Experience
SOC Lead with roughly 6 years in cybersecurity and 8 in IT, grown through one organization from network engineering to the SOC floor. I lead a team of 8 analysts protecting 20,000+ endpoints across 10+ clients in multiple industries — driving detection engineering and threat hunting, owning high-severity incident response, and mentoring analysts while keeping response fast and evidence-based.
~6 yrs cybersecurity8 yrs ITTeam of 8 led20K+ endpoints10+ clients
// career.log
Where I've worked
Eight years at one managed IT & security services provider — promoted from network engineering up to leading the SOC.
- 2025 — Present
SOC LeadCurrent
Managed IT & Security Services Provider- Lead a team of 8 SOC analysts protecting 20,000+ endpoints across 10+ clients in multiple industries — owning triage quality, escalation, and shift handoffs.
- Drive detection engineering in Elastic SIEM: build and tune detections, map coverage to MITRE ATT&CK, and cut false positives on the highest-volume alert sources.
- Lead incident response for high-severity cases end to end — scoping, containment, and post-incident reporting.
- Run proactive threat hunts across client environments and convert hunt findings into durable new detections.
- Mentor L1/L2 analysts and standardize playbooks, documentation, and escalation paths.
- 2020 — 2025
SOC Analyst · L1 → L2
Managed IT & Security Services Provider- Monitored and triaged alerts across Elastic SIEM, CrowdStrike EDR/XDR, and SentinelOne, determining severity and business impact.
- Investigated suspicious activity using logs, threat intelligence, and forensic data; documented findings, actions, and remediation.
- Executed and refined incident-response playbooks; used CrowdStrike RTR and PowerShell for live response and evidence collection.
- 2019 — 2020
L2 Service Desk Administrator · Staff Augmentation
Managed IT & Security Services Provider- Resolved escalated technical issues via ScreenConnect, minimizing downtime and holding SLA compliance across queues.
- Led RingCentral softphone support for the City of Phoenix's COVID-19 vaccination registration effort.
- Managed Active Directory — account creation, password resets, and group policy — and adapted across diverse client environments.
- 2018 — 2019
Network Technician & Engineer
Managed IT & Security Services Provider · Integration Division- Configured switches, routers, and wireless access points; installed and troubleshot equipment across multiple sites.
- Ran physical and wireless site surveys; designed and remediated WLANs with Ekahau Pro.
- Traveled nationally for deployments and network upgrades.
// skills --list
Technical skills
SIEM & Detection
Elastic SIEMDetection tuningMITRE ATT&CKLog & forensic analysis
EDR / XDR
CrowdStrike EDR/XDRCrowdStrike RTRSentinelOneCortex XDR · XQL
IR & Threat
Incident triageEscalationThreat intelligenceIR playbooksNIST-aligned response
Scripting
PowerShellXQLCrowdStrike RTR
Networking & Systems
TCP/IP · DNS · DHCPSubnettingAir-gapped networksEkahau ProWindows · Linux · macOSActive Directory
// certs --list
Certifications
◆
CompTIA Security+Certified
◆
Google IT Support ProfessionalCoursera · Certified
◇
CompTIA CySA+In progress
◇
CompTIA PenTest+In progress
// training
Education & training
PluralSightSOC Analyst 1 & 2 — hands-on labs
UdemyCySA+, PenTest+ & CCNA coursework
CourseraGoogle IT Support Professional