Cybersecurity Analyst
Willamette Shield Defense · Portland, OR
Jan, 2023 · Present
• Own detection content for a Splunk + CrowdStrike stack covering ~4,200 endpoints and 38 SaaS apps; reduced high-fidelity false positives 41% in 9 months.
• Lead vulnerability triage for AWS and Azure workloads; drove critical CVE remediation SLA from 21 days to 6 days median across product engineering.
• Built and tabletop-tested IR playbooks for ransomware, BEC, and supply-chain package compromise; cut MTTD from 4.2 hours to 52 minutes on phishing-led incidents.
• Partner with identity team on Conditional Access and privileged-access reviews; eliminated standing domain-admin on 11 legacy jump hosts.
• Author weekly threat briefings for leadership; mapped detections to MITRE ATT&CK and closed 23 coverage gaps in credential-access and lateral-movement tactics.
Security Operations Analyst
Columbia River Digital · Beaverton, OR
Mar, 2020 · Dec, 2022
• Triaged 80–120 SOC tickets/day across Microsoft Sentinel and EDR; maintained <15-minute P1 acknowledgment during business hours.
• Automated enrichment (VirusTotal, AbuseIPDB, internal CMDB) via Python + Logic Apps, saving ~9 analyst hours/week.
• Led containment for a contractor VPN credential-stuffing event affecting 64 accounts; coordinated forced resets and geo-block rules with zero customer data loss.
• Hardened Windows server baselines with CIS benchmarks; reduced critical findings on quarterly pen-test by 37% year-over-year.
• Mentored two junior analysts on alert triage, containment checklists, and ticket quality standards.
Junior Security Analyst
Rose City InfoSec Partners · Portland, OR
Jun, 2018 · Feb, 2020
• Supported managed SIEM monitoring for 12 regional clients (healthcare-adjacent and professional services); documented escalation paths and runbooks.
• Performed quarterly vulnerability scans (Nessus/Qualys) and produced prioritized remediation packages for IT owners.
• Assisted with phishing simulations and awareness campaigns; improved click-rate from 18% to 7% over three campaign cycles.
• Maintained asset inventory and firewall change tickets; audited rule cleanup that removed 140 unused allow rules.