Nathan H.

Cyber Engineer Manager | Cybersecurity Practitioner | CrowdStrike · Splunk · SIEM · Tenable | CISSP | 16 Yrs Experience

Portland, Oregon Metropolitan Area

About

Cybersecurity practitioner with 16+ years in IT and 12+ in security — now bringing that real-world expertise to the vendor side. I've spent my career as the customer: deploying CrowdStrike Falcon in regulated environments, building SIEM programs from scratch with Splunk and Elastic, leading exposure management platform migrations, and driving incident response through high-stakes situations including nuclear energy infrastructure and election security. I know exactly what organizations struggle with because I've lived it firsthand. That practitioner depth is what makes a great Solutions Engineer, Technical Account Manager, or Professional Services Consultant — someone who can walk into a customer conversation, understand their environment, and translate platform capabilities into real business outcomes. What I bring to the vendor side: 12+ years deploying and operationalizing security platforms (CrowdStrike, Splunk, Elastic, Tenable); proven ability to communicate complex security concepts to both technical teams and executive leadership; experience mentoring and advising security professionals; and the credibility of CISSP + M.S. in MIS. If you're building a technical advisory or professional services team in cybersecurity, I'd love to connect. Key platforms: CrowdStrike Falcon · Splunk · Elastic SIEM · Tenable · Zero Trust Architecture · AWS · CIS Controls · NIST 800-53

Experience

  • Security Engineering Manager at Horizon3.ai
    Jun 2026 - Present · 2 mos

  • Security Operations Manager at Payscale
    Aug 2022 - May 2026 · 3 yrs 10 mos

    • Lead a 4-person SecOps team, driving security operations, incident response, and threat detection across enterprise environments. • Reduced time-to-detection (MTTD) by 40% through NG-SIEM optimization, improving log ingestion pipelines and alerting workflows. • Managed successful migration from Tenable Security Center to CrowdStrike Spotlight Exposure Management, improving vulnerability SLA visibility compliance. • Collaborated cross-functionally with DevOps, Infrastructure, CorpIT, and GRC to align security strategy with business objectives.

  • Cyber Security Advisor at Springboard
    Mar 2023 - Aug 2023 · 6 mos

    • Mentored students through an advanced cybersecurity curriculum, coaching on SIEM, incident response, vulnerability management, and governance. • Supported career readiness by conducting mock interviews, resume reviews, and personalized skill development plans. • Helped students achieve 100% certification completion rates and improve real-world security analysis capabilities.

  • Information Security Analyst 4 (Team Lead) at NuScale Power
    Aug 2020 - Aug 2022 · 2 yrs 1 mo

    • Directed security monitoring in a high-regulation nuclear energy environment with strict NIST 800-53 and SOX compliance. • Led CrowdStrike Falcon deployment to improve security and service reliability across a sensitive environment. • Led deployment of ElasticSearch & Kibana SIEM with advanced detection rules, resulting in a 70% reduction in threat detection gaps. • Managed enterprise vulnerability management program using Tenable Security Center, Nessus Agents, and Tenable.io, improving SLA adherence by 55%. • Designed third-party vendor risk assessment frameworks to enhance supply chain security posture. • Served as incident response lead, collaborating with federal agencies during coordinated detection efforts.

  • Senior Information Security Specialist at Oregon Secretary of State
    Apr 2018 - Jul 2020 · 2 yrs 4 mos

    • Led 2020 Election Security Program for Oregon, protecting statewide voter registration systems against foreign and domestic threats. • Partnered with CISA and CrowdStrike on a pilot deployment securing election infrastructure across the state. • Architected a Splunk-based detection and monitoring program, improving visibility into election-related threats by 65%. • Directed vulnerability scans, phishing simulations, and firewall tuning, reducing attack surface exposure.