Cybersecurity @ UTSA

Nicolas Portilla Gomez

OT security and detection engineering.

I monitored production OT alerts in Dragos inside a regulated critical infrastructure energy environment at Marathon Petroleum. In industrial control systems coursework I analyzed how Suricata and Zeek detect live DNP3 and Modbus attacks, and I maintain my own Sigma detections mapped to MITRE ATT&CK. Graduating December 2026.

  • CompTIA Security+
  • AWS Cloud Practitioner
  • Microsoft AZ-900
  • Google Cybersecurity Cert
  • SC-200 in progress
pathway.log

The path into OT security

Every entry below is real, dated, and verifiable. Enterprise security operations first, then production OT monitoring, now the detection engineering and networking depth that industrial environments run on.

  1. 2024 to 2025 [INFO]

    Security and cloud foundations

    CompTIA Security+, AWS Cloud Practitioner, Microsoft AZ-900, and the Google Cybersecurity Certificate, alongside core work in Azure, AWS, networking, and Python.

  2. AUG to DEC 2025 [INFO]

    Cloud security · Trevenx

    Built an AWS SIEM pipeline forwarding GuardDuty findings through S3 and Firehose into OpenSearch, with dashboards and high severity alerting.

  3. MAY to AUG 2026 [ALERT]

    IT and OT security operations · Marathon Petroleum

    Monitored and investigated OT alerts in Dragos inside a regulated critical infrastructure energy environment, extending coverage across converged IT and OT. Owned alerts end to end in a flat SOC across Google SecOps, CrowdStrike Falcon, and Microsoft Defender.

  4. 2026 [INFO]

    Industrial control systems security · UTSA

    Coursework attacking and defending simulated plant networks. Ran DNP3 Direct Operate and Modbus coil write attacks, analyzed how Suricata and Zeek caught them, compared rule fidelity, and wrote up the defenses. Write ups below.

  5. NOW [ACTIVE]

    SC-200

    Studying for the Microsoft Security Operations Analyst certification, targeted for late October, to formalize the SIEM and detection work I did day to day at Marathon.

  6. DEC 2026 to 2027 [QUEUED]

    Graduation, then deeper into OT

    Graduating from UTSA in December 2026 (BBA Cybersecurity, 3.75 GPA) and targeting SOC and detection roles. CCNA planned for spring 2027 to harden the networking foundation OT depends on, then ISA/IEC 62443 Cybersecurity Fundamentals Specialist in summer 2027.

ot/

OT and ICS security

At Marathon Petroleum I monitored production OT alerts in Dragos inside a regulated energy environment. In industrial control systems coursework at UTSA I worked the other side of that screen: running live protocol attacks in simulated plant networks and analyzing what the sensors did and did not catch. The rules and environments came from the course. The analysis, the fidelity comparisons, and the defense recommendations in both write ups below are mine.

OTForge · Ironhorse Midstream

Catching a DNP3 Direct Operate with Suricata and Zeek

An unauthorized compressor start command on a simulated natural gas gathering network, and what it takes to catch it. Why a raw byte match rule drowns in false positives where an application layer rule stays quiet, and what changes when the sensor moves from alerting to blocking.

  • Suricata
  • Zeek
  • DNP3
  • IDS and IPS
Read the write up →

OTForge · Meridian Petrochemical

TRITON/TRISIS: defending a safety instrumented system

An attack that pivots through an IP camera left on factory credentials, reaches a petrochemical OT network, and writes a Modbus coil to a Triconex safety controller. Why detection here has to be scoped by destination address: the safety system and the process controller are indistinguishable on the wire.

  • Modbus
  • Triconex SIS
  • XENOTIME
  • Pivoting
Read the write up →
rules/

Detection work (enterprise)

The enterprise side of the same practice. A small, growing library of platform agnostic Sigma rules mapped to MITRE ATT&CK, where one rule converts to KQL (Sentinel), SPL (Splunk), or YARA-L (Google SecOps). The point is not collecting rules, it is showing the thinking: technique → log source → logic → fidelity and tuning. Every rule here is fully documented before the next one starts.

Detection Tactic Technique Log source
Windows Security event log cleared Defense Impairment T1685.005 Windows Security (1102)
Shadow copy deletion via vssadmin Impact T1490 Windows process creation
Browse the rules and write ups →

Each rule ships with a write up covering detection logic, expected false positives, and tuning notes.

cloud/

Cloud projects

Detections are only as good as your understanding of the environment they run in. These builds are the cloud and infrastructure foundation underneath the security work.

AWS

AWS SIEM log analysis pipeline

A cloud native SIEM built during my Trevenx internship. GuardDuty findings are forwarded through S3 and Firehose into OpenSearch for centralized log analysis, dashboards that update in real time, and high severity alert triggers. Lives under the Trevenx org.

  • GuardDuty
  • OpenSearch
  • S3
  • Firehose
  • VPC
Azure

Azure administration lab series

14 documented labs covering identity, governance, networking, storage, compute, containers, data protection, and monitoring. Each lab is written up as its own report. Browse the index below.

  • Entra ID
  • RBAC
  • ARM and Bicep
  • AKS
  • Azure Monitor
experience/

Where I have done the work

Cybersecurity Incident Detection & Response Intern

May 2026 to Aug 2026

Marathon Petroleum

  • Monitored and investigated OT security alerts in Dragos inside a regulated critical infrastructure energy environment, extending detection and threat hunting coverage across converged IT and OT systems.
  • Owned alerts end to end in a flat SOC, triaging and investigating in Google SecOps, CrowdStrike Falcon, and Microsoft Defender from first alert through root cause analysis and closure.
  • Identified a manual reporting bottleneck and designed an AI assisted notification workflow in Google SecOps, cutting analyst drafting time from over 12 minutes to a single click.
  • Used Falcon Real Time Response to collect host artifacts, contain, and remediate threats; built automated CrowdStrike response workflows supported by Python and PowerShell.
  • Enriched investigations with Recorded Future, VirusTotal, and Proofpoint; supported IAM in Entra ID and GCP under least privilege and documented every investigation in ServiceNow.

Cloud Security Intern

Aug 2025 to Dec 2025

Trevenx

  • Selected to the intern team for sustained open source contributions across EDR, threat modeling, cloud security, and compliance automation.
  • Implemented the GuardDuty → S3 → OpenSearch SIEM pipeline for log analysis and visualization in real time.

Level 1 Help Desk Technician

Jul 2025 to Aug 2025

TEKsystems (contracted to NRTC)

  • Resolved 30+ weekly service requests across VoIP, IPTV, and DSL for 40+ rural ISPs, holding a 92%+ first call resolution rate.
  • Operated 13+ diagnostic and CLI tools (Calix, SmartRG, Plume) to isolate the root cause of network outages, cutting average customer downtime by 15 to 30 minutes.
  • Coordinated escalations with Tier 2, NOC, and vendor teams through ServiceNow and Zendesk.

EMT-B

Dec 2022 to Sep 2025

Allegiance Mobile Health

  • 100+ emergency responses with rapid triage, cross team coordination, and calm decisions under real pressure. Trained 3+ new EMTs on unit protocols and radio procedures.

Detection & response

  • CrowdStrike Falcon
  • Microsoft Defender
  • Google SecOps
  • Sigma
  • MITRE ATT&CK
  • Dragos (OT)
  • Recorded Future
  • Proofpoint
  • Suricata
  • Zeek

Cloud & identity

  • Azure
  • AWS
  • Entra ID
  • GCP IAM
  • Wiz
  • Docker

Automation & analysis

  • Python
  • PowerShell
  • Bash
  • SQL
  • Git
  • Wireshark

OT / ICS

  • DNP3
  • Modbus
  • SCADA
  • Safety systems (SIS)
  • IEC 61511
  • Purdue model

Frameworks & process

  • NIST CSF
  • ISO 27001
  • OWASP
  • ServiceNow
  • Agile
contact/

Get in touch

Open to Fall 2026 internships and entry-level detection engineering or SOC roles. The fastest way to reach me is email or LinkedIn.