- Lead threat intel and incident response investigations with a team of analysts and reduced critical alert response times to 24 hours.
- Communicate complex threat insights through clear, actionable reports and presentations for leadership, stakeholders, and external partners.
- Manage an initiative to improve GRC risk analysis by adding security incident details, resulting in higher fidelity risk scoring.
- Directed 2 tabletop exercises to assess and refine incident response protocols, consistently raising coordination and preparedness across operational teams.
- Ensure SEC compliance by participating in assessments, aligning with industry standards, and recommending improvements to security protocols.
Work
- Aug2023 - PresentHondaSenior Incident Response Analyst
- Jan2020 - Apr2023Principal Financial GroupSenior Cyber Security Engineer III
- Performed continuous operational support of QRADAR, Splunk, Crowdstrike, and Corelight Zeek/Suricata including architecture, policies, rule recommendations, tuning, and upgrades.
- Built 10+ high-fidelity incident detections based on threat actor analysis, attack methodologies, and intelligence sources.
- Performed artifact analysis of suspected threat actors using Crowdstrike Falcon Sandbox, completing 4 incident response investigations.
- Configured and maintained custom nTop NSM infrastructure on Debian Linux servers, maintaining a 99% uptime.
- Maintained and configured network monitoring tools, intrusion detection systems, web application firewalls, and data loss prevention tools.
- Sep2017 - Jan2020PratumSOC Analyst II
- Performed event correlation and analyzed network traffic anomalies on security incidents in Fortinet SIEM appliances.
- Developed and executed 3 threat mitigation strategies, policies, and incident response procedures consistent with business strategies while effectively protecting data integrity, security, and limiting liability.
- Actively lead and triaged 5 incident investigations involving malware analysis from Microsoft Defender XDR driven alerts.
- Validated intrusion detection system (IDS) alerts against network traffic.
- Deployed infrastructure using Docker, Ansible, and Terraform on Linux systems and cloud-native services.