I build security systems that show their work.

I'm Michael Rico, a Staff Threat Hunter building tools for threat intelligence, incident readiness, and detection engineering.

I turn noisy security data into decisions analysts can verify and leaders can act on, with the sources, evaluation boundaries, and operating history left visible.

About

I build security systems around a simple idea: a result is only useful when someone can inspect how it was produced. At SentinelOne, my work spans proactive threat hunting, detection engineering, automation, and analyst workflows for incident readiness and response.

The projects below apply that approach to threat research, security briefings, exploitation intelligence, and GRC reporting. Each one keeps the evidence visible and makes the next decision clearer.

See Michael Rico on GitHub for public code and project evidence.

  • Python
  • Go
  • TypeScript
  • PostgreSQL
  • AWS
  • LangGraph

Outside of work, I am interested in geopolitics, security research, and how technical systems shape real-world decisions.

Michael Rico Profile

Experience

SentinelOne

December 2024 — present

Staff Threat Hunter

  • Lead proactive threat hunts across incident readiness and response workflows, turning ambiguous signals into investigations teams can validate and communicate
  • Build detections and analyst-facing tooling that make supporting evidence and next actions easier to review

Uber

October 2023 — July 2024

Threat Detection Engineer II

  • Built detections across large-scale event and streaming data to surface high-signal security behavior
  • Combined multiple weak signals into higher-confidence alerting patterns for security operations

Dell Secureworks

August 2013 — August 2023

Information Security Researcher

  • Tracked threat actors and emerging techniques across a decade of security research
  • Translated research into deployable countermeasures that strengthened detection and response coverage

Selected work

SentrySearch

Threat Intelligence Research Workspace

For threat analysts who need research they can defend, SentrySearch turns malware, attack tools, and exposed technologies into source-backed reports with detection guidance, a persistent report library, and explicit evaluation status.

Built with Next.js, TypeScript, FastAPI, PostgreSQL, Supabase, AWS S3.

SentryDigest

Analyst-Ready Security Briefings

For analysts who need to know what changed without rereading every feed, SentryDigest publishes a scheduled three-hour briefing with source health, UTC freshness, retained history, and stable handoffs for review.

Built with Node.js, RSS, GitHub Actions.

SentryInsight

Exploitation Intelligence Reports

SentryInsight turns CVE and exploitation evidence into dated reports that connect affected systems, attack context, and response priorities. If a new run is not trustworthy, it preserves the last verified report.

Built with Python, LangGraph, Pydantic, OpenRouter.

GRCInsight

Audit-Ready GRC Intelligence

GRCInsight turns regulatory and security feeds into framework-mapped reports with evidence manifests and a visible publication history, so reviewers can see what was published, retained, or refused.

Built with Go, Python, AWS Lambda, DynamoDB, FastAPI.