Mick Cecil
π United States | π§ the.m1ck(at)proton.me | π LinkedIn | π Website
Professional Summary
Accomplished Information Security Engineering Leader with over 15 years of experience in strategic security operations, offensive security, threat hunting, and threat intelligence.
Built and led multiple high-impact security teams at Amazon, including:
- Amazonβs first Insider Threat Prevention Team within Retail Security, focused on proactive insider risk detection and mitigation.
- Global Customer Service Securityβs CSIRT, strengthening Amazonβs ability to rapidly detect, investigate, and respond to security incidents at scale.
- Proactive Security Operations (PSO), a Purple Team bridging blue and red team functions, specializing in threat hunting, intelligence analysis, and adversarial emulation.
- Threat Operations for Amazon Global Customer Service Security, overseeing 50+ engineers and analysts across incident response, automation, red teaming, and legal support functions.
Holds a patent in anomalous computer activity detection, demonstrating expertise in behavioral threat modeling, automation, and security innovation. Recognized as a SANS Holiday Hack Winner, excelling in offensive security techniques, exploit development, and adversary simulation. Passionate about building and leading high-performance security teams, driving offensive security research, and enhancing enterprise security resilience through automation and strategic threat management.
Professional Skills
Leadership & Management Skills
- Security Team Development & Leadership β Built and led multiple high-impact security teams, scaling teams up to 50+ engineers and analysts.
- Strategic Security Program Development β Designed and executed large-scale security programs for incident response, adversarial emulation, and insider threat detection across Amazonβs global enterprise.
- Cross-Functional Collaboration β Partnered with engineering, legal, HR, and executive leadership to drive security initiatives and influence key stakeholders.
- Threat-Informed Defense & Security Automation β Integrated threat intelligence, red teaming, and security automation to proactively improve security posture.
- Crisis Management & Incident Command β Managed high-severity security incidents, ensuring rapid containment, forensic investigation, and mitigation.
Offensive Security & Adversarial Emulation
- Penetration Testing & Red Team Operations β Extensive experience in web, mobile, network, cloud, and infrastructure security testing.
- Purple Team Operations β Developed and led Proactive Security Operations (PSO), a hybrid red/blue team, conducting threat hunting, adversary emulation, and security gap analysis.
- Threat Intelligence & Attack Simulation β Designed and executed covert and overt security assessments, leveraging real-world attacker TTPs.
- Insider Threat Detection & Digital Forensics β Built Amazonβs first Insider Threat Prevention program, implementing automated behavioral anomaly detection and forensic analysis.
- Exploitation Techniques & Security Research β Recognized as a SANS Holiday Hack Winner, demonstrating expertise in reverse engineering, exploit development, and adversary simulation.
Security Engineering Skills
- Cloud Security & AWS Security β Deep expertise in AWS security architecture, IAM hardening, and securing cloud-native applications.
- Security Automation & Tool Development β Developed custom security tooling for forensic evidence collection and automated security response in Python.
- Threat Modeling & Risk-Based Security β Conducted threat modeling, secure architecture reviews, and risk-based security testing.
- Vulnerability Research & Zero-Day Discovery β Experienced in reverse engineering, fuzzing, and exploit development for high-impact vulnerabilities.
- Adversary Tactics, Techniques & Procedures (TTPs) β Strong knowledge of MITRE ATT&CK framework, red team methodologies, and advanced attack simulation.
Certifications & Recognitions
- GIAC Certified Incident Handler (GCIH) β Certified in incident handling, adversary tactics, and intrusion detection.
- Patent in Anomalous Computer Activity Detection β Developed machine learning-based threat detection models.
- SANS Holiday Hack Winner β Recognized for offensive security expertise, red teaming, and complex vulnerability exploitation.
Professional Experience
Amazon Stores Security - Multiple Positions
Amazon β Manager, Security Engineer, Proactive Security Operations
π Amazon Global Customer Service Security | π 12/2024 β Present
- Founded and led Proactive Security Operations (PSO), a specialized purple team bridging blue and red team functions.
- Designed and implemented adversarial emulation frameworks, combining threat hunting, intelligence analysis, and covert/overt offensive testing.
- Led high-impact security assessments, including simulated adversary engagements, breach attack simulations, and custom exploit development.
- Developed custom automation and tooling to enhance continuous security monitoring and proactive threat detection.
Amazon β Manager, Security Engineer, Threat Operations
π Amazon Global Customer Service Security | π 12/2022 β 12/2024
- Spearheaded security initiatives, reducing incident response triage times by 96% (from 52 days to 2 days).
- Led and managed four security teams across threat operations, incident response, red teaming, legal, and data protection.
- Focused on building an inclusive, high-performance security organization, fostering innovation and operational efficiency.
Amazon β Manager, Security Engineer, CSIRT
π Amazon Global Customer Service Security | π 7/2021 β 12/2022
- Established and led a new incident response team, improving Amazonβs global customer service security.
- Developed tactical incident response protocols, enabling rapid detection and mitigation of security threats.
Amazon β Security Engineer, Insider Threat Prevention
π Amazon Security Operations Center | π 12/2019 β 7/2021
- Built Amazonβs first Insider Threat Prevention program, integrating behavioral anomaly detection and forensic analysis.
- Developed custom covert forensic collection tools in Python, enhancing real-time threat identification.
Amazon β Security Engineer, Security Incident Response Team (SIRT)
π Amazon Security Operations Center | π 12/2018 β 12/2019
- Investigated and remediated high-severity security incidents, including malware containment, AWS service takeovers, and exposed data breaches.
TMC Healthcare β Senior Security Engineer
π TMC Healthcare | π 2011 β 2018
- Established and built TMCβs first formal information security program.
- Conducted penetration tests and developed HIPAA-compliant security policies.
- Led incident response and deployed security controls across medical systems and applications.
Sunquest Information Systems β Senior Network Security Engineer
π Sunquest Information Systems | π 2009 β 2011
- Designed and maintained secure network infrastructure for a global healthcare software company.
- Ensured HIPAA compliance and conducted vulnerability assessments.
- Integrated security best practices into application and network design.
Patents & Publications
- Patent: Anomalous Computer Activity Detection and Prevention (US 12058157)
- Publication: Protecting Healthcare Data (SANS Secure the Human 2015)
Honors & Awards
- π SANS Holiday Hack Winner β Most Creative (2014)
- π SANS Holiday Hack Super Honorable Mention (2016, 2017)
Relevant Volunteer Work
- 𧩠Neurodivergent Career Mentor
- ποΈ Transitioning Military Mentor
- π Counter Hack Challenges: CTF Game Contributor & Artist (2016, 2017)
- π» Microsoft TEALS Volunteer Computer Science Teacher
- π οΈ Amazon CTF Builder & Tester for ZonCon internal Security Conference (2019)
Military Experience
United States Army β Specialist, 31R Multichannel Transmission Systems Operator
π 1995 β 1999
- Operated and secured high-frequency (HF) and very-high-frequency (VHF) multichannel transmission systems.
- Led Quick Reaction Force (QRF), developing early leadership skills in site defense and response operations.
Education & Certifications
π SANS SEC-660, SEC-642, SEC-560, SEC-504, SEC-575, FOR-500
π AWS Certified β Architecting on AWS, AWS Cloud Practitioner
π GIAC Certified Incident Handler (GCIH)