> initializing operations wall ok

> mounting telemetry feeds ok

> loading analyst profile ok

> sector: HISTORY ready

SYSTEM NOMINAL SECTOR HISTORY THREAT LEVEL LOW COVERAGE 24/7 SESSION 00:00:00 CST --:--:--
Deployment History

Hands-On
Background

From imaging lab computers in high school to leading incident response in a 24/7 embedded SOC. This is the path, oldest deployment at the bottom.

// Log Stream03 RECORDS

SOC Analyst 1

BlackSwan Cybersecurity // San Antonio, TX

  • Assume shift lead responsibilities in a 24/7 embedded SOC supporting national energy, leading off-hours and weekend incident response.
  • Update and maintain firewall configurations to meet NERC CIP compliance requirements for critical infrastructure.
  • Develop KQL queries in Microsoft Sentinel and use NDR tooling to detect anomalies and investigate threats.
  • Perform Tier 2 responsibilities including deeper incident investigation, threat hunting, and escalation support.
  • Use threat intelligence enrichment and detection tuning to improve correlation and reduce false positives.
  • Classify, prioritize, and escalate alerts based on threat severity in a high-availability, mission-critical setting.
  • Assume incident command during off-hours and weekend shifts, coordinating analyst response and ensuring continuity of SOC operations.
  • Maintain incident response documentation and post-incident reporting in ServiceNow.

SOC Security Analyst

University of Texas at San Antonio // San Antonio, TX

  • Monitored Windows and Linux security events using Splunk, Microsoft Defender, Carbon Black, and ExtraHop.
  • Correlated alerts from Abnormal AI and DUO Admin to determine severity and mitigation steps.
  • Conducted vulnerability assessments and risk analysis to identify and remediate security gaps.
  • Built and optimized Splunk searches and dashboards for real-time threat detection.
  • Assisted security engineers with Python scripting and automation of security monitoring tasks using ExtraHop.
  • Supported incident response with chain of custody procedures for secure device handoff.
  • Mentored and trained 15+ interns each semester on SOC workflows and security best practices.

IT Apprentice

El Paso Independent School District // El Paso, TX

  • Set up and imaged computer labs across multiple schools in the district, roughly 30 machines per lab, configuring OS installations and standard software loadouts.
  • Connected lab workstations to the network and verified Wi-Fi connectivity as part of new setup and deployment.
  • Installed, configured, and troubleshot software across lab machines to ensure readiness for classroom use.
  • Diagnosed and resolved hardware issues, building early hands-on experience with Windows file systems and application deployment paths that later shaped how I approach security investigations.
Live Feed