About
I build and validate defenses against real-world attacker behavior.
I'm Agron Gemajli, a cybersecurity engineer specializing in threat-informed defense, detection engineering, incident response, and purple team operations. My work focuses on helping security teams move beyond static alerts toward detection that is measurable, tested, and continuously improved.
I've worked across detection and response, security engineering, cloud security, and enterprise defense validation: building and maintaining detection logic, supporting investigations across endpoint, identity, SaaS, and cloud data sources, and maturing detection-as-code workflows with tools like Splunk, Bitbucket, and CI/CD pipelines.
What I care about most is the gap between "we have coverage" and "we know this works." That mindset pulls me toward detection validation, adversary emulation, breach and attack simulation, and automation that lets defenders test their assumptions before real attackers do.
Core areas
- Detection engineering
- Threat-informed defense
- Purple teaming and adversary emulation
- Splunk Enterprise Security
- Cloud security with AWS, CloudTrail, and GuardDuty
- Incident response and investigation workflows
- Detection-as-code and security automation
- Endpoint, identity, SaaS, and network telemetry
Outside of the day job, I build personal security projects and research labs to explore attacker behavior, defensive telemetry, and scalable validation workflows. I hold an M.S. in Cybersecurity from NYU and a B.S. in Computer Science from UConn, plus certifications including AWS Security Specialty, AWS Cloud Practitioner, Azure Fundamentals, and Splunk Cybersecurity Defense Analyst.
I'm always happy to connect with people working in detection engineering, security research, purple teaming, cloud defense, or security product development.