Experience

Security Operations Background

Hands-on SOC experience supporting monitoring, investigation, incident response, and analyst mentorship.

July 2025 - Present

SOC Analyst 1

BlackSwan Cybersecurity | San Antonio, TX

  • Support a 24/7 embedded SOC for national energy infrastructure across OT and IT environments.
  • Develop KQL queries in Microsoft Sentinel and use NDR tooling to detect anomalies and investigate threats.
  • Perform Tier 2 responsibilities including deeper incident investigation, threat hunting, and escalation support.
  • Use threat intelligence enrichment and detection tuning to improve correlation and reduce false positives.
  • Maintain incident response documentation and post-incident reporting in ServiceNow.
Jan 2023 - July 2025

SOC Security Analyst

University of Texas at San Antonio | San Antonio, TX

  • Monitored Windows and Linux security events using Splunk, Microsoft Defender, Carbon Black, and ExtraHop.
  • Correlated alerts from Abnormal AI and DUO Admin to determine severity and mitigation steps.
  • Built and optimized Splunk searches and dashboards for real-time threat detection.
  • Supported incident response with chain of custody procedures for secure device handoff.
  • Mentored and trained 15+ interns each semester on SOC workflows and security best practices.