The Team

25 years.
One practitioner.
AI-augmented.

Keser Security Operations is a practitioner-founded firm. The person who takes your call, runs your assessment, and manages your network is the same person who built the platform, has been doing this work since 2001 — and uses AI tools every day to move faster and see more than any one practitioner could before.


Paul Keser
▣ Founder

Paul Keser

Information Security · SecOps · IR · Detection Engineering



Credentials
▣ CISSP: Certified Information Systems Security Professional
▣ AWS Certified Security: Specialty
▣ AWS Certified Solutions Architect: Associate
▣ AWS Generative AI Security
▣ PCI-DSS Internal Security Assessor (ISA)
▣ NASA Certified Cyber Security Expert

Education
MS, Information Assurance / Network Security
Capitol Technology University
BA, Business Administration
Augustana College
Background

Built on production experience,
not certification theory.

I started in security in 2001 at NASA Ames Research Center, managing firewall and network security infrastructure for research and supercomputing environments. From there I joined Stanford University, first as Senior Network Security Engineer, deploying and managing the campus-wide Netscreen firewall infrastructure, then advancing to Associate Information Security Officer: digital forensics, investigations, and incident response for critical university systems, including coordination with law enforcement.

The next decade ran through Pandora Media (built and led the enterprise IR program; PCI Internal Security Assessor), PIX System (AWS security monitoring built from scratch), and Spin - Electric Scooter Sharing (DevSecOps operations across cloud infrastructure, SOC 2 audit readiness).

At Amazon Web Services I was an Incident Responder on the AWS Customer Incident Response Team (CIRT), leading response for customer security events including identity compromise, ransomware, malware, and data exposure. Working directly from identity, endpoint, and cloud telemetry to reconstruct events and drive containment. I authored incident response and forensic playbooks used globally by AWS teams and customers.

Most recently I led security operations and incident response at Couchbase, architecting a transition from SIEM to MDR and security data lake models, and maintaining control alignment across SOC 2 and ISO 27001.

The platform underlying every Keser Security Operations service started as my own infrastructure: Zeek for traffic analysis, RITA for beacon detection, Falco for runtime security, Tailscale for zero-trust mesh networking, DuckDB and Parquet for telemetry analytics. I built it to solve a real problem — how do you run enterprise-grade security operations on your own hardware, with open-source tooling, when you're the only practitioner? KeserNet is that answer, available as a managed service.

I'm also an active, daily practitioner of AI tools — the same ones your team is using. That's not incidental. It means I understand AI risk from both sides: as a security professional who has to defend against AI-powered threats, and as an operator who uses AI to investigate faster, find patterns at scale, and build things that would have taken weeks before. The AWS Generative AI Security credential reflects that work. The AI Security Assessment reflects what I built from it.


Career

Where the experience came from.

Period Organization Role What I did there
2001 – 2005 NASA Ames
Research Center
Sr. Network Security Engineer Firewall and network security for research and supercomputing. Vulnerability assessment, forensic networks.
2005 – 2010 Stanford University Sr. Network Security Engineer → AISO Campus-wide Netscreen firewall deployment and management, then promoted to Associate Information Security Officer: forensics, investigations, IR, law enforcement coordination.
2014 – 2018 Pandora Media Data Security Manager Built enterprise IR program. PCI Internal Security Assessor. Led Ticketfly subsidiary into PCI compliance.
2018 – 2019 PIX System Cloud Security Architect Built AWS security monitoring from scratch. Cloud IR procedures, forensic workflows, ISO 27001.
2020 – 2022 Spin - Electric Scooter Sharing DevSecOps Manager Security operations, detection, and vulnerability management across cloud. SOC 2 audit readiness.
2022 – 2024 Amazon Web Services Incident Responder, CIRT Customer IR across AWS: identity compromise, ransomware, malware, data exposure. Global playbook author.
2024 – 2025 Couchbase SecOps & IR Manager SIEM → MDR + data lake transition. SOC 2 and ISO 27001 alignment. Telemetry pipeline architecture.
Dec 2025 – Present Keser Security Operations Founder AI Security Assessments, Security Monitoring Assessments, fractional SecOps, and KeserNet managed private networking. 25 years of SecOps, now AI-augmented.

Why It Matters

What 25 years actually buys you.

▣ Pattern recognition

Seen it before

When you've run IR for AWS customers across hundreds of incidents (ransomware, identity compromise, insider threat) you recognize the early signals. Pattern recognition is not something you can buy with a tool or a framework.

▣ Practitioner judgment

Knows what matters

Findings are easy to generate. Prioritizing them is the skill. After decades of post-incident analysis, vulnerability management, and remediation work, the judgment of what to fix first and why is grounded in what actually gets exploited.

▣ Built, not bought

Platform credibility

Every tool in the Keser Security Operations stack is one I've built with, broken, fixed, and operated in production. When I recommend a detection approach or network architecture, it's because I've run it, not because the vendor told me to.

▣ Dual fluency

AI defender + AI user

I use AI tools every day — the same ones your employees are using. I understand the risk from both sides: the security professional defending against AI-powered threats, and the practitioner who knows what these tools actually do with your data. That's not a common combination.


Work Together

You'll talk to the person
who does the work.

No account managers, no handoffs. Start with a conversation.

Get in Touch