🛡
Yrs Experience
18
2008 – Present
📊
SIEM Dashboards
60+
Custom Splunk
⚡
Alert Types
200
Fine-tuned
🏆
Awards
1
Innovator 2023
👥
Team Size
12
Analysts led
📜
Certifications
6
CISM · CISSP · CySA+…
Career Timeline
2008 – Present
DeepWatch MSSP
2022 – Present · 4 yrs
Lead Security Analyst
U.S. SOCOM HQ (Contractor)
2015 – 2022 · 7 yrs
Senior CSIRT Analyst · TS/SCI Clearance
GoRACK
2014 – 2015 · 1 yr
NOC Technician
U.S. Air Force
2008 – 2012 · 4 yrs
Windows System Administrator
Certifications & Education
CISM
CISSP
CySA+
Security+ CE
SOAR Admin
Intro SNYPR
Education
Florida State College
B.S. Computer Science · 64 Credits
Issuing Bodies
ISACA
ISC²
CompTIA
Splunk
Tools & Platforms Proficiency
Splunk SIEM98%
Microsoft Sentinel90%
SecurOnix / Google SecOps85%
TORQ SOAR + OpenAI88%
FTK Imager / EnCase (DFIR)80%
Wireshark / Network Analysis82%
Active Directory / Group Policy87%
CrowdStrike Falcon (EDR)85%
SentinelOne (EDR/XDR)82%
Specialization
SIEM / Detection Eng.25%
Incident Response45%
Threat Hunting15%
SOAR Automation10%
Digital Forensics5%
Key Achievements
2023 Innovator of the Year — SIEM sourcetype downtime ↓ 70% via automated notification system
SOAR + GPT-4o — Co-built automated case creation combining TORQ and OpenAI
SolarWinds SUNBURST — Executed critical IR containment ops for USSOCOM
200+ Alert Types — Enabled & tuned across ~80 MSSP customers
MSP-Wide Training — Weekly initiative standardizing analysis across 200+ alert types
Red Team Response — Kerberoasting, LSASS dump, Pass-the-Hash, AD enumeration detection
DW
DeepWatch MSSP
Lead Security Analyst · Full-time · MSSP
Current Role
2022 – Present
👥
Team Led
12
Security Analysts
📊
SIEM Dashboards
60+
Custom Splunk
⚡
Alert Types Tuned
200
~80 MSSP Customers
🏆
Award
2023
Innovator of the Year
Responsibilities & Achievements
Lead Security Analyst
Team Leadership — Currently leading a team of twelve analysts in the triage and investigation of security events using Splunk, MS Sentinel, SecurOnix, and Google SecOps SIEM environments.
SLA & Quality Delivery — Ensured delivery of SLAs focusing on high quality output, leveraging TORQ SOAR automation to streamline incident response workflows.
SIEM Dashboard Engineering — Created and managed 60+ custom Splunk SIEM security dashboards for monitoring user activities and log ingestion.
MSP-Wide Training Initiative — Established a weekly training program to standardize analysis and investigative methodologies across 200+ alert types, driving consistency, accuracy, and operational efficiency.
Detection Engineering — Performed Detection Engineer duties including enabling and fine-tuning 200 security content alerts for approximately 80 MSSP customers.
Blue Team / Adversarial Response — Executed blue team response operations during red team and penetration testing exercises, including detection and containment of Kerberoasting, LSASS memory dumping, Pass the Hash, SMB-based remote command execution, and Active Directory domain enumeration techniques.
SOAR + AI Automation — Assisted in building and designing an automated case creation system combining the TORQ SOAR platform with the OpenAI ChatGPT-4o model.
🏆 2023 Innovator of the Year — Recognized for the development of an advanced notification system that reduced SIEM sourcetype downtime by 70% across MSSP customer environments.
Customer Briefings — Delivered comprehensive briefings to customers, outlining their current cybersecurity posture, the risks linked to observed alerts, and the potential impact of these threats on their environment.
Technologies Used
SIEM Platforms
Splunk
MS Sentinel
SecurOnix
Google SecOps
Automation & AI
TORQ SOAR
OpenAI GPT-4o
Security Operations
Red Team Ops
Blue Team
Detection Eng.
🏆
2023 Innovator of the Year
DeepWatch MSSP
Recognized for developing an advanced notification system that reduced SIEM sourcetype downtime by 70%, improving observability and uptime assurance across MSSP customer environments.
Previous Experience
JT
Jacobs Technology
Senior Incident Response Analyst (CSIRT) · Contractor · U.S. SOCOM HQ
🔒 TS/SCI Clearance
2015 – 2022
🛡️
Tenure
7
Years on Mission
⚡
IR Tier
CSIRT
Senior Responder
🌐
Environment
DoD
Classified Networks
🔍
Coverage
24/7
SOC Operations
Responsibilities & Achievements
Senior Incident Response Analyst
Computer Security Incident Response — Served as a senior CSIRT analyst supporting U.S. Special Operations Command, leading the detection, triage, containment, and eradication of security incidents across classified and unclassified DoD enterprise networks.
Threat Hunting — Conducted proactive, hypothesis-driven threat hunts against advanced persistent threat (APT) activity, leveraging SIEM analytics and endpoint telemetry to surface dwell-time adversaries ahead of automated alerting.
Digital Forensics & Malware Triage — Performed host and network forensic analysis and malware triage to reconstruct attack timelines, determine root cause and scope, and recover indicators of compromise for enterprise-wide blocking.
Incident Documentation & Reporting — Authored detailed incident reports and after-action reviews for command leadership, ensuring compliance with DoD reporting requirements and feeding lessons learned back into detection content.
Detection Content & Tuning — Developed and refined SIEM correlation rules and signatures mapped to the MITRE ATT&CK framework, reducing false positives and improving mean time to detect across the SOC.
Mentorship & Shift Lead — Mentored junior analysts and served as a shift lead during 24/7 SOC operations, escalating critical events and coordinating response actions with stakeholders across the command.
Technologies Used
SIEM & Detection
Splunk
ArcSight
Snort / IDS
Forensics & Analysis
EnCase
Wireshark
Volatility
Frameworks
MITRE ATT&CK
Cyber Kill Chain
NIST IR
🛡️
Mission Assurance
U.S. SOCOM HQ
Held an active TS/SCI clearance while defending mission-critical special operations networks, delivering senior-level incident response and threat hunting across a 24/7 defensive cyber operations team.
📜
Professional Certifications
Industry-recognized credentials · SOC · GRC · Cloud · Automation
9 Credentials
📜
Certifications
9
Active credentials
🏛
Issuing Bodies
7
ISC² · ISACA · CompTIA…
🗓
Most Recent
2026
Splunk SOAR Admin
🎯
Domains
5
Defense · GRC · Cloud
ISACA
Certified Information Security Manager
ISACA · CISM
Management-focused credential validating expertise in governing, designing, and overseeing an enterprise information security program.
ISC²
Certified Information Systems Security Professional
ISC² · CISSP
Globally recognized gold-standard certification confirming the ability to design, implement, and manage a best-in-class cybersecurity program.
⊞
Microsoft 365 Certified: Security Administrator Associate
Microsoft
Validates the skills to secure Microsoft 365 environments through threat protection, identity and access management, and information governance.
>
Administering Splunk SOAR
Splunk · Issued Apr 2026
Demonstrates the ability to configure, manage, and administer Splunk SOAR to automate and orchestrate security operations workflows.
>
Splunk Core Certified User
Splunk
Validates foundational proficiency in searching, navigating, and creating reports and dashboards within the Splunk platform.
G
Google Cybersecurity
Google · Issued Nov 2025
Professional certificate covering core SOC analyst skills, including SIEM tooling, intrusion detection, Python, and incident response.
SX
Introduction to SNYPR
Securonix
Foundational training in the Securonix SNYPR platform for next-generation SIEM and user-and-entity behavior analytics.
CompTIA
CompTIA Security+
CompTIA
Industry-standard certification covering core security functions including threat management, cryptography, and risk mitigation.
CompTIA
CompTIA Cybersecurity Analyst (CySA+)
CompTIA · CySA+
Validates behavioral-analytics skills for proactive threat detection, continuous security monitoring, and incident response.
📁
Forensic Case File — Insider-Threat Cryptocurrency Miner
Case DF-2016-0314 · Microsoft Edge — Coinminer · Insider · McAfee ePO block
⚠ High Severity
March 2016
On 11 March 2016, host forensics on a finance workstation traced activity to a CPU coinminer that user John.Doe downloaded as a fake Adobe Flash "update" through their Microsoft Edge (EdgeHTML 13) browser session. McAfee ePolicy Orchestrator (ePO) detected the malicious file as it was downloaded and blocked and quarantined it. Windows Event Viewer was then used to correlate the McAfee threat events with John.Doe's logon and security-control tampering, concretely confirming this as an insider-threat event. The drive was imaged and a full chain of custody maintained. All entities, names, serials, and indicators below are fictional and provided for training and demonstration purposes only.
🗓
Date Opened
2016-03-14
Reported by SOC Tier-2
💽
Evidence Items
2
1× HDD · 1× E01 image
🛡️
Crypto miner detected
Action: Blocked
Quarantined by McAfee ePO
✅
Custody Status
SEALED
Integrity verified
Event Reconstruction — Infection Timeline
EST · 10–11 Mar 2016
Browsing session begins — John.Doe opens Microsoft Edge 25.10586.0.0 and navigates directly to a known coinminer download portal, bypassing the corporate proxy category block.10 Mar · 23:51
Security control tampered — Prior to download, the McAfee VirusScan on-access scanner is locally disabled from the workstation — an action requiring John.Doe's interactive session and elevation.10 Mar · 23:53
Payload downloaded — Disguised as an "Adobe Flash Player" update, Edge downloads flash_setup_v21.exe to the Downloads folder.10 Mar · 23:54
Dropper executed — Installer spawns from Edge's download path and writes a coinminer payload to %AppData%\Roaming\WinTelemetry\svhost.exe (note the misspelling masquerading as svchost).10 Mar · 23:55
Persistence established — Dropper creates Run key HKCU\...\CurrentVersion\Run\WinTelemetry so the miner relaunches at every logon.10 Mar · 23:55
Mining begins — svhost.exe opens a Stratum connection to a Monero pool and pins all four logical cores at ~98%; the fans audibly spin up overnight.10 Mar · 23:57
McAfee ePO detects & blocks — When the McAfee agent policy is re-enforced from the ePO server, the on-access scanner identifies flash_setup_v21.exe / svhost.exe as a coinminer, blocks execution and quarantines the file. Threat event forwarded to ePO.11 Mar · 02:41
SOC incident opened — The ePO threat event plus the sustained-CPU behavioral alert are correlated by SOC Tier-2; an incident is raised.11 Mar · 02:47
Event Viewer confirmation — Windows Event Viewer is used to correlate the McAfee threat event with Security-log logon 4624 for John.Doe and the service-stop 7036 for the AV scanner — concretely confirming a deliberate insider-threat event.11 Mar · 03:02
Host isolated — Workstation network-contained via EDR; John.Doe's account disabled pending review.11 Mar · 03:10
Evidence seized — Workstation powered down, hard drive removed, tagged, and forensically imaged. Chain of custody opened (see below).11 Mar · 09:20
Subject / Custodian
JD
John Doe
Accounts Payable Specialist · Finance
Domain accountCORP\John.Doe
WorkstationWKS-FIN-0427
Asset tagCORP-IT-118934
DispositionInsider threat — confirmed
⊞
Infection Vector — Microsoft Edge
BrowserEdge 25.10586.0.0
EngineEdgeHTML 13.10586
OS buildWin 10 · 1511
LureFake Flash update
Artifactspartan.edb / WebCacheV01.dat
Process Lineage
Reconstructed from Prefetch + EDR
MicrosoftEdge.exepid 4120
SIGNED
└─browser_broker.exepid 5388
SIGNED
└─flash_setup_v21.exepid 6012
DROPPER
└─svhost.exepid 6480
MINER
└─conhost.exepid 6492
CHILD
# Stratum login captured on the wire (pcap)
{"method":"login","params":{
"login":"4xMonErO...WkdF.WKS-FIN-0427",
"pass":"x","agent":"xmr-stak-cpu/1.3"}}
→ tcp 51.x.x.x:4444 (stratum+tcp, Monero)
Indicators of Compromise
Sanitized · defanged
SHA-256
b1f9...c47a · svhost.exe
CPU coinminer (xmr-stak variant)
FILE
%AppData%\Roaming\WinTelemetry\svhost.exe
Masquerades as svchost (note: "svhost")
REG
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\WinTelemetry
Logon persistence
DOMAIN
cdn-flashupdate[.]xyz
Fake update / payload host
POOL
stratum+tcp://pool.minexmr[.]example:4444
Monero mining pool C2
Endpoint Detection — McAfee ePO
🛡 Blocked
McAfee ePolicy Orchestrator received the on-access scan detection from the endpoint agent, blocked execution, and quarantined the downloaded file.
ConsoleMcAfee ePO 5.3.1
EngineVSE 8.8 · On-Access Scan
Threat nameTrojan-Miner!2F
Detected fileflash_setup_v21.exe
Action takenBlocked · Quarantined
Source hostWKS-FIN-0427
UserCORP\John.Doe
Event Viewer — Insider-Threat Confirmation
Windows Event Log
Windows Event Viewer was used to concretely confirm the insider-threat event — correlating the McAfee block with John.Doe's interactive logon and the deliberate stop of the AV service.
# Security log — interactive logon
Event 4624 An account was successfully logged on.
Account Name: John.Doe Logon Type: 2 (Interactive)
Workstation: WKS-FIN-0427 10 Mar 2016 23:48
# System log — security control disabled
Event 7036 The McAfee McShield service entered the
stopped state. 10 Mar 2016 23:53
# Application log — McAfee threat event
Event 257 McAfee Endpoint: Trojan-Miner!2F
blocked / quarantined — flash_setup_v21.exe
User: CORP\John.Doe 11 Mar 2016 02:41
✔ Logon → AV stop → blocked download tie to one user = insider threat
Chain of Custody Report
Evidence Item — 1A
Hard Disk Drive
💽
Western Digital WD10EZEX
1 TB · 3.5" SATA III · 7200 RPM
Evidence tagDF-2016-0314-1A
Serial no.WD-WCC6Y4PXN8K2
Acquired2016-03-11 10:42
ToolFTK Imager 3.4.2
Write blockerTableau T35u
Image formatE01 (compressed)
Acquisition hashes — verified
MD5 9f2c4e1a7b08d3f6a1c9e0b4d27f5a83
SHA1 3ab19f77e0c4d2b8516fae902c7d4419b8e6f0a1
✔ Acquire hash == Verify hash — image integrity confirmed
Custody Transfer Log — Item DF-2016-0314-1A
🔒 Seal intact
| Date / Time (EST) | Released By | Received By | Purpose / Location |
|---|---|---|---|
| 2016-03-11 09:20 |
— (point of seizure) |
D. Reyes IR Responder |
Drive removed from WKS-FIN-0427, bagged & tagged at user desk (Floor 4, Finance). |
| 2016-03-11 10:05 |
D. Reyes | A. Noplis Forensic Examiner |
Hand-carried to forensic lab intake; tamper-evident bag #E-44821 logged. |
| 2016-03-11 10:42 |
A. Noplis | A. Noplis | Forensic imaging via Tableau write-blocker → E01. Hashes captured & verified. |
| 2016-03-11 14:18 |
A. Noplis | Evidence Locker Vault B, Shelf 3 |
Original drive returned to seal; working copy retained for analysis. |
| 2016-03-18 11:30 |
Evidence Locker | K. Brennan Legal / Counsel |
Image reviewed for HR/legal proceeding; returned same day, re-sealed. |
| 2016-03-18 16:05 |
K. Brennan | Evidence Locker Vault B, Shelf 3 |
Returned to long-term hold pending case closure. Seal verified intact. |
Examiner attestation — A. Noplis, Lead Security Analyst. Evidence handled per NIST SP 800-86 guidelines; no unaccounted custody gaps.
✔ Custody unbroken