Summary
Cybersecurity Analyst with 8 years on the blue team — SOC operations, incident response, and threat hunting. Active TS/SCI clearance. CISSP and OSCP certified. Led IR for 40+ incidents across Fortune-500 healthcare and financial services clients. Reduced MTTR from 8h to 90 minutes through Splunk + SOAR playbook automation.
Experience
Lead IR consultant for Fortune-500 incidents — 40+ engagements across ransomware, BEC, and APT scenarios.
Authored SOAR playbooks in Tines that reduced average MTTR from 8h to 90m across client SOCs.
Conducted forensic analysis using FTK, Volatility, and Splunk Enterprise Security for litigation-grade evidence chains.
Briefed C-suite stakeholders on threat actor TTPs (LockBit, ALPHV/BlackCat, Scattered Spider) and remediation roadmaps.
Operated 24×7 SOC for federal civilian client; triaged 1,200+ alerts/week across Splunk and Microsoft Sentinel.
Built threat-hunting hypotheses anchored on MITRE ATT&CK and surfaced 14 confirmed intrusions over 18 months.
Maintained SOC runbooks and onboarded 6 junior analysts through shadow + reverse-shadow rotations.