Drilling · Building · Available for hire

Cyber officer building real things.

2LT, U.S. Army National Guard Cyber Officer (17A). By day, a Cyber Security Engineer at a defense systems integrator. After hours, I build security tools, detection labs, and AI-assisted workflows — most of them in production on my own infrastructure.

Rank
2LT · 17A · ARNG
Role
Cyber Security Engineer I
Employer
Textron Systems
Based in
Baltimore / DC Area
Focus
Blue team · Detection · AI × Security
Elijah Beese
01Projects
Selected work

Things I built and shipped.

A detection lab spanning two states, an AI job-intelligence platform, an air-gapped vulnerability management tool, an RL attacker-vs-defender simulation, and an OSINT pipeline for scam takedowns.

2026

sitrep — AI Job Intelligence Platform

A nine-source job discovery and outreach platform for federal and defense roles. Parallel scraping, AI scoring against your background, automated recruiter recon via Hunter.io, and gap and interview prep generated per role.

// sitrep-ai-job-intelligence-platform
2026

homelab — Multi-Site Security Lab

An enterprise-grade detection lab spread across two states. Proxmox + OPNsense in Florida, an HP ProLiant DL360 in Iowa, Tailscale stitching them together. Splunk indexing 40k+ events shipped from Kali via Universal Forwarder.

// homelab-multi-site-security-lab
2026

AAvsD-Sim — Adversarial RL Network Security Simulation

A Q-Learning attacker against a Deep Q-Network defender, competing in real time across Linux network namespaces over a GRE/IPSec tunnel. Raw socket packet construction in pure Python — no scapy, no hping3.

// aavsd-sim-adversarial-rl-network-security-simulation
2026

lab5-vuln-mgmt — Offline Vulnerability Management

An ACAS/Tenable.sc-style vulnerability management toolchain for RHEL 9 environments where the internet is not a given. OpenSCAP scans feed a SQLite store mapped against NIST 800-53. Stdlib Python only — no pip at runtime.

// lab5-vuln-mgmt-offline-vulnerability-management
2026

scambusters-agent — OSINT Pipeline for Crypto Scam Investigation

An autonomous OSINT pipeline that investigates crypto scam infrastructure and drafts takedown notices. URLScan, WHOIS, passive DNS, and GPT-4o orchestrated end-to-end.

// scambusters-agent-osint-pipeline-for-crypto-scam-investigation
02Experience
Where I've worked

The track record.

Active operational roles across defense systems, critical infrastructure, enterprise IT, and DoD cyber.

JUN 2026 — PRESENT  ·  Textron Systems

Cyber Security Engineer I

Defense systems integrator · Unmanned systems · Hunt Valley, MD
  • Cybersecurity engineering supporting unmanned and defense systems programs in a contractor environment.
  • Applying RMF, NIST 800-53, and STIG-driven hardening across system development and authorization workflows.
  • Bridging enterprise blue-team experience with platform and mission-system security requirements.
RMFNIST 800-53STIGsSystems Security
MAY 2026 — PRESENT  ·  U.S. Army National Guard

Cyber Officer (17A)

MOS 17A · Cyberspace Operations
  • 2LT, U.S. Army National Guard — Cyberspace Operations branch (MOS 17A). Drilling in a cyber unit with operational mission focus on defensive and offensive cyber mission support.
  • Commissioned via Army ROTC, University of Tampa, following completion of Basic Camp (CST 2024) and Advanced Camp (CST 2025).
  • Operating across both military and civilian cyber environments — applying enterprise-side experience to military missions and vice versa.
Cyberspace OperationsLeadership
JAN 2026 — JUN 2026  ·  Tampa Electric Company

Network Technologies Analyst

Critical infrastructure · 24×7 Technology Operations Center · Tampa, FL
  • Staffed the 24×7 Technology Operations Center across network, security, incident response, and after-hours service desk for a major utility.
  • SIEM-based monitoring via Splunk and SolarWinds — triage, correlation, and escalation across servers, storage, and network infrastructure.
  • Troubleshot LAN/WAN environments including MPLS and SD-WAN; coordinated vendor engagement for incident resolution.
  • Maintained security posture across firewalls, OS, and network systems; deployed patches and configuration changes via iLO and virtual console access.
SplunkSolarWindsMPLSSD-WANIncident Response
JUL 2025 — AUG 2025  ·  Air Force Institute of Technology

Cybersecurity Intern — DoD Joint Cyber Operations

Wright-Patterson AFB, OH · Joint Army / Air Force / Space Force
  • Selected from thousands of ROTC cadets — one of 40 nationwide for a joint-service DoD cyber internship spanning Army, Air Force, and Space Force.
  • Participated in nation-level cyber defense exercises focused on intrusion detection, threat analysis, and incident response under operational DoD conditions.
  • Hands-on with firmware analysis, exploit development, network forensics, and malware triage in live DoD network environments.
Network ForensicsFirmware AnalysisIntrusion Detection
MAY 2025 — MAY 2026  ·  University of Tampa

Information Technology Analyst

Enterprise IT · 10,000+ users · Tampa, FL
  • Enterprise technical support across campus networks, servers, and endpoints serving 10,000+ students, faculty, and staff.
  • Account and device management in Active Directory and VMware/vSphere; system imaging, hardware/software troubleshooting, endpoint lifecycle.
  • Vulnerability scanning and endpoint protection initiatives; collaboration on network reliability and incident response workflows.
Active DirectoryVMware vSphereVulnerability Scanning
DEC 2025 — MAY 2026  ·  University of Tampa

Cybersecurity Research Assistant

Under Dr. Giovannetti · Tampa, FL
  • Research analyzing emerging-technology implications across data privacy, surveillance, and cyber operations.
  • Real-world case studies on responsible disclosure, data protection, and technology misuse.
  • Review of academic literature on cyber governance and compliance frameworks including NIST directives and DoD policy.
NIST FrameworksPolicy Research
03Capabilities
What I do

Across the kill chain and back again.

Day-job blue team, off-hours research, and the boring infrastructure work that makes both possible.

01 / Defense

Defensive Operations

  • SIEM & detection Splunk / Wazuh
  • Incident response
  • Threat hunting
  • Network defense SD-WAN / MPLS
  • Critical infrastructure
02 / Research

Offensive & Research

  • Vulnerability assessment OpenSCAP
  • Network forensics
  • Firmware analysis
  • Adversarial ML RL agents
  • OSINT pipelines
03 / Build

Build & Automate

  • Python stdlib-first
  • LLM integration OpenAI · Claude
  • Linux infra RHEL · Proxmox
  • Cloud AWS · Azure
  • RMF · NIST 800-53 · STIGs
04Credentials
Education & certs

The paperwork.

Education

M.S. Computer Engineering — Security
2026 — 2027
Florida International University · Online · In progress
B.S. Cybersecurity
2023 — 2026
University of Tampa · NSA CAE-CD · MIS minor
A.A. General Studies
2020 — 2023
Tarrant County College

Certifications

CompTIA Security+ (SY0-701)
Active
DoD 8140/8570 IAT Level II compliant
ISC2 Certified in Cybersecurity
Active
Foundational practitioner credential
AWS Cloud Practitioner · Microsoft AZ-900
Active
Cloud fundamentals across both major providers
FCC General Class Amateur Radio
Licensed
Callsign KI5TGC · RF / SIGINT-adjacent
05Writing
Notes from the field

Writing.

All posts →
06Contact
Open to opportunities

Let's talk shop.

Federal, defense contractor, or applied-security roles where the work matters and the team is sharp. Direct outreach is the fastest path — I read everything and reply quickly.