Work Preference
Summary
Overview
Work History
Education
Skills
Certification
Clearances
Timeline
web
DAVID RUSSELL
Open To Work

DAVID RUSSELL

San Antonio,TX

Work Preference

Job Search Status

Open to work
Desired start date: Immediately

Desired Job Title

Subject Matter ExpertShift Lead Security AnalystCyber SOC Analyst Tier IIAdvanced Traffic Analyst

Work Type

Full TimeContract Work

Location Preference

On-SiteRemoteHybrid
Location: San Antonio, TX, US
Open to relocation: No

Salary Range

0/yr - 0/yr

Important To Me

Work-life balanceTeam Building / Company RetreatsPaid sick leavePaid time offWork from home optionHealthcare benefits

Summary

Results-oriented Cybersecurity SOC Analyst with over 20 years of expertise in threat detection, incident response, and security operations. Recognized for mentoring junior analysts, leading high-stakes incident response initiatives, and serving as a subject matter expert in various security tools and frameworks. Demonstrated success in reducing security risks and streamlining operations while effectively communicating complex security concepts to technical and non-technical stakeholders. Committed to enhancing organizational security posture through proactive measures and strategic insights.

Overview

20
20
years of professional experience

Work History

Subject Matter Expert

CACI
09.2024
  • Function as a subject matter expert regarding our analytical tools, processes, and procedures. Establish and implement new analytical and operational processes and procedures. Address analytical and technical escalations form the shift leads. Coach and mentor analysts of all skill levels throughout the task.

Shift Lead Security Analyst

CACI
09.2022 - 08.2024
  • Work with management to develop and deploy processes that seek to improve the overall function of Lackland CSOC. Be the lead on all training items. See that new hires receive training on all the tools and platforms currently in use. Ensure a smooth transition to your team. Direct the correlation of data from various sources (including potentially the SIEM, network traffic analyzer, PCAP data, open source data, etc.) in preparation for a potential Network Activity Report.

Cyber SOC Analyst Tier II

ASM Research
12.2021 - 08.2022
  • Responsible for 24/7/365 continued monitoring of Enterprise IT as a service (EITaaS) dashboards and intrusion detection and prevention systems (IDS/IPS). Performing initial analysis and investigation into alerts as they are seen (to include anti-virus and phishing alerts) using DEVO and XSOAR. Performing initial malware analysis utilizing automated means. Supporting cyber defense functions to protect our clients from cyber security incidents that have potential to cause negative impact. Also responsible for incident intake, ticket updates and reporting of cyber events.

Information Security Engineer/Analyst

CACI
10.2012 - 11.2021
  • Responsible for real-time monitoring of USAFCENT and USCENTCOM classified and unclassified information networks. Responds to threats against AFCENT/CENTCOM networks in a timely manner, blocks potential intruders and responds to other alerts that require immediate attention. Escalates events per AFCENT/USCENTCOM Standing Operating Procedures (SOPs). Creates suspicious event reports daily and QC's prior to release. Interacts with subject matter experts and network defense/information assurance personnel at the AFCENT NOSC and the Air Force Computer Emergency Response Team (AFCERT).

Advanced Traffic Analyst

Computer Science Corporation (CSC)
06.2011 - 09.2012
  • Correlates various data points using historical network traffic, operational events, reporting patterns, and other data to discern anomalies, patterns or trends. He analysis network connections “low and slow attacks” that are not seen by Real Time Analysis using various IDS and UNIX systems i.e.; (Fidelis, Splunk, CENTAUR and Noesis). He also investigates self-reporting incidents from outside agencies/bases and coordinates accordingly from within the 33 NWS/AFCERT.

ArcSight Instructor

MacAulay Brown Inc.
10.2007 - 07.2009
  • Responsible for the research, development, editing, teaching, and maintaining comprehensive training materials for network management applications (IDS’s) and network attack and security tools (ArcSight). Developed and instructed approximately 20 ArcSight courses in support of the 33 Network Warfare Squadron (NWS). The course was a week in duration and introduced students how to and effectively perform the following hands-on tasks within ArcSight:
  • 1. Case building, editing and deleting
  • 2. Filters and Inline filters
  • 3. Create/Edit/Delete Public Active Channels and Personal Active Channels.
  • 4. The importance of the usage of rules and lists
  • 5. Understand the differences between basic events and correlated events.
  • 6. Dashboard creation and various reporting templates with ArcSight.
  • 7. Annotating Events
  • 8. Manipulate between the Navigation, Event and Inspect/Edit panels.
  • 9. Run IP and Whois queries.

Network Analyst (CITS) Block 30 Analyst

MacAulay Brown Inc.
12.2006 - 09.2007
  • Validates authorized and unauthorized activity on Air Force Networks through 16 AF Gateways using UNIX/Windows and IDS systems. He correlates suspicious activity across Major Air Force Commands providing documentation of reportable activity.

Education

High School -

Westfield High School
Houston, TX
05-1982

Skills

  • Cyber Security - Current - Advanced - 20 years
  • Strong analytical skills
  • Customer focus
  • Creative solutions
  • Training and mentoring
  • Teamwork and collaboration
  • Attention to detail
  • Multitasking

Certification

  • COMPTIA SECURITY+CE - SYSTEM SECURITY (COMP001009098831) - Acquired: 2015-05-24 - Expires: 2027-05-24
  • COMPTIA NETWORK+CE - NETWORKING PROFESSIONAL (COMP001009098831) - Acquired: 2015-05-24 - Expires: 2027-05-24
  • CEH - CERTIFIED ETHICAL HACKER (EC-COUNCIL- ECC75330228339) - Acquired: 2014-04-15 - Expires: 2029-04-30
  • COMPTIA A+ - (COMPTIA) - Acquired: 2014-01-25 - Expires: 2027-05-24
  • COMPTIA LINUX+ - NETWORKING PROFESSIONAL (COMP001009098831) - Acquired: 2014-01-25 - Expires: N/A
  • LPIC-1, LINUX PROFESSIONAL INSTITUTE CERTIFICATION JUNIOR LEVEL (LINUX) (LP1000305549) - Acquired: 2014-01-25 - Expires: 2019-01-25
  • GCIA - GIAC CERTIFIED INTRUSION ANALYST (GIAC - 6213) - Acquired: 2010-06-10 - Expires: 2018-06-30
  • ITIL-4 Foundation - Acquired: 2021-04-29 - Expires: N/A
  • ArcSight Instructor

Clearances

  • Level: TS-SCI
  • Agency: Not Available
  • Investigated: 2026-04-30
  • Expires: 2031-04-30
  • Polygraphed: N/A

Timeline

Subject Matter Expert

CACI
09.2024

Shift Lead Security Analyst

CACI
09.2022 - 08.2024

Cyber SOC Analyst Tier II

ASM Research
12.2021 - 08.2022

Information Security Engineer/Analyst

CACI
10.2012 - 11.2021

Advanced Traffic Analyst

Computer Science Corporation (CSC)
06.2011 - 09.2012

ArcSight Instructor

MacAulay Brown Inc.
10.2007 - 07.2009

Network Analyst (CITS) Block 30 Analyst

MacAulay Brown Inc.
12.2006 - 09.2007

High School -

Westfield High School