Experience
Security Operations Background
Hands-on SOC experience supporting monitoring, investigation, incident response, and analyst mentorship.
July 2025 - Present
SOC Analyst 1
BlackSwan Cybersecurity | San Antonio, TX
- Support a 24/7 embedded SOC for national energy infrastructure across OT and IT environments.
- Develop KQL queries in Microsoft Sentinel and use NDR tooling to detect anomalies and investigate threats.
- Perform Tier 2 responsibilities including deeper incident investigation, threat hunting, and escalation support.
- Use threat intelligence enrichment and detection tuning to improve correlation and reduce false positives.
- Maintain incident response documentation and post-incident reporting in ServiceNow.
Jan 2023 - July 2025
SOC Security Analyst
University of Texas at San Antonio | San Antonio, TX
- Monitored Windows and Linux security events using Splunk, Microsoft Defender, Carbon Black, and ExtraHop.
- Correlated alerts from Abnormal AI and DUO Admin to determine severity and mitigation steps.
- Built and optimized Splunk searches and dashboards for real-time threat detection.
- Supported incident response with chain of custody procedures for secure device handoff.
- Mentored and trained 15+ interns each semester on SOC workflows and security best practices.