matt@benko:/portfolio$ whoami

Matthew Benko

matt@benko:/portfolio$ ./capability --probe
  • [ OK ] email_defense.module — KnowBe4 Defend · Barracuda Gateway
  • [ OK ] identity_edge.module — Entra ID Conditional Access · MFA
  • [ OK ] secure_automation.module — PowerShell · Python

IT Security Engineer email security attack-surface reduction secure automation

80% phishing attack surface cut — Conditional Access, site-wide MFA & geolocking

70–90% malicious email volume removed — KnowBe4 Defend + Barracuda Gateway Defense

5,000+ enterprise risks migrated — zero data-integrity incidents

250+ employees trained — simulated phishing campaigns tailored by department

CEHCompTIA Network+CompTIA A+AWS CCPFCC KF8ACL

matt@benko:/portfolio$ cat summary.md

IT Security Engineer cutting attack surface with measured, verifiable results — 80% phishing-surface reduction, 70–90% fewer malicious emails, a 5,000-risk platform migration with zero data-integrity incidents. Hands-on across manufacturing, energy, and healthcare environments: identity and access management, EDR monitoring, email security, and enterprise risk governance. Ships secure automation in PowerShell and Python. CEH, CompTIA Network+, CompTIA A+, and AWS Certified Cloud Practitioner. Master of Science, Information Security & Intelligence (May 2026).

matt@benko:/portfolio$ ./skills --list --grouped

identity & access management [5]

  • Microsoft Entra ID / Azure AD
  • Active Directory (Server 2019)
  • Conditional Access
  • MFA / IAM
  • Microsoft 365 (Exchange, SharePoint, OneDrive)

endpoint & detection [4]

  • ESET Protect EDR
  • Endpoint Deployment
  • Imaging
  • Forensic Analysis

email security [5]

  • Barracuda Email Gateway
  • KnowBe4
  • VirusTotal
  • AnyRun
  • Security Awareness Training

network infrastructure [4]

  • VLAN Administration
  • Routing
  • Network Troubleshooting
  • CAT 5e/6 Cabling

governance & compliance [3]

  • Risk Management / GRC
  • Audit Support
  • Quality Assessment

scripting & automation [3]

  • Python Scripting
  • Automation
  • PowerShell

matt@benko:/portfolio$ tail -f experience.log

  1. IT Security Engineer

    Jan 2025 → Present

    Reed City Group — Reed City, MI

    • Cut phishing attack surfaces by 80% by deploying Microsoft Entra ID Conditional Access policies enforcing site-wide MFA, geolocking, session re-authentication, and third-party app restrictions
    • Removed malicious email volume by 70–90% through administration of KnowBe4 Defend Email Threat and Barracuda Email Gateway Defense systems
    • Orchestrated simulated phishing campaigns tailored by department, training 250+ employees on real-world attack tactics and techniques
    • Automated AD–KnowBe4 user synchronization, reducing manual compliance tracking by 10+ hours per quarter
    • Installed and terminated 2,000+ feet of CAT 5e/6 cabling, wireless cameras, and switches; configured VLANs and routing rules to segregate network segments
    • Drove migration of ~5,000 IT and infrastructure risks with zero data-integrity incidents  → detail under Consumers Energy, 2024

    Also: administered segregated Active Directory on Windows Server 2019 with role-based access controls aligned to Principle of Least Privilege · deployed and tuned ESET Protect EDR across endpoints for real-time threat detection, containment, and remediation · conducted forensic analysis of suspicious files and URLs using VirusTotal and AnyRun sandbox environments · managed Microsoft 365 (Exchange, SharePoint, OneDrive) for 250+ employees with Exchange mail-flow troubleshooting · partnered with Pathfinders IT Managed Service Provider on quarterly security audits · delivered daily technical support across endpoints, mobile, printers, network shares, and file access on the manufacturing floor.

  2. CX&T Security Intern — GRC Team

    May 2024 → Jan 2025

    Consumers Energy — Jackson, MI

    • Drove transition of enterprise risk management systems, migrating ~5,000 IT and infrastructure risks with zero data integrity incidents
    • Partnered with networking, systems, and application teams to identify and document risks during project planning, surfacing gaps before deployment
    • Gained hands-on exposure to utility-scale IT environments supporting 24/7 uptime and strict regulatory standards
  3. Senior Information Technology Extern

    May 2022 → Aug 2022

    Hurley Medical Center — Flint, MI

    • Resolved 300+ IT service tickets in a high-availability healthcare environment, maintaining clinician uptime and minimizing disruption to patient care
    • Imaged, configured, and deployed 20+ computers with full provisioning from OS installation through domain join and user handoff
    • Mentored 2 incoming IT externs on ticket workflows, troubleshooting procedures, and IT best practices, accelerating their time-to-productivity

    Also: coordinated project deliverables across networking, systems administration, biomed, database management, and application analysis teams · presented project progress and operational updates to the IT team during regular meetings

  4. Information Technology Extern

    Jun 2021 → Aug 2021

    Hurley Medical Center — Flint, MI

    • Delivered first-level support via Ticket+, resolving Wi-Fi connectivity, switch port, workstation, and hardware issues in a 24/7 healthcare environment
    • Collaborated with cross-functional IT teams spanning networking, systems administration, biomed, database management, and application analysis
    • Participated in quality assessment and continuous improvement initiatives, contributing to higher service-desk efficiency metrics

matt@benko:/portfolio$ ls ~/projects --case-studies

VPS Security Hardening — Automated Server Lockdown

0 public inbound firewall rules — every allow rule scoped to the private mesh; public SSH disabled
problem
A personal cloud VPS running an AI gateway and LLM stack sat on the public internet with a default posture: public SSH, exposed services, no firewall policy. A single misconfigured daemon away from a compromise.
approach
Rebuilt the host around deny-by-default: UFW with every allow rule scoped exclusively to the mesh-VPN interface, public SSH listeners disabled, SSH hardened (MaxAuthTries, idle timeouts, AllowUsers restrictions), and fail2ban progressive-ban policies tuned. Daily config backups automated via cron with GitHub push for change tracking and disaster recovery.
result
0 public inbound firewall rules — every allow rule scoped to the private mesh, public SSH disabled. The hardened state is live and verifiable in the public report: before/after port scans, full service inventory, and rollback procedures.

constraint: locking SSH behind the mesh meant giving up the convenience of reaching the box from any network — the fix was accepting that friction as the design, not engineering around it.

stack: UFW · fail2ban · Tailscale · Ubuntu 24.04

open github.com/BenkoMatt/VPS-Security-Hardening-Report

Cybersecurity Frameworks Guide

4 frameworks one public reference guide — used by peers studying for security certifications
problem
NIST CSF, ISO 27001, CIS Controls, and MITRE ATT&CK each assume prior fluency; newcomers studying for security certifications face four dense, overlapping frameworks with no Rosetta stone.
approach
Authored a public reference guide mapping the four frameworks against each other — what each controls, where they overlap, and how they slot into a working security program.
result
A public reference guide used by peers studying for security certifications.

constraint: published knowing the frameworks will drift — keeping a mapping current is a maintenance commitment, not a one-time write.

stack: Technical Writing · NIST CSF · ISO 27001 · CIS Controls · MITRE ATT&CK

open github.com/BenkoMatt/Claw-Framework-Report

Active Directory Cleanup Automation

repeatable stale AD objects surfaced and audited on a repeatable schedule
problem
Stale AD objects — departed users, decommissioned computers — accumulate silently and widen the attack surface; at production scale the audit is unmanageable by hand.
approach
Built PowerShell scripts to audit stale AD users and computers and generate resulting reports — designed to run on a repeatable schedule, not as a one-off cleanup.
result
Stale AD objects surfaced and audited on a repeatable schedule.

constraint: the script surfaces candidates for cleanup; disabling or deleting accounts still gets a human review — automation narrows the queue, it doesn't own the decision.

stack: PowerShell · Active Directory · Reporting

open github.com/BenkoMatt/AD-OldObjects-Audit

YT2MP3 Station — YouTube Queue & MP3 Tools

1-click instant MP3 handoff plus a local yt-dlp command builder — zero stored media, zero accounts
problem
Public "YouTube → MP3" converters are ad-soaked, shady, and constantly get rate-limited or shut down — while GitHub Pages is static-only, so the obvious fix (host a real converter yourself there) is off the table.
approach
Built a fully client-side station: queue and playback via YouTube's official privacy embed, state in localStorage. Saving is split by honesty — an instant button hands the current video to the open-source cobalt.tools converter with the link prefilled, and a command builder emits a ready-to-run yt-dlp/ffmpeg one-liner for high-quality local extraction. Files are always created on the user's machine.
result
A live station at mattbenko.xyz/yt2mp3 with public source — watch and queue anywhere, two clean save paths, no tracking and nothing stored.

constraint: browser CORS walls mean a static page can never finish a conversion itself — "instant" is a prefilled handoff to cobalt.tools, and the page says so plainly instead of pretending.

stack: Static HTML/CSS/JS · yt-dlp · cobalt.tools · GitHub Pages

open mattbenko.xyz/yt2mp3 — the station open github.com/BenkoMatt/yt2mp3-demo

matt@benko:/portfolio$ openssl verify certs/*

Verified CompTIA A+ ce ID D72JQJ6YCME4QGCS verify on Credly → Verified CompTIA Network+ ce ID YS27STN64806HFSJ verify on Credly → Verified AWS Certified Cloud Practitioner ID 3a040b5349a3498686d2e38b5e66b9bc verify on Credly →
Verified EC-Council CEH ID ECC4916837250 verify via EC-Council — ID on request
Licensed FCC Amateur Radio Technician Call sign KF8ACL
Certified American Red Cross Adult First Aid/CPR/AED ID 01L9OOG

matt@benko:/portfolio$ ps aux | grep caddy

This site was designed, built, and QA'd by Caddy — a code-specialist AI agent running inside a multi-agent Hermes system on a private VPS. The rebuild you are reading ran as an adversarial workflow: parallel research agents, three competing design candidates, independent judge and refuter agents, and a human deploy gate. Every number in this section was pulled from the live system by the same fleet that built the page — the board queries, git history, and firewall state are the sources, recorded per fact. If the board counts shift, the agents recount at integration: the rebuild counted 24 live workflow cards across 6 phases on 2026-09-16.

7specialized agent profiles — role separation on one model fleet, least-privilege for agents

145documented skill modules across 38 categories

23scheduled operational jobs — security snapshots, watchers, reports

7.8 GiBRAM / 4 vCPU on the hardened VPS this runs on

0public inbound firewall rules — deny-by-default, fail2ban, mesh-only admin

9/9site commits authored by the agent — including an 8-commit favicon-iteration honesty record

Deep dive: the full architecture, and how this page was built

// host & perimeter

  • Everything runs on a single Contabo VPS (Ubuntu 24.04 LTS, 4 vCPU, 7.8 GiB RAM) inside a default-deny perimeter: UFW allows inbound only on the Tailscale mesh interface, fail2ban guards SSH, and the public site itself is static — served by GitHub Pages, with no app server exposed to exploit
  • This site itself ships as static files — no server-side code to exploit

// model fleet

  • A single open-weights GLM model (glm-5.3-flash) served via Ollama Cloud, uniformly deployed across seven agent profiles: orchestration, operations, research, review, security, webdev, and work
  • Differentiation comes from role separation and tooling — least-privilege for AI agents, like service accounts: reviewers are structurally independent from builders

// memory & orchestration

  • Honcho provides hybrid persistent memory — a compact peer card, semantic search over full message history, and a synthesized-reasoning layer, with hard character budgets that force curation over hoarding
  • A SQLite kanban board runs the task graph: dependency-gated cards, a dispatcher that promotes child tasks when parents complete, a 4-hour per-card cap and a 6-agent concurrency ceiling, and stale-run requeueing
  • Adversarial convergence: every QA claim must be atomic and located (file:line), independent refuter agents try to break each claim, and only claims that survive refutation get fixed — capped at three rounds
Caddy agent architecture internet / tailnet edge 0 public inbound kanban dispatcher gateway · 24 cards 7 profiles glm-5.3-flash 145 skills 38 categories honcho memory hybrid mode 23 cron jobs scheduled ops github pages deploy static hosting this site 1 file · 0 js Caddy agent architecture (stacked) internet / tailnet edge 0 public inbound rules kanban dispatcher gateway · 24 cards 7 profiles glm-5.3-flash 145 skills · honcho memory 38 categories · hybrid 23 cron jobs scheduled ops github pages deploy static hosting this site single file · no js

counts pulled live from the running system · 2026-09-16

Caddy runs on a Contabo VPS behind a Tailscale-only edge (zero public inbound rules). A kanban dispatcher schedules 24 live workflow cards across 7 glm-5.3-flash agent profiles, drawing on 145 skills (38 categories) and Honcho hybrid memory, with 23 cron jobs automating operations; pushes deploy through GitHub Pages to this site. (Full prose equivalent of the diagram above — same chain, node for node.)

// how this site was built — this workflow's real numbers

  • 24 live kanban cards in a single task graph across 6 phases — reconcile & baseline → parallel research → adversarial design convergence → build → adversarial QA convergence → deploy gate
  • 3 independent candidate designs built blind, in parallel, from three different creative briefs (58.4 / 48.2 / 58.7 KiB), scored by 3 adversarial judges (reviewer, security, research lenses) — 32 evidence files, 15 independently recomputed contrast pairs
  • Adversarial convergence throughout: every finding must be atomic and located (file:line); independent refuter agents try to break each claim; only claims that survive refutation get acted on — capped at 3 rounds. This run: 2 refutation rounds (design-judge, then QA-hunters with 2 independent refuters)
  • 5 agent profiles engaged (webdev builders ×3, reviewer / security / research judges, daily synthesis) — all on one open-weights GLM model via Ollama Cloud; differentiation comes from tooling and role separation, not a "smarter" model per role
  • 4 h per-card hard cap · 6 concurrent workers max · human deploy gate never waived
  • Honesty records kept: the previous site's favicon went through 8 small, dated, reversible commits (emoji → recenter → revert → satellite) — one visual change per commit; the record stands in the public git history

// honesty record

  • All 9 commits in this site's repository are authored by Caddy — including 8 favicon-iteration commits in a single day: small, dated, reversible changes, exactly how careful engineers work
  • Production deploys are never autonomous: the build blocks until the owner approves

matt@benko:/portfolio$ cat education.json

Master of Science — Information Security & Intelligence

Ferris State University — Big Rapids, MI

May 2026

Bachelor of Science — Information Security & Intelligence

Ferris State University — Big Rapids, MI

December 2024

Postgraduate Certificate: Business Intelligence / Incident Response / Information Systems Assurance, Strategy, & Governance
Minor: Artificial Intelligence & Penetration Testing