Cyber Defense Analyst

Angelina Sanchez

Cyber Defense Analyst with experience across classified security operations, Department of Defense environments, incident response, threat detection, and signals intelligence. Currently pursuing a Master of Science in Cybersecurity at Southern New Hampshire University while continuing to expand expertise in advanced cyber defense and security engineering.

Core competencies

  • SOC Operations & Incident Response
  • Threat Detection & Cyber Analysis
  • SIEM Detection & Tuning
  • Splunk
  • Microsoft Sentinel
  • Elastic SIEM
  • Trellix
  • ACAS / Tenable.sc
  • Tanium
  • QMulos
  • Malware Analysis & IOC Identification
  • Network Forensics & Traffic Analysis
  • SIGINT & Digital Network Intelligence
  • Vulnerability Management
  • Classified Computing Environments

Professional highlights

Cyber Defense

SOC & Incident Response

Defense Industry

Mission-Critical Environments

Intelligence

SIGINT Background

Clearance

TS/SCI w/ CI Poly

Certifications

Security+ • CySA+

Graduate Education

M.S. Cybersecurity — In Progress

Career path

  1. Homeland Security

    B.S. Criminal Justice

  2. SIGINT & Intelligence

    U.S. Navy Reserve CTR1

  3. Cyber Defense

    SOC & Incident Response

  4. Advanced Cybersecurity Education

    M.S. Cybersecurity

From a foundation in homeland security and criminal justice, through signals intelligence and cyber defense operations, to advanced graduate study in cybersecurity — each step builds toward deeper technical and senior security responsibility.

Experience

  1. Feb 2026 — Present

    Cyber Defense Analyst

    Lockheed Martin · Orlando, FL

    • Monitor and analyze cybersecurity alerts in a classified Security Operations Center, validating and escalating threats to mission-critical systems.
    • Conduct incident investigations and network traffic analysis, documenting findings and supporting containment and mitigation.
    • Develop and refine detection content with cybersecurity stakeholders to strengthen threat visibility across classified environments.
  2. May 2024 — Jan 2026

    Cyber Defense Analyst

    Leidos (supporting DISA) · Scott AFB, IL

    • Served as initial point of contact for security operations and incident escalation across classified systems.
    • Correlated alerts from Splunk, Microsoft Sentinel, Elastic and Trellix to identify malicious activity and determine root cause.
    • Built and tuned SIEM content — correlation searches, dashboards and alerts — to improve detection and prevention.
    • Coordinated containment with internal and external stakeholders including DISA and USCYBERCOM.
  3. Mar 2021 — Present

    Cryptologic Technician (CTR1)

    U.S. Navy Reserves

    • Deliver signals intelligence (SIGINT) and digital network intelligence supporting national defense operations.
    • Support cyber threat identification and reporting aligned to DoD INFOSEC and OPSEC standards.
    • Handle and disseminate classified intelligence products with 100% compliance.
  4. Jan 2023 — Jul 2023

    Administrative Assistant

    Chenega CABS · NAWCTSD

    • Supported technical and administrative functions for Navy training operations.
    • Improved documentation processing time by 30% and raised training record compliance to 92% using ESAMS.
  5. Nov 2014 — Aug 2022

    Correctional Officer

    Florida DOC / Volusia County Detention Center

    • Maintained discipline and order within high-security environments.
    • Built rehabilitation and mentorship programs that improved behavioral outcomes by 35%.

Continuing to grow

Between graduate studies, professional cybersecurity work, independent technical projects, and hands-on labs, I continue developing deeper expertise across defensive security and security engineering.

  • Detection Engineering
  • Threat Hunting
  • Advanced Network Defense
  • Security Engineering
  • Cyber Threat Intelligence
  • Adversary Emulation
  • Incident Response
  • Risk Management

Active professional development

M.S. Cybersecurity — Southern New Hampshire University

In Progress

Certifications

CompTIA

CySA+ ce

CompTIA

Security Analytics Professional (CSAP)

CompTIA

Security+ ce

Active

ISC2

CISSP

In progress

Projects & labs

The visuals below are original conceptual illustrations built for this portfolio with fictional data. They are not screenshots of any employer, government or classified system.

SOC Monitoring Console

Conceptual Visualization
SOC · Monitoring ConsoleLIVE (SIMULATED)

Security events (24h)

1,284,730

Authentication activity

9,120142 failed

Network traffic events

48,210

Event timeline

Alert severity distribution

Critical8
High21
Medium44
Low27

Top detection categories

Credential Access82
Execution64
Defense Evasion51
Command & Control33
Persistence22

Threat indicators

IOC hits 14Known-bad IP 3Hash match 2Domain rep 5

Notable events

08:00HighSuspicious PowerShell Execution
08:02MediumMultiple Failed Authentication Attempts
08:04HighUnusual Outbound Connection
08:06CriticalEndpoint Malware Detection

Representative SOC Monitoring Workflow

Conceptual visualization representing experience monitoring, correlating, and investigating security events within enterprise SIEM environments.

  • Splunk
  • SIEM
  • SOC Operations
  • Threat Detection
  • Incident Analysis

Cloud Security Incident Investigation

Representative Workflow
IncidentSuspicious Account ActivitySeverity: HighUnder Investigation

Investigation graph

UserEndpointSuspicious IPCloud Resource
User Account

a.reyes@contoso-lab

Endpoint

WKSTN-0142

IP Address

203.0.113.47

Cloud Resource

storage-acct-prod-lab

Activity timeline

  1. 08:42 Authentication anomaly detected
  2. 08:44 Multiple failed login attempts
  3. 08:47 Successful authentication
  4. 08:49 Suspicious endpoint activity
  5. 08:53 Outbound connection detected
  6. 08:57 Incident escalated

Representative SIEM Investigation Workflow

Conceptual incident investigation demonstrating how security telemetry can be correlated across users, endpoints, network activity, and cloud resources.

  • Microsoft Sentinel
  • Incident Response
  • Threat Investigation
  • Security Analytics

Elastic SIEM Security Lab

Lab Recreation
Home Lab · Telemetry PipelineLab Recreation
  1. Kali Linux
  2. Elastic Agent
  3. Elastic Stack
  4. Detection Rules
  5. Security Alerts

Lab dashboard

Endpoint Events24,180
Network Connections11,402
Authentication Events3,975
Detection Rules37
Security Alerts12

Personal Lab Environment — Mar 2024

Built an Elastic Stack SIEM lab with Kali Linux and Elastic Agents to practice endpoint monitoring, detection engineering, dashboard creation, and security investigation.

  • Elastic
  • Kali Linux
  • SIEM
  • Detection Engineering
  • Endpoint Monitoring

Network Investigation

Conceptual Visualization
Network Investigation · Conceptual Topology Normal Suspicious
Workstation-01Domain-ControllerWeb-ServerDatabaseExternal-IP

Highlighted path: Workstation-01 → External-IP · unusual outbound connection flagged for review.

Representative Network Analysis Workflow

Conceptual topology showing routine internal traffic alongside a single anomalous outbound connection of the kind that triggers triage and deeper packet or flow analysis.

  • Network Forensics
  • Traffic Analysis
  • Threat Hunting
  • Anomaly Detection

May 2025

Verizon Cloud Platform Simulation — Forage

Used Python to assess a cloud VPN design for redundancy, resiliency and least privilege, then presented application security and risk mitigation findings.

From Telemetry to Detection

Modern cyber defense depends on turning large volumes of security telemetry into actionable detections. My work includes analyzing security events, investigating alerts, and helping refine detection logic to improve threat visibility.

Raw Security Events
Normalization
Correlation
Detection Rule
Security Alert
Analyst Investigation

Education

Southern New Hampshire University

Master of Science in Cybersecurity

In Progress

Currently pursuing a Master’s degree in Cybersecurity at Southern New Hampshire University, expanding knowledge in advanced cybersecurity concepts, risk management, security architecture, cyber defense, and organizational security.

Graduate Studies — In Progress

Florida Technical College

Bachelor of Science in Criminal Justice

Emphasis in Homeland Security

Completed a B.S. in Criminal Justice with a Homeland Security emphasis, building the foundation for a career spanning national security, intelligence, and cybersecurity.

Aug 2020

Open to cleared cyber defense roles.

SOC operations, detection engineering and incident response — on-site at cleared facilities or remote.