← back home// experience --load

Experience

SOC Lead with roughly 6 years in cybersecurity and 8 in IT, grown through one organization from network engineering to the SOC floor. I lead a team of 8 analysts protecting 20,000+ endpoints across 10+ clients in multiple industries — driving detection engineering and threat hunting, owning high-severity incident response, and mentoring analysts while keeping response fast and evidence-based.

~6 yrs cybersecurity8 yrs ITTeam of 8 led20K+ endpoints10+ clients
// career.log

Where I've worked

Eight years at one managed IT & security services provider — promoted from network engineering up to leading the SOC.

  1. SOC LeadCurrent

    Managed IT & Security Services Provider
    2025 — Present
    • Lead a team of 8 SOC analysts protecting 20,000+ endpoints across 10+ clients in multiple industries — owning triage quality, escalation, and shift handoffs.
    • Drive detection engineering in Elastic SIEM: build and tune detections, map coverage to MITRE ATT&CK, and cut false positives on the highest-volume alert sources.
    • Lead incident response for high-severity cases end to end — scoping, containment, and post-incident reporting.
    • Run proactive threat hunts across client environments and convert hunt findings into durable new detections.
    • Mentor L1/L2 analysts and standardize playbooks, documentation, and escalation paths.
  2. SOC Analyst · L1 → L2

    Managed IT & Security Services Provider
    2020 — 2025
    • Monitored and triaged alerts across Elastic SIEM, CrowdStrike EDR/XDR, and SentinelOne, determining severity and business impact.
    • Investigated suspicious activity using logs, threat intelligence, and forensic data; documented findings, actions, and remediation.
    • Executed and refined incident-response playbooks; used CrowdStrike RTR and PowerShell for live response and evidence collection.
  3. L2 Service Desk Administrator · Staff Augmentation

    Managed IT & Security Services Provider
    2019 — 2020
    • Resolved escalated technical issues via ScreenConnect, minimizing downtime and holding SLA compliance across queues.
    • Led RingCentral softphone support for the City of Phoenix's COVID-19 vaccination registration effort.
    • Managed Active Directory — account creation, password resets, and group policy — and adapted across diverse client environments.
  4. Network Technician & Engineer

    Managed IT & Security Services Provider · Integration Division
    2018 — 2019
    • Configured switches, routers, and wireless access points; installed and troubleshot equipment across multiple sites.
    • Ran physical and wireless site surveys; designed and remediated WLANs with Ekahau Pro.
    • Traveled nationally for deployments and network upgrades.
// skills --list

Technical skills

SIEM & Detection
Elastic SIEMDetection tuningMITRE ATT&CKLog & forensic analysis
EDR / XDR
CrowdStrike EDR/XDRCrowdStrike RTRSentinelOneCortex XDR · XQL
IR & Threat
Incident triageEscalationThreat intelligenceIR playbooksNIST-aligned response
Scripting
PowerShellXQLCrowdStrike RTR
Networking & Systems
TCP/IP · DNS · DHCPSubnettingAir-gapped networksEkahau ProWindows · Linux · macOSActive Directory
// certs --list

Certifications

CompTIA Security+Certified
Google IT Support ProfessionalCoursera · Certified
CompTIA CySA+In progress
CompTIA PenTest+In progress
// training

Education & training

PluralSightSOC Analyst 1 & 2 — hands-on labs
UdemyCySA+, PenTest+ & CCNA coursework
CourseraGoogle IT Support Professional