Junior Cybersecurity Analyst focused on Security Operations Center (SOC), Blue Team operations, threat detection and incident response.
I specialize in building defensive security environments, analyzing security events, investigating indicators of compromise (IoC), and implementing monitoring solutions using enterprise security tools.
My approach combines:
- Defensive security operations.
- Network security.
- Threat intelligence.
- Security automation.
- Ethical hacking fundamentals.
Experience with:
- Security event monitoring.
- Log analysis.
- Alert triage.
- Incident investigation.
- Detection engineering fundamentals.
Tools:
- Wazuh SIEM.
- Splunk fundamentals.
- Windows Event Logs.
- Linux security logs.
Capabilities:
- IOC investigation.
- Malware behavior analysis fundamentals.
- Network anomaly detection.
- MITRE ATT&CK mapping.
- Incident response workflow.
Knowledge:
- TCP/IP analysis.
- VLAN segmentation.
- Firewall concepts.
- IDS/IPS fundamentals.
- Network traffic analysis.
Tools:
- Wireshark.
- Cisco Packet Tracer.
- Nmap.
A defensive Linux endpoint monitoring agent designed for:
- Endpoint telemetry collection.
- Network anomaly detection.
- Behavioral analysis.
- Automated defensive response.
- Wazuh SIEM integration.
Architecture:
Linux Endpoint
|
v
AetherGuard Agent
|
v
Detection Engine
|
v
Wazuh SIEM
|
v
SOC Analyst Investigation
Implemented security monitoring environment:
Features:
- Centralized log collection.
- Authentication monitoring.
- Brute-force detection.
- Threat intelligence enrichment.
- Alert investigation workflow.
Technologies:
- Wazuh.
- Docker.
- Linux.
- VirusTotal.
- AbuseIPDB.
Email security project focused on:
- Phishing detection.
- Email analysis.
- Threat intelligence enrichment.
- SOC workflow automation.
Technologies:
- Python.
- Docker.
- APIs.
- AI-assisted analysis.
| Category | Tools |
|---|---|
| SIEM | Wazuh, Splunk |
| Monitoring | Linux Logs, Windows Events |
| Threat Intelligence | VirusTotal, AbuseIPDB, OTX |
| Network Analysis | Wireshark |
| Detection | MITRE ATT&CK, Sigma concepts |
| Category | Tools |
|---|---|
| Recon | Nmap |
| Web Security | Burp Suite |
| Testing | Metasploit |
| OSINT | Security Research Tools |
Completed:
- Junior Cybersecurity Analyst
- Cybersecurity Fundamentals
- Network Security Foundations
- Security Blue Team pathway.
- SOC Analyst training.
- Threat Intelligence.
- Cloud Security Fundamentals.
| Domain | Level |
|---|---|
| SOC Monitoring | Junior |
| SIEM Operations | Junior+ |
| Threat Intelligence | Junior+ |
| Incident Response | Junior |
| Network Security | Junior+ |
| Linux Security | Junior+ |
| Security Automation | Junior |
"Security is not only detecting attacks, but understanding behavior, reducing risk and improving resilience."
I focus on building practical defensive solutions based on:
- Continuous monitoring.
- Evidence-based investigation.
- Automation.
- Security engineering principles.
LinkedIn: https://linkedin.com/in/joaquin_ocampo_cibersecurity
Portfolio: https://cyberzenithai.github.io/CyberShield-Portfolio/
GitHub: https://github.com/CyberZenithAI
Evidence-driven cybersecurity portfolio
Projects | Labs | Detection Engineering | SOC Operations