Incident response leadership · Securing the future of cyber with AI · Building new things and ideas every day

Eric Kelly

CSIRT Director at U.S. Bank. One of about 300 GIAC Security Experts in the world. I lead the response, stay for the technical details, and take an AI-first pass at how the SOC works.

Portrait of Eric Kelly
Portrait erickel.ly

Scroll the dossier

GIAC Security Expert

GSE #0

DoD bug bounty

Hack the Pentagon

Service

U.S. Army veteran

Current

CSIRT Director

Selected work

01 / Career

01

Dec 2019 — Present

CSIRT leadership at a Fortune 500 bank

U.S. Bank · Remote · Illinois

Technical lead for incident response at a large U.S. bank. First chair on DDoS, credential stuffing, phishing, malware, and multi-cloud incidents spanning Microsoft 365, AWS, Azure, and GCP.

Built IR capability in AWS and the playbooks that sit beside it. Lead SOC quality with an AI-first approach. Defensive lead in peer-bank cyber competitions. IR technical lead when the red team comes through the door.

  • Incident response
  • Multi-cloud
  • SOC quality
  • Red team

02

May 2016 — Dec 2019

Hunt methodology, then the detections to match

Discover Financial Services · Riverwoods, Illinois

Progressed from SOC analyst to hunt and adversary-simulation lead. Designed a structured methodology for proactive hunts. Mapped alerting and telemetry to MITRE ATT&CK so coverage gaps were visible, not guessed.

Built an in-house tool for EDR signature operations. Wrote detection logic against database activity monitoring across Oracle, SQL Server, and DB2.

  • Threat hunting
  • ATT&CK
  • EDR
  • Detection engineering

03

Feb 2017 — 2022

Vetted red team, including Hack the Pentagon

Synack · Remote

Vetted red-team operator. Hack the Pentagon live events with Synack: 2018 at the Pentagon in Washington, D.C., 2019 in Las Vegas. Critical findings across web, hardware, host, mobile, and IoT — the kind you report, not the kind you tweet.

  • Bug bounty
  • Red team
  • IoT

Training

04 / Courses

01

Aug 5–6, 2023

Black Hat Machine Learning

NVIDIA AI Red Team · Black Hat USA · Las Vegas

Two-day course taught by NVIDIA’s AI Red Team. Jupyter labs on attacking machine-learning systems: evasion, model extraction, inversion, membership inference, dataset poisoning, and the same classes of attack against large language models.

02

Oct 16–19, 2018

Adversary Tactics: Detection (AT:D)

SpecterOps Summit · San Antonio

Inaugural four-day course. Built TTP-based hunt hypotheses against MITRE ATT&CK, then hunted live post-exploitation with Sysmon, ELK/HELK, ACE, and host baselining — the kind of adversary behavior signature tools miss.

About

05 / Operator

I run incident response like a craft: fast when it has to be, careful when it matters, and allergic to theater.

GIAC Security Expert #204 — one of about 300 worldwide. Army veteran, combat deployment OIF 06–07, NCO Academy leadership award at Fort Campbell. I still like the packet more than the slide.

GIAC

GSE #204
GSP #170
GX-IH #170
GX-IA #170
GX-CS #170
GREM #6405
GCFA #13296
GCWN #3373
GCIA #11629
GWAPT #5262
GSEC #37418
GCIH #25611
GFACT #8120

Microsoft

AZ-900 Azure Fundamentals
AI-900 Azure AI Fundamentals
AI-102 Azure AI Engineer Associate
Verify on GIAC →