Summary
Greg Carson is a Threat Intelligence and Incident Response lead with 11 years of hands-on experience designing, implementing and running SOC capabilities for large enterprises, currently leading TI/IR at TMX Group in Toronto. He blends deep technical skills—incident response, memory and malware analysis, reverse engineering, and custom tooling in C/C++, Python and PowerShell—with program-level work such as TIP/EDR/BAS deployments, use-case development, threat hunting, and tabletop/social engineering exercises. Greg has a strong MSSP and consulting background from Herjavec Group where he built tooling, led large SIEM and managed-security engagements, and delivered offensive assessments and red/purple team activities. He’s as comfortable advising senior leadership on roadmaps and vendor selection as he is writing low-level Windows collectors and automations that ingest forensic data into Splunk. A pragmatic mentor and operator, he routinely bridges gaps between security engineering, SOC ops and IT to reduce operational risk and streamline intelligence-driven blocking.
11 years of coding experience
5 years of employment as a software developer
BIT, Specializations in Networking & IT Security, BIT, Specializations in Networking & IT Security at University of Ontario Institute of Technology