Summary
Overview
Work History
Education
Skills
Accomplishments
Certification
Timeline
Generic

Alexander Longo

Summary

Detail-oriented cybersecurity professional, with a drive for everything cybersecurity has to offer. With a Masters and Bachelors in Cybersecurity and Information Assurance and nearing 3 years of experience working in IT, my goal is to leverage my expertise in cybersecurity to be a valuable team member for an innovative organization that values continuous improvement and professional development.

Overview

2
2
years of professional experience
1
1
Certification

Work History

Penetration Tester / Incident Response Handler

CyberForce|Q
03.2023 - 03.2024

- Worked as part of an internal team that exclusively performs penetration testing, incident response, vulnerability scanning, OSINT investigations, and Tier 3.

- Led and assisted in penetration tests of all types, including internal, external, physical, web app, and social engineering.

- Discovered a previously unknown CVE (zero-day exploit) in an externally-facing production environment for a penetration test client in the government sector.

- Proficient in Python, Powershell, SQL, Bash, PHP, Burp Suite, OWASP ZAP, SQLmap, Hydra, Nmap, Responder, Metasploit, Nikto, John the Ripper, Bloodhound, PowerView, CrackMapExec, Rubeus, Mimikatz, Nikto, Kali Linux, and many other pentesting tools.

- Deploy custom scripts to aid in pentesting and incident response using Python, Powershell, and Bash.

- Experience in leading multiple incident response engagements for companies in healthcare, business, government, education, and security sectors.

- Conducted an independent technical review and penetration test of many large-scale corporate networks as well as created and authorized the final reports.

- Deployed, managed, and performed in-depth investigations in popular EDR platforms such as Crowdstrike, Defender, and FortiEDR.

- Experienced in writing event search queries for Splunk, Crowdstrike, Elasticsearch, Defender, and FortiNet.

- Used digital forensics tools (Autopsy, FTK imager, etc.) to recover data, investigate ransomware attacks, and more.

Event Response Analyst

CyberForce|Q
01.2024 - 03.2024

-Triaged alerts coming into the SOC at Tier 1.

-Escalated true positives to Tier 2 for further investigation and remediation. Worked in a multitude of cybersecurity technologies to assist in alert triage and investigation.

-Worked in an internal DevOps team to automate playbooks for incoming alerts.

Cybersecurity Analyst

CyberForce|Q
03.2022 - 03.2023

-Made use of popular firewalls, EDRs, SIEMs, and other tools to assist in investigation and remediation of alerts.

-Maintained regular contact with InfoSec teams in healthcare, government, education, security, and private business sectors.

-Experience in writing custom Python scripts for automation and general software development tasks.

Education

Master of Science - Cybersecurity and Information Assurance

Western Governors University
Salt Lake City, Utah
04-2023

Bachelor of Science - Cybersecurity and Information Assurance

Western Governors University
Salt Lake City, Utah
12-2021

Skills

  • Threat Hunting
  • Python
  • Linux
  • Network Security
  • Incident Response
  • Security Analysis
  • Document Creation
  • Team Management
  • Penetration Testing

Accomplishments

CVE-2024-25327 National Institute of Science and Technology March 2024

Cross Site Scripting (XSS) vulnerability in Justice Systems FullCourt  Enterprise v.8.2 allows a remote attacker to execute arbitrary code via  the formatCaseNumber parameter of the Citation search function.


Top 1% on TryHackMe TryHackMe

Certification

Pentest+ CompTIA


A+ CompTIA


CySA+ CompTIA


Certified Ethical Hacker (CEH) EC-Council


CCNA Cisco


Security+ CompTIA


Network+ CompTIA


Project+ CompTIA

Timeline

Event Response Analyst

CyberForce|Q
01.2024 - 03.2024

Penetration Tester / Incident Response Handler

CyberForce|Q
03.2023 - 03.2024

Cybersecurity Analyst

CyberForce|Q
03.2022 - 03.2023

Master of Science - Cybersecurity and Information Assurance

Western Governors University

Bachelor of Science - Cybersecurity and Information Assurance

Western Governors University
Alexander Longo