Summary
Overview
Work History
Education
Skills
Certification
Personal Information
Custom
Timeline
Generic

Mat O

Houston,TX

Summary

Results-driven Cybersecurity and Security Operations professional with 5+ years of experience in Security Operations Center (SOC) environments, incident response, threat detection, security monitoring, vulnerability management, and threat hunting across enterprise hybrid and cloud environments. Experienced in investigating and responding to security incidents involving phishing, Business Email Compromise (BEC), malware, suspicious authentication, account compromise, endpoint threats, and network-based attacks. Proven success reducing SIEM false positives by 30–45% and improving Mean Time to Respond (MTTR) by 25–35% through detection tuning, incident response playbooks, automation, and improved escalation workflows. Hands-on experience with Microsoft Sentinel, IBM QRadar, Splunk, Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Proofpoint, Microsoft Entra ID, Intune, Nessus, Qualys, Wireshark, and Nmap. Strong knowledge of NIST CSF, NIST SP 800-61, MITRE ATT&CK, Cyber Kill Chain, incident response, vulnerability management, threat intelligence, and security risk management.

Overview

1
1
Certification
6
6
years of professional experience

Work History

Cybersecurity / Incident Response Analyst

GOVERNMENT AGENCY
Houston, TX
12.2024 - Current
  • Monitor, analyze, prioritize, and respond to security alerts generated by SIEM, EDR, email security, identity, cloud, and network security platforms.
  • Triage and investigate 50–100+ security alerts and incidents weekly, including phishing, Business Email Compromise (BEC), malware, credential attacks, suspicious authentication, account compromise, typo-squatting, brand impersonation, and endpoint security events.
  • Perform security event correlation across multiple data sources to establish incident scope, identify affected users and systems, determine attack vectors, and assess business impact.
  • Reduced SIEM false-positive alerts by approximately 30–45% through correlation-rule tuning, detection logic refinement, threshold optimization, and analysis of recurring benign activity.
  • Improved Mean Time to Respond (MTTR) by 25–35% through developing and enhancing incident response playbooks, investigation procedures, automation, and escalation workflows.
  • Conduct end-to-end incident response activities encompassing identification, analysis, containment, eradication, recovery, and post-incident review in alignment with NIST SP 800-61.
  • Investigate phishing and BEC incidents using Proofpoint, including sender/domain analysis, malicious URL and attachment investigation, IOC identification, message tracing, mailbox impact analysis, and containment.
  • Perform proactive threat hunting and root cause analysis across endpoint, identity, network, and cloud environments using Microsoft Defender XDR, CrowdStrike Falcon, SIEM telemetry, and threat intelligence sources.
  • Investigate suspicious endpoint activity, malware detections, unauthorized processes, PowerShell activity, anomalous user behavior, and indicators of compromise.
  • Analyze authentication and identity-related events involving suspicious sign-ins, failed-login patterns, MFA events, privilege misuse, impossible travel, and potential account compromise.
  • Use Microsoft Entra ID, Microsoft 365, Azure, and Intune telemetry to investigate identity, device, and cloud security incidents.
  • Enrich security investigations using threat intelligence and IOC data involving malicious IP addresses, URLs, domains, file hashes, email senders, and other observable indicators.
  • Map attacker behavior and investigation findings to MITRE ATT&CK tactics and techniques to improve detection coverage and identify security control gaps.
  • Develop and maintain SOC investigation procedures, incident response playbooks, escalation procedures, and security operations documentation.
  • Coordinate incident containment and remediation activities with infrastructure, network, cloud, endpoint, identity, and application teams.
  • Review vulnerability findings from Nessus and Qualys, prioritize remediation based on severity, exploitability, asset criticality, and business impact, and track findings through closure.
  • Maintain and update the organizational cybersecurity risk register, documenting security risks, remediation activities, risk owners, and mitigation status.
  • Participate in Incident Response and Disaster Recovery (IR/DR) tabletop exercises, technical recovery testing, lessons-learned sessions, and security preparedness activities.
  • Collect, validate, and organize cybersecurity evidence supporting SOC 2 audits, risk assessments, compliance reviews, and internal security control testing.
  • Create detailed incident tickets documenting investigation timelines, evidence, affected assets, IOCs, containment actions, remediation recommendations, and final disposition.
  • Escalate high-severity incidents according to established SOC procedures and communicate actionable findings to technical teams and management.

SOC / Information Security Analyst

IBM
Houston, TX
03.2021 - 12.2024
  • Monitored and analyzed security events across enterprise SIEM, EDR, firewall, IDS/IPS, identity, endpoint, network, and cloud security platforms.
  • Performed Tier 1/Tier 2 SOC alert triage and incident investigation to distinguish true-positive security incidents from benign activity and false positives.
  • Analyzed multi-source SIEM logs to identify malicious behavior, suspicious authentication activity, Indicators of Compromise (IOCs), anomalous network activity, and potential policy violations.
  • Executed the complete incident response lifecycle, including detection, analysis, containment, eradication, recovery, documentation, and lessons learned, in accordance with NIST guidance.
  • Investigated security incidents involving phishing, malware, unauthorized access, suspicious login activity, compromised credentials, endpoint threats, and network anomalies.
  • Performed IOC investigations involving IP addresses, domains, URLs, file hashes, hostnames, usernames, and suspicious processes.
  • Conducted log correlation and timeline analysis across multiple security technologies to identify attack vectors, lateral movement, impacted assets, and potential data exposure.
  • Investigated suspicious emails by analyzing email headers, sender reputation, embedded URLs, attachments, domains, and message-delivery information.
  • Enhanced security response workflows by validating suspicious messages, identifying affected users, determining organizational exposure, and coordinating containment actions.
  • Conducted threat hunting using SIEM queries, endpoint telemetry, network logs, and threat intelligence to identify previously undetected malicious activity.
  • Mapped recurring attacker behaviors and security events to MITRE ATT&CK tactics, techniques, and procedures (TTPs) to strengthen SOC detection and investigation capabilities.
  • Assisted with SIEM detection-rule tuning and use-case optimization to reduce alert fatigue and improve detection accuracy.
  • Reviewed endpoint telemetry and EDR alerts to identify suspicious processes, malware execution, persistence mechanisms, privilege escalation, and other malicious activity.
  • Prioritized vulnerability findings according to CVSS severity, exploitability, threat intelligence, asset criticality, exposure, and business impact.
  • Coordinated vulnerability remediation with infrastructure, application, endpoint, and network teams and tracked remediation activities through closure.
  • Assisted with security control assessments, vulnerability management, security audits, and compliance evidence collection.
  • Created and maintained incident tickets in ServiceNow and Jira, documenting analysis, evidence, IOCs, investigation actions, escalation decisions, and resolution.
  • Escalated confirmed and high-risk incidents to senior analysts, incident response teams, and appropriate stakeholders according to defined severity and SLA requirements.
  • Developed investigation notes, incident reports, post-incident documentation, and knowledge-base content to improve SOC consistency and analyst knowledge sharing.
  • Collaborated with IT, engineering, cloud, network, identity, and security teams to remediate identified threats and strengthen organizational security controls.

Education

Master of Science - Management Information Systems

Texas Southern University
Houston, TX
05-2019

Skills

  • Security Operations & Incident Response: Security Monitoring Alert Triage Incident Investigation Incident Response Incident Containment Root Cause Analysis Threat Hunting Escalation Management Security Incident Documentation Post-Incident Analysis
  • SIEM & Security Analytics: Microsoft Sentinel IBM QRadar Splunk SIEM Rule Tuning IOC Analysis Security Monitoring
  • Endpoint Security & EDR: Microsoft Defender CrowdStrike Falcon SentinelOne Endpoint Detection & Response Malware Investigation Advanced Threat Protection
  • Cloud & Identity Security: Microsoft Azure Microsoft Entra ID Microsoft Intune Microsoft 365 Admin Center MFA Identity Monitoring Conditional Access Suspicious Sign-In Investigation Cloud Security Monitoring
  • Email Security: Proofpoint Phishing Investigation Business Email Compromise (BEC) Malicious URL Analysis Malicious Attachment Analysis Email Header Analysis Sender/Domain Investigation
  • Network Security: Wireshark Nmap IDS/IPS Firewall Monitoring Network Traffic Analysis TCP/IP DNS HTTP/HTTPS Network Security Monitoring
  • Vulnerability & Risk Management: Nessus Qualys Vulnerability Assessment Vulnerability Prioritization Remediation Tracking Risk Register Management Security Risk Assessment
  • Frameworks & Compliance: NIST CSFNIST SP 800-61MITRE ATT&CK Incident Response Planning Disaster Recovery
  • Case Management & Ticketing: ServiceNow (SNOW) Jira Salesforce Incident Documentation SLA Tracking Escalation Management

Certification

CompTIA Security+, CompTIA CySA+, CompTIA PenTest+, eLearnSecurity Junior Penetration Tester (eJPT)

Personal Information

  • Title: SOC ANALYST | CYBERSECURITY ANALYST | INCIDENT RESPONSE ANALYST
  • Nationality: U.S. Citizen

Custom

  • MA
  • Houston, TX | Email: [Email Address] | Phone: [Phone Number]
  • U.S. Citizen | Active Security Clearance

Timeline

Cybersecurity / Incident Response Analyst

GOVERNMENT AGENCY
12.2024 - Current

SOC / Information Security Analyst

IBM
03.2021 - 12.2024

Master of Science - Management Information Systems

Texas Southern University