's happening, why it's happening, and how to stop it.
When I'm not working, you'll probably find me running, cycling, watching films, taking photos, building something in my home lab, breaking something in my home lab, or pretending that maintaining a firewall, SIEM, honeypots, and servers is a normal hobby.
I genuinely enjoy regex, which is usually the point where people stop asking follow-up questions. Being a Slytherin, I felt contractually obligated to learn Python.
Owner and creator of leonoramilisa[.]com, cybercroatia[.]org, and cyber-europe[.]org.
Collector of certifications, suspicious IP addresses, and stories that begin with: "It was only supposed to be a small change."
Because somehow, the best part of cybersecurity isn't the technology itself; it's the moment when a pile of seemingly unrelated logs suddenly starts telling a story.