Professional Summary
Overview
Work History
Education
Skills
Timeline

Matthew Sobota

Meta
22
years of professional experience

Security engineer and threat intelligence professional with experience investigating and disrupting cyber threat actors at scale, targeting billions of users on one of the world's largest technology platforms. Specialized in all source threat actor tracking to help enable cross-functional threat disruption and engineering solutions for platform defense.

Work History

Security Engineer

8 Years 4 Months
Meta | 02.2018 - Current
  • Member of Meta's Counter Espionage Team responsible for identifying, investigating, and disrupting Nation State and Private Sector Offensive Actors abuse of platform services.
  • Analyzed large complex dataset using SQL, Python, Pandas, Claude/GPT/Muse, Tableau, and other technologies to aid in discovery, analysis, and effectiveness of mitigation efforts.
  • Productionized AI-native agentic workflows for ingesting and triaging threat intelligence to build detection signals.
  • Developed threat actor behavior pattern detections to improve speed and accuracy while identifying strategies for addressing detection gaps in product vulnerabilities or abuse.
  • Led organization's crisis investigative response team responsible for analyzing and executing high priority escalations. Provided strategic and tactical direction to the 16 analysts supporting the overall program.
  • Conducted additional support to Youth Safety, Human Exploitation, Dangerous Organizations, and Information Operations investigations across platforms to reduce risks to users and improve Trust & Safety.
  • Strengthened the broader security community's understanding of various cyber threats by contributing to Meta's public reporting on adversarial actors and other information sharing initiatives.

Cyber Threat Intel Analyst

7 Years 11 Months
ThreatConnect | 03.2010 - 02.2018

Federal Bureau of Investigations - Cyber Division/National Cyber Investigative Joint Task Force (2013-2018)

  • Operational lead for team of network threat analysts responsible for generating Intelligence Community reporting derived from analysis of network data, forensically acquired host images, malware analysis, and additional surveillance capabilities.
  • Analyzed netflow and PCAP to identify anomalous and/or malicious content.
  • Reverse engineered network/malware communications protocols allowing for identification of infrastructure, functionality, transport methods, and decoding of control processes.
  • Develop network (SNORT) and malware (YARA) signatures for identification of malicious activity.
  • Author and co-contributor on Intelligence Community Assessments and Presidential Daily Briefs.

National Security Agency (2010-2013)

  • Investigated and contributed to the understanding of Nation State Espionage capabilities through exploitation of Signals Intelligence.
  • Aid investigating global computer networks intrusions in order to determine scope, identify adversarial capabilities, and threat attribution.
  • Identify and analyze adversarial threats to US interests by projecting the future cyber environment and adversary capabilities, intentions, Tactics, Techniques, and Procedures (TTPs).
  • Actively worked with Law Enforcement and Intelligence Community peers to share intelligence, conduct operations, and organize additional activities that provide a greater understanding of the threat to US interests.

Cyber Threat Intel Analyst

5 Years 7 Months
Northrop Grumman | 08.2004 - 03.2010

United States Army Cyber Command / 1st IO

  • Analyzed threat intelligence data to identify potential risks and vulnerabilities related to Army DoDIN platforms, providing tactical and strategic solutions to reduce risks.
  • Conducted long term, all-source analysis of state and non-state actor use of technologies for command and control by analyzing both classified and open source resources.
  • Produced Intelligence Information Reports (IIRs) related to ongoing intelligence investigations, broadening the Intelligence Community's understanding of threats to computer systems.

Education

Bachelor of Science - Information Technology Management

Radford University | Radford, VA | 05-2004

Skills

Crisis Response Planning & Execution
AI Native Workflows
Geopolitical Analysis
Scaled Abuse Detection Engineering
Insider Threat Investigations
Network & Behavioral Analysis

Timeline

Security Engineer

Meta
02.2018 - CurrentRead More

Cyber Threat Intel Analyst

ThreatConnect
03.2010 - 02.2018Read More

Cyber Threat Intel Analyst

Northrop Grumman
08.2004 - 03.2010Read More

Radford University

Bachelor of Science from Information Technology Management
Read More
Matthew Sobota