Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic
ANDREW SAMPSON

ANDREW SAMPSON

Houston,Texas

Summary

Aspiring SOC Analyst with four years of cybersecurity experience in education and practical projects. Proficient in risk analysis, threat detection, and incident response, with a strong foundation in cloud security and compliance frameworks. Demonstrated ability to apply secure software development principles across the SDLC.

Overview

1
1
Certification
2
2
years of professional experience

Work History

M.S. Cybersecurity and Information Insurance

Western Governers University
Salt Lake City, Utah
04.2025 - Current
  • Evaluated healthcare penetration-testing engagement across internal/external networks, workstations, internet-facing systems, endpoint security, Active Directory, ePHI, and payment-card environments; identified gaps in scope, testing boundaries, evidence handling, reporting, and operational safeguards to enhance overall security posture.
  • Developed penetration-testing recommendations aligned with NIST SP 800-115, PTES, HIPAA, PCI DSS, and OWASP, including rules of engagement, maintenance windows, stop conditions, escalation procedures, evidence retention, credential resets, and post-engagement cleanup.
  • Conducted cybersecurity risk analysis for healthcare environment, assessing least privilege, continuous monitoring, risk assessments, risk response, and Plans of Action & Milestones (POA&M); assigned risk based on potential impact to confidentiality, integrity, availability, and compliance.
  • Analyzed and secured a simulated Microsoft Azure IaaS environment supporting a 2,000+ employee organization operating across four data centers, with emphasis on regulatory compliance, cloud migration risks, access control, encryption, backups, and vulnerability management.
  • Applied secure software-development principles throughout the SDLC, incorporating security requirements, threat modeling, secure architecture, code review, static analysis, penetration testing, fuzzing, deployment hardening, logging, monitoring, and vulnerability remediation.

CompTIA & TryHackMe,

Hands-On Cybersecurity Labs
Houston, Texas
01.2025 - Current
  • Executed hands-on cybersecurity labs focusing on network reconnaissance, vulnerability identification, and log analysis to enhance practical skills.
  • Analyzed simulated security incidents and used evidence from logs, network traffic, alerts, and system activity to determine potential threats.
  • Utilized command-line and security tools to investigate systems and analyze technical output for threat detection.
  • Maintained updated knowledge through continuing education and advanced training.

Education

Master of Science - Cybersecurity and Information Assurance

Western Governors University
04-2025

Bachelor of Science - Health Sciences

Sam Houston State University
08-2020

Skills

  • Penetration testing
  • Vulnerability management
  • Risk analysis
  • Cloud security
  • Regulatory compliance
  • Secure software development
  • Incident response
  • Continuous monitoring
  • Network reconnaissance
  • Effective communication
  • Team building
  • Professional demeanor

Certification

  • ISC2 Certified in Cybersecurity (CC), CompTIA Security+, CompTIA CySA+, Google Cybersecurity Certificate, CompTIA Pen+

Timeline

M.S. Cybersecurity and Information Insurance

Western Governers University
04.2025 - Current

CompTIA & TryHackMe,

Hands-On Cybersecurity Labs
01.2025 - Current

Master of Science - Cybersecurity and Information Assurance

Western Governors University

Bachelor of Science - Health Sciences

Sam Houston State University
ANDREW SAMPSON