Every entry below is real, dated, and verifiable. Enterprise security operations first, then
production OT monitoring, now the detection engineering and networking depth that industrial
environments run on.
-
2024 to 2025 [INFO]
Security and cloud foundations
CompTIA Security+, AWS Cloud Practitioner, Microsoft AZ-900, and the Google Cybersecurity Certificate, alongside core work in Azure, AWS, networking, and Python.
-
AUG to DEC 2025 [INFO]
Cloud security · Trevenx
Built an AWS SIEM pipeline forwarding GuardDuty findings through S3 and Firehose into OpenSearch, with dashboards and high severity alerting.
-
MAY to AUG 2026 [ALERT]
IT and OT security operations · Marathon Petroleum
Monitored and investigated OT alerts in Dragos inside a regulated critical infrastructure energy environment, extending coverage across converged IT and OT. Owned alerts end to end in a flat SOC across Google SecOps, CrowdStrike Falcon, and Microsoft Defender.
-
2026 [INFO]
Industrial control systems security · UTSA
Coursework attacking and defending simulated plant networks. Ran DNP3 Direct Operate and Modbus coil write attacks, analyzed how Suricata and Zeek caught them, compared rule fidelity, and wrote up the defenses. Write ups below.
-
NOW [ACTIVE]
SC-200
Studying for the Microsoft Security Operations Analyst certification, targeted for late October, to formalize the SIEM and detection work I did day to day at Marathon.
-
DEC 2026 to 2027 [QUEUED]
Graduation, then deeper into OT
Graduating from UTSA in December 2026 (BBA Cybersecurity, 3.75 GPA) and targeting SOC and detection roles. CCNA planned for spring 2027 to harden the networking foundation OT depends on, then ISA/IEC 62443 Cybersecurity Fundamentals Specialist in summer 2027.