Cybersecurity architect · Security engineering leader · Author · Educator
I am Lester E. Nichols III, a cybersecurity architect with more than 25 years across security, infrastructure, networking, cloud, applications, and technology leadership. I hold an MS in Information Assurance as well as CISSP and GIAC certifications.
My work starts where diagrams and control language meet real systems. I publish deployable examples, sanitized reference architectures, detection content, and reusable automation for people who need to design, build, operate, and defend an enterprise.
| 🏗️ Architecture Security architecture, threat modeling, control design, cloud, network, application, and platform security. |
🛡️ Security operations SIEM, detection engineering, threat intelligence, vulnerability management, SOAR, DFIR, and telemetry pipelines. |
⚙️ Engineering DevSecOps, infrastructure as code, Linux, Windows, automation, and AI agent workflows for technical teams. |
Cybersecurity Architect's Handbook, Second Edition
An architect's guide to designing, building, and defending the modern enterprise. Published by Packt in 2026, it connects architecture principles to the technical, organizational, and leadership decisions that shape a working security program.
Read about the book at secdoc.tech · Get it on Amazon
| Project | What it gives you |
|---|---|
| SOC Pipeline | An end-to-end, IaC-deployed security operations pipeline that correlates network, DNS, endpoint, identity, and vulnerability telemetry, with AI enrichment, SOAR, and DFIR workflows. |
| DevSecOps Pipeline | A sanitized, buildable reference for a self-hosted delivery plane that isolates untrusted builds, validates source and dependencies, produces SBOM and policy evidence, and promotes immutable artifacts. |
| AI Agent Skills | Practitioner-built skills for cybersecurity architecture, threat modeling, application and code security, networking, Linux, Windows, firewall engineering, and executive reporting. |
| WAF to SIEM | A first-class WAF detection lane from Caddy, Coraza, and OWASP CRS into Wazuh and Graylog, including collection, normalization, detections, and dashboards. |
| Greenbone to Wazuh and Graylog | A read-only Greenbone/OpenVAS collector with normalized vulnerability findings, Wazuh rules, and dashboard content. |
| Technitium to Wazuh and Graylog | DNS query telemetry, enrichment, and detections for blocking, NXDOMAIN activity, DGA behavior, and tunneling signals. |
Security operations architecture and integrations
- soc-pipeline-public: Sanitized, adaptable, end-to-end security operations architecture deployed with Terraform and Ansible.
- socfortress-waf-siem: SOCFortress WAF telemetry collection, normalization, detections, and dashboards for Wazuh and Graylog.
- greenbone-wazuh-graylog: Read-only Greenbone/OpenVAS findings integrated with Wazuh and Graylog.
- technitium-wazuh-graylog: Technitium DNS telemetry, enrichment, and behavioral detection content.
- wazuh-unifi-detections: Custom Wazuh decoders, rules, MITRE ATT&CK mappings, and dashboards for UniFi gateway logs.
Graylog and network telemetry
- Graylog_Dashboards: Dashboards for DHCP, Maltrail, NAXSI, NetFlow, OPNsense, DNS, Suricata, and Zenarmor telemetry.
- Graylog_Inputs: Reusable Graylog inputs and parsers for network and security data sources.
- Graylog_Pipeline: Pipeline rules for normalizing and processing network and security events.
- OPNsense-24.7-Graylog-Grok-Patterns: Grok patterns, pipelines, content packs, and dashboards for OPNsense filterlog and Suricata data.
- Unifi-Graylog-Grok-Patterns: Grok patterns and pipeline rules for UniFi Network CEF events.
Detection content, automation, and professional resources
- custom_suricata_rules: Custom Suricata IDS and IPS rules for additional protocol and traffic visibility.
- whois_search: A shell utility that performs WHOIS lookups from an IP address list and writes a report.
- AI-Agent-Skills: Reusable AI agent skills built for technical security and architecture work.
- Recommended_Reading: A maintained reading list for security, networking, operating systems, software development, AI, leadership, and technical careers.
- Practitioner-built: useful to engineers and architects doing the work.
- Sanitized by design: public examples do not disclose private environments or operational secrets.
- Tradeoffs included: architecture without constraints and failure modes is incomplete.
- Built for reuse: configurations, detections, runbooks, and reference patterns should be adaptable.
More writing and architecture at secdoc.tech
Code and configuration are licensed under Apache License 2.0. Documentation, guides, and diagrams are licensed under CC BY 4.0. Attribution is required. See LICENSING.md and NOTICE.
GitLab CI validates tracked JSON, Python, and shell syntax, then runs a network-independent high-confidence secret scan across full Git history. The public pipeline contains no private registry, runner, credential, CA, or internal-domain reference.
