AI Security Researcher / Security Engineer

Garrett Ennis

Building AI-assisted attackers, and the defenders that stop them.

About

Garrett Ennis

I am a master’s student and researcher at the SecAI Lab at Sungkyunkwan University (SKKU), and a security engineer by background. My work covers both sides of one problem: how AI assistance changes what an attacker can do at scale, and what a defender needs in order to keep pace. Before moving into research, I designed SOC architectures and SIEM ingestion pipelines for regulated environments. The limiting factor there was rarely detection logic. It was alert volume that no team could triage, which is the constraint my research starts from.

Experience

  1. AI Security Researcher, SecAI Lab, SKKU

    • Study how AI assistance changes adversary capability, and what detection has to do once reconnaissance and evasion are cheap to automate.
    • Evaluate where AI assistance lowers analyst load in a security operations center (SOC), and where it moves the bottleneck instead of removing it.
    • Research in progress, with no published results yet.
  2. Lead Security Engineer, SysArc

    • Led the security engineering and incident response team.
    • Directed threat hunting initiatives and cloud security operations across Azure and Microsoft 365 environments.
    • Delivered executive-level reporting and strategic security posture assessments.
  3. Security Engineer, SysArc

    • Helped enterprises and government contractors reach and maintain NIST 800-171 and CMMC compliance.
    • Designed and implemented enterprise SOC architectures for commercial and government contractor clients.
    • Engineered SIEM ingestion pipelines processing firewall, endpoint, and cloud telemetry; improved alert fidelity and reduced noise through structured normalization validation.
    • Wrote and tuned SIEM detection rules across endpoint, firewall, and cloud telemetry to expand attack coverage.
    • Managed the cybersecurity tool stack for the proactive services department.
  4. Software Engineer III, Cybersecurity (Pentest), Walmart Global Tech

    • Conducted enterprise application penetration testing for web and mobile platforms.
    • Scoped and ran assessments as the final gate in the application development cycle.
    • Developed structured threat models and collaborated with engineering teams to integrate secure SDLC controls.
    • Evaluated authentication, authorization, and input sanitization implementations in high-sensitivity environments.
  5. Earlier: Network Administrator, Blue Heron Systems

    Details on the résumé

Education

  1. M.S. Computer Science and Engineering (AI), Sungkyunkwan University (SKKU) 성균관대학교

    SecAI Lab. Research on AI-assisted defense and SOC automation.

  2. Microsoft Certified: Security Operations Analyst Associate (SC-200)

    Earned February 2024, expired February 2026. Verification page

  3. B.S. Computer Networks and Cybersecurity, University of Maryland Global Campus

    Completed after transferring credits from Anne Arundel Community College. Minor in East Asian Studies.

  4. Associate degrees, Cyber Security and Computer Networking, Anne Arundel Community College

    Dual degrees. Concentration in computer and information systems security and information assurance.

Research

Each area links to my reading list for it: peer-reviewed papers, linked to the publisher, none of them mine.

Projects

Radio

Tracks play from YouTube, so nothing loads from Google until you press play. The bar fields across the site follow whatever is playing.

Contact

I am looking for research collaborations and opportunities to present at conferences. If you work on AI-assisted defense, detection engineering, or SOC automation, I would like to hear from you.

Based in Suwon (수원), South Korea, with a home base in Maryland, USA. Send research and collaboration email to my SKKU address, and everything else, including recruiting, to my personal one.

Research and collaboration (SKKU)
redrobe9@g.skku.edu
Everything else (personal)
williamgarrettennis@gmail.com