I have spent most of my career working in the oil and gas industry as a production specialist, including time in emergency management as both a field operator and control room operator. That work put me in the middle of real time incident response: monitoring for anomalies, triaging fast, and containing situations before they escalated. Cybersecurity, and the SOC in particular, felt like a natural extension of that instinct, applied to protecting critical infrastructure on the digital side instead of the physical side.
I'm currently transitioning into cybersecurity and looking for remote, entry-level SOC or analyst roles where I can build hands-on experience responding to and managing real threats. Alongside my home SOC lab pack, I am currently completing an internship with Expadox Limited, cohort 3, where I have helped build a DevSecOps and SOAR automation pipeline, a vulnerability assessment and endpoint protection setup for a healthcare logistics firm, and a security monitoring environment for a logistics company. These are published by Expadox on LinkedIn. I'm currently collaborating with a team on IdentityForge, an identity and access management project for a client, VitalGov, as the capstone project closing out the internship. I've also completed several labs on Forage.
My current technical focus includes SIEM, endpoint detection and response, vulnerability management, security monitoring, incident response, and security automation, with hands-on work using tools such as Wazuh, Splunk, Action1, Zeek, Sysmon, Tailscale, etc.
Longer term, I'm interested in moving into governance, risk, and compliance. I hold an MSc in project management and a PMP certification, both of which line up naturally with that work: structured planning, risk thinking, and cross-team coordination. There's no fixed timeline for that shift, it's a direction I expect to grow into as I build depth on the technical side first.
SIEM alert triage and rule tuning (Wazuh, Splunk)
Traffic and packet analysis (Zeek, Suricata, Wireshark, Cisco Packet Tracer)
Case triage and response workflows (TheHive, Cortex)
IOC enrichment and analysis (VirusTotal, CyberChef)
Scanning and remediation tracking (Trivy)
SOAR playbook design (Shuffle)
Static/dynamic scanning and secret detection (Burp Suite, OWASP ZAP, Semgrep, Gitleaks)
Endpoint management, secure remote access, containerization (Action1, Tailscale, Docker)