Cybersecurity professional with a strong interest in penetration testing, log analysis, security engineering, and data analytics.
Overview
6
6
years of professional experience
1
1
Certification
Work History
Security Engineer
Deloitte
09.2024 - Current
Administered and maintained Splunk infrastructure, including configuring indexers, search heads, and forwarders for efficient log aggregation and analysis. Engineered custom security-specific dashboards and alerts to provide real-time visibility into network activities and potential threats.
Managed and administered Trellix ePolicy Orchestrator (ePO) to centrally deploy, monitor, and configure endpoint security solutions across the environment.
Provided weekly briefings to client on the current security status, covering key metrics, recent threats, and ongoing remediation efforts.
Responded promptly to security incidents, conducting thorough investigations to identify, contain, and mitigate potential threats. Produced detailed incident reports, documenting timelines, findings, actions taken, and recommendations for future prevention.
Managed and oversaw the security of cloud environments within AWS, ensuring the protection of infrastructure, applications, and data.
Configured and maintained AWS services such as CloudTrail, CloudWatch, and VPC Flow Logs to capture detailed activity across resources. Regularly reviewed and analyzed logs to detect anomalous behavior, investigate potential security incidents, and ensure compliance with internal security policies and government regulations.
Penetration Tester
Deloitte
10.2021 - 09.2024
Performed monthly penetration tests using Kali Linux to identify vulnerabilities and assess the security posture of network infrastructure, applications, and systems
Utilized Burp Suite Enterprise to perform automated vulnerability scans on 70+ public-facing websites, identifying security flaws and weaknesses in web applications.
Simulated quarterly phishing campaigns with GoPhish to evaluate user awareness and test organizational resilience against social engineering attacks.
Delivered detailed reports outlining findings, risk assessments, and actionable remediation recommendations to enhance security controls and mitigate threats.
Cyber Security Analyst
Sentar
10.2019 - 10.2021
Conducted in-depth analysis of Falcon detections, performing root cause analysis and leveraging contextual data to assess the validity of alerts.
Developed and optimized advanced queries and custom dashboards within Splunk to proactively detect, monitor, and respond to suspicious network activity.
Reviewed and optimized detection rules across Tanium Threat Response, Trellix, and Firepower to minimize false positives and enhance the precision of threat detection.
Created detailed and comprehensive incident reports for security events, documenting findings, impact assessments, response actions, and remediation steps.
Vulnerability Analyst
Sentar
11.2018 - 10.2019
Maintained and administered Tenable Security Center, overseeing the configuration, execution, and management of vulnerability scans across the organization's 3000 endpoints.
Troubleshot and resolved failed scan issues, diagnosing configuration errors, connectivity problems, and system resource limitations to ensure successful and timely assessments.
Education
Bachelor’s - Cybersecurity & Information Assurance
Western Governors University
Online
09.2019
Certification
GIAC Certified Incident Handler (GCIH)
CompTIA CYSA+, Security+, Network+, A+
Splunk Enterprise Certified Architect & Admin
AWS Solutions Architect Associate (SAA)
TCM Security Practical Web Pentest Associate (PWPA)
Timeline
Security Engineer
Deloitte
09.2024 - Current
Penetration Tester
Deloitte
10.2021 - 09.2024
Cyber Security Analyst
Sentar
10.2019 - 10.2021
Vulnerability Analyst
Sentar
11.2018 - 10.2019
Bachelor’s - Cybersecurity & Information Assurance