

Dynamic security-focused professional with over 6 years of experience in cybersecurity operations, technical support, and armed public safety. Adept in network traffic analysis, vulnerability management, malware investigation, and incident response. Former Special Police Officer (SGT) with a strong background in physical security, surveillance monitoring, access control, and emergency response. Experienced in technical support roles focusing on cloud platforms, Linux systems, Python scripting, Active Directory, Azure, and AWS environments. Proven ability to collaborate across teams, manage escalations, support project timelines, and implement cybersecurity best practices. Committed to continuous learning, proactive risk mitigation, and cross-functional communication to safeguard digital and physical assets.
GPA: 3.07
ServiceNow
Syslog
JIRA
Splunk
Tenable
Security Onion
CrowdStrike
Qualys
Nmap
Logrhythm
IBM QRadar
Monitored and Triaged 100+ Security Alerts Weekly
Used tools like Splunk and Microsoft Defender to review and respond to security alerts, escalating high-priority incidents per SOC playbooks.
Assisted in Investigating Phishing Attempts
Identified phishing indicators through email headers and URL analysis; contributed to incident reports and user awareness efforts.
Contributed to 24/7 Alert Coverage
Supported shift-based monitoring for a live production environment, helping maintain continuous threat detection and response.
Performed Basic Log Analysis Using SIEM Tools
Searched logs in Splunk and QRadar to investigate login anomalies, failed authentication attempts, and unusual network activity.
Documented and Escalated Potential Incidents
Maintained detailed notes and summaries of suspicious activity and collaborated with senior analysts during incident escalation. Participated in Internal Threat Hunting Exercises
Supported senior team members by gathering data, running IOC queries, and mapping findings to MITRE ATT&CK techniques.
Supported Vulnerability Scanning Reviews
Helped review and prioritize vulnerability scan results from Nessus/OpenVAS and tracked remediation tasks with team leads.
Utilized VirusTotal and AbuseIPDB for IOC Enrichment
Used free tools to enrich IPs and hashes for alerts, enhancing incident understanding and ticket quality.
Maintained 95%+ SLA Response Rate
Ensured timely response to tickets and incidents within expected service level agreements, even during peak alert periods.
Created SOP for Basic Alert Handling
Developed a simple Standard Operating Procedure (SOP) for new analysts to follow when triaging low-severity alerts.