I build security systems that show their work.

I'm Michael Rico, a Staff Threat Hunter focused on threat intelligence, incident readiness, and detection engineering.

My projects turn noisy signals into clear decisions, with the evidence, failure modes, and history left visible.

About

I am currently a Staff Threat Hunter at SentinelOne, working in ThreatOps on Incident Readiness and Response. My work sits at the intersection of threat hunting, detection engineering, automation, and analyst workflows.

See Michael Rico on GitHub for public code and project evidence.

  • Python
  • Go
  • TypeScript
  • PostgreSQL
  • AWS
  • LangGraph

Outside of work, I am interested in geopolitics, security research, and how technical systems shape real-world decisions.

Michael Rico Profile

Experience

SentinelOne

December 2024 — present

Staff Threat Hunter

  • Lead proactive threat hunting work across incident readiness and response workflows
  • Build tooling, detection logic, and analyst-facing systems that make threat activity easier to investigate, validate, and communicate

Uber

October 2023 — July 2024

Threat Detection Engineer II

  • Built and refined threat detections using large-scale data and real-time streaming systems
  • Combined multiple detection signals into higher-fidelity alerting patterns for security operations

Dell Secureworks

August 2013 — August 2023

Information Security Researcher

  • Tracked threat actors, analyzed anomalous activity, and identified emerging attack techniques
  • Wrote and deployed countermeasures quickly to improve detection and response coverage

Selected work

SentrySearch

Threat Intelligence Research Workspace

SentrySearch turns scattered threat research into source-backed security profiles with persistent reports, authenticated report-library search, detection guidance, and explicit evaluation status when a section could not be scored.

Built with Next.js, TypeScript, FastAPI, PostgreSQL, Supabase, AWS S3.

SentryDigest

Analyst-Ready Security Briefings

SentryDigest turns noisy security feeds into a scheduled three-hour briefing with UTC freshness, source health, retained issues, and stable handoffs you can inspect before sharing.

Built with Node.js, RSS, GitHub Actions.

SentryInsight

Exploitation Intelligence Reports

SentryInsight publishes exploitation-focused reports with CVE evidence, affected systems, dated archives, and fail-closed retention of the last verified report when a new run is not trustworthy.

Built with Python, LangGraph, Pydantic, OpenRouter.

GRCInsight

Audit-Ready GRC Intelligence

GRCInsight publishes audit-ready reports with framework mapping, evidence manifests, and a machine-readable outcome journal for published, retained, and refused runs.

Built with Go, Python, AWS Lambda, DynamoDB, FastAPI.