Summary
Overview
Work History
Education
Skills
Certification
Projects
Timeline
Generic

Alan Ledesma

Chicago,IL

Summary

Security Engineer with experience in endpoint detection and response (EDR), incident response, identity security, email security engineering, and vulnerability management. Leads investigations into phishing, business email compromise, and account compromise incidents while supporting internal, external, and web application penetration testing engagements. Designs and advises on Microsoft Entra security hardening, Conditional Access, MFA enforcement, and risk mitigation strategy. Combines offensive security expertise with defensive operations to improve enterprise security posture and reduce organizational attack surface.

Overview

1
1
Certification
2
2
years of professional experience

Work History

Security Engineer

Proven IT
05.2025 - Current
  • Engineer and improve enterprise email security controls through the implementation and administration of ProofPoint, Sublime Security, and KnowBe4, reducing phishing risk and strengthening organizational defense against email-based threats.
  • Investigate and triage endpoint, identity, and cloud security alerts within CrowdStrike Falcon and Microsoft Entra, performing analysis, containment, remediation, and escalation of security incidents.
  • Managed incident response cases, including phishing, account compromise, and business email compromise (BEC) investigations, conducting mailbox scoping, log analysis, credential resets, and account hardening activities to strengthen organizational security posture.
  • Scope and support internal, external, and web application penetration testing engagements, assisting with vulnerability validation, attack surface analysis, and client-facing reporting.
  • Advised clients on Microsoft Entra and Microsoft 365 security hardening, focusing on Conditional Access policy design, MFA enforcement, identity protection, and access control best practices to enhance overall security framework.
  • Completed cybersecurity insurance assessments, security questionnaires, and risk evaluations to align client environments with security, compliance, and cyber insurance requirements, supporting risk mitigation efforts.

Cybersecurity Specialist

Preferred Communications Systems
09.2024 - 04.2025
  • Investigated and responded to security alerts across endpoint and network environments, performing threat analysis and coordinating remediation efforts to enhance compliance.
  • Conducted vulnerability and risk assessments to identify critical exposures, prioritizing remediation and implementing manual and automated strategies to strengthen client system security.

Education

Bachelor of Science - Information Technology

Governors State University
University Park, IL
05-2027

Associate of Applied Science - Information Technology

Prairie State College
Chicago Heights, IL
03-2023

Associate of Science - Kinesiology

Prairie State College
Chicago Heights, IL
03-2013

Skills

Security operations: CrowdStrike, Microsoft Entra, Incident response and identity management

Offensive security: Burp Suite, Cobalt Strike,

Active Directory exploitation

Vulnerability management: Nessus risk prioritization and remediation

Programming and scripting: Python

Domains: Web application security and network security

Domains: Web Application Security, Network

Security

Certification

  • OffSec Certified Professional+ (OSCP+) - OffSec (09/2026 - 09/2029)
  • Hack The Box Certified Penetration Testing Specialist - Hack the Box (10/21/2024)
  • Hack The Box Certified Web Exploitation Specialist - Hack the Box (04/15/2025)
  • Red Team Operator - Zero-Point Security LTD (03/30/25)
  • CompTIA PenTest+ CompTIA (10/18/2025 - 10/18/2025)
  • CompTIA CySA+ - CompTIA (03/2025 - 03/2028)
  • CompTIA Security+ - CompTIA (06/2023 - 06/2026)

Projects

Bug Bounty & Security Research (Ongoing)

• Active security researcher on HackerOne, identifying web application vulnerabilities through manual testing and targeted exploitation techniques.

• Perform application-layer assessments using Burp Suite, custom payload development, and fuzzing methodologies to uncover logic and access control flaws.

Timeline

Security Engineer

Proven IT
05.2025 - Current

Cybersecurity Specialist

Preferred Communications Systems
09.2024 - 04.2025

Bachelor of Science - Information Technology

Governors State University

Associate of Applied Science - Information Technology

Prairie State College

Associate of Science - Kinesiology

Prairie State College
Alan Ledesma