Summary
Overview
Work History
Education
Skills
Tools
Certification
Timeline
Generic

RHODA KWOBA

Austin,TX

Summary

Senior Cybersecurity Engineer experienced in leading Security Operations, Vulnerability Management, Incident Response, and Threat Hunting across enterprise environments. Delivered significant improvements in SOC maturity and strengthened security controls as Incident Commander during high-severity cyber incidents. Focused on enhancing enterprise resilience through proactive threat hunting, security automation, and development of scalable security programs while mentoring high-performing teams.

Overview

1
1
Certification
10
10
years of professional experience

Work History

Cybersecurity Technology Consultant

Eyepoint Consulting
Dallas, TX
10.2025 - Current
  • Led client-facing security engineering, incident response, vulnerability management, and threat hunting engagements across enterprise and public-sector environments, identifying security risks, control gaps, and actionable remediation strategies to enhance overall security posture.
  • Managed vulnerability assessment and remediation activities across enterprise and cloud environments, prioritizing findings based on exploitability, asset criticality, exposure, and business impact, coordinating remediation efforts and validating corrective actions to mitigate security risks.
  • Performed security risk and architecture assessments across new technologies and enterprise environments, identifying control deficiencies and recommending risk-based improvements aligned with NIST, SOC 2, and organizational security requirements.
  • Architected, deployed, configured, and tuned MDR/XDR, DLP, SIEM, and SaaS security solutions across identity, endpoint, network, application, and cloud environments to strengthen detection and response capabilities.
  • Developed and tuned Microsoft Sentinel detection rules and automated security workflows using Logic Apps and PowerShell, streamlining alert enrichment, triage, escalation, and response to enhance incident response speed and accuracy.
  • Conducted proactive threat hunts and incident investigations involving ransomware, malware, phishing/BEC, insider threats, and suspicious identity activity, correlating endpoint, identity, network, and cloud telemetry and mapping adversary behavior to MITRE ATT&CK.
  • Supported Microsoft Entra ID and Zero Trust security initiatives, including MFA, Conditional Access, least privilege, and identity controls, while providing security guidance to technical and business stakeholders and mentoring junior security professionals.

Lead Security Engineer

Covius
Remote, TX
12.2022 - 09.2025
  • Led incident response efforts for high-severity cybersecurity incidents, coordinating containment, eradication, recovery, stakeholder communications, and post-incident reviews.
  • Drove continuous vulnerability management and risk assessment across enterprise and cloud environments, continuously identifying, validating, and prioritizing vulnerabilities based on exploitability, asset criticality, exposure, and business impact; partnered with GRC, infrastructure, cloud, and application teams to assess residual risk, track remediation and exceptions, validate corrective actions, and maintain ongoing visibility into organizational risk.
  • Partnered with Black Hills Information Security to conduct enterprise incident response tabletop exercises, validating organizational readiness against real-world cyberattack scenarios, identifying procedural gaps, and leveraging exercise findings to continuously improve incident response playbooks and overall cyber resilience.
  • Leveraged Cymulate adversarial attack simulations to emulate real-world attack techniques and identify exploitable gaps, validating security controls and informing remediation efforts.
  • Designed and executed intelligence-driven phishing simulation campaigns replicating current real-world phishing techniques and attacker TTPs to improve organizational cyber resilience.
  • Increased employee phishing awareness through targeted security education, improving phishing reporting metrics, and contributing to a 60% reduction in successful phishing compromises.
  • Created and maintained operational playbooks for ransomware incidents, phishing investigations, WAF monitoring, and enterprise incident response, ensuring consistent and efficient SOC responses.
  • Championed continuous improvement initiatives by evaluating security tools and implementing workflow enhancements, enhancing overall effectiveness and maturity of Security Operations.

VP - Senior Security Engineer

Citigroup
Las Colinas, TX
01.2021 - 12.2022
  • Lead efforts in securing the company’s network infrastructure, including the configuration and management of firewalls, VPNs, DLPs, and intrusion detection/prevention systems.
  • Implemented and continuously improved the incident response process, reducing the response time to security breaches by 40%.
  • Conducted ongoing security assessments to proactively identify threats and manage vulnerabilities, enhancing overall security posture.
  • Conducted threat analysis, vulnerability assessments, and penetration testing, identifying and remediating high-risk vulnerabilities.
  • Researched attacker tradecraft, emerging malware, and TTPs aligned with MITRE ATT&CK to inform strategic security enhancements.
  • Reduced SOC alert triage timelines by 45% by leveraging automation for alert tuning freeing up the team to focus on other key deliverables.
  • Collaborated with cross-functional teams to ensure compliance with security frameworks such as NIST, ISO, achieving successful SOC 2 certification.
  • Guided secure application development and cloud security best practices, reducing potential security risks.

AVP - Cybersecurity Engineer

Citigroup
Las Colinas, TX
03.2018 - 12.2021
  • Designed and implemented security controls for cloud-based platforms (AWS and Azure) to protect sensitive data and ensure compliance with industry standards.
  • Developed automated security reporting and monitoring tools using Python and PowerShell, streamlining security operations and improving incident response times.
  • Collaborated with product and infrastructure teams to enhance security measures, resulting in strengthened product offerings and reduced vulnerabilities.
  • Delivered training to internal teams on cybersecurity best practices, raising awareness and decreasing user-related security incidents by 25%.
  • Contributed to development and enforcement of security policies and procedures, mitigating risks from internal and external threats.

Cybersecurity Analyst

T-Mobile RBO
Frisco, TX
06.2016 - 02.2018
  • Conducted network security assessments, identifying and remediating vulnerabilities in firewalls, network configurations, and endpoint devices to enhance overall security posture.
  • Managed endpoint security solutions (antivirus, EDR) across enterprise, improving threat detection and response capabilities.
  • Collaborated with incident response teams to investigate and resolve security breaches, minimizing downtime and enhancing recovery processes.
  • Supported creation and enforcement of data protection strategies, ensuring encryption and secure storage of sensitive data to mitigate risks.

Education

Master of Science - Cybersecurity and Information Assurance

Western Governors University
Salt Lake City, Utah

Bachelor of Science - Cybersecurity and Information Assurance

Western Governors University
Salt Lake City, Utah

Skills

  • Incident response and threat analysis
  • Vulnerability management and penetration testing
  • Cybersecurity frameworks and policies
  • Cloud and network security
  • Security orchestration
  • Problem solving and strategic thinking
  • Relationship building and stakeholder engagement
  • Employee training programs

Tools

  • SIEM/SOAR/XDR : MS Defender, Sophos, Crowdstrike, Cortex XDR, Arcsight, Sentinel, InsightIDR.
  • Vulnerability Management: Qualys, OpenVAS, InsightVM.
  • Email Gateways: Avanan,MS Exchange, Mimecast.
  • WAF, DLP , DAST : Proofpoint, MS Purview, Cyberhaven, Akamai , Varonis, Veracode.
  • Red Teaming: Kali Linux, Cymulate, Burp Suite.
  • Cloud : Azure , AWS , M365, MS Entra ID.

Certification

  • Certified Information Systems Security Professional (CISSP) – (ISC)²
  • Certified Ethical Hacker (CEH) – EC-Council
  • CompTIA Security+
  • CompTIA Pentest+
  • CompTIA CYSA+
  • SC-200, SC-900, AZ 500/900

Timeline

Cybersecurity Technology Consultant

Eyepoint Consulting
10.2025 - Current

Lead Security Engineer

Covius
12.2022 - 09.2025

VP - Senior Security Engineer

Citigroup
01.2021 - 12.2022

AVP - Cybersecurity Engineer

Citigroup
03.2018 - 12.2021

Cybersecurity Analyst

T-Mobile RBO
06.2016 - 02.2018

Master of Science - Cybersecurity and Information Assurance

Western Governors University

Bachelor of Science - Cybersecurity and Information Assurance

Western Governors University
RHODA KWOBA