Open to SOC Analyst & detection roles

Antonio Beltran-Miller

SOC Analyst · Detection & Automation · Bug Bounty Researcher

Security+ certified professional transitioning into a SOC role. I build detections and automation in my home lab, deploy honeypots to capture real-world threat telemetry, and conduct bug bounty research to analyze practical intrusion techniques.

Ann Arbor, Michigan GitHub LinkedIn Email

I spent about two and a half years as the only IT person for a 200-person logistics company, so I know what a normal Windows and Active Directory environment looks like and how to keep people working while something is broken.

Since then I have been building toward security operations on purpose: a Splunk, n8n, and GPT-4 alert-triage pipeline in my lab, distributed T-Pot honeypots for live attack data, and responsible bug bounty disclosure. I would rather show a smaller number I can defend than a big one I cannot.

Projects & research

Things I built, and what they taught me

Home-lab detection work and bug bounty research. Each write-up is honest about what I built, what I based it on, and what the screenshots actually show.

Toolkit

Tools I actually use

Grouped by what I reach for, not rated on a scale. Most of these show up in the projects above.

SIEM & detection

Splunk (SPL, dashboards, alerts)Suricata rule writingSysmonWiresharkMicrosoft Sentinel (familiarity)

Security operations

Alert triageIncident response (NIST 800-61)Threat huntingIOC analysisMITRE ATT&CKDiamond Model

Systems & cloud

WindowsActive DirectoryLinuxTCP/IPAWS fundamentals (CloudWatch, GuardDuty, IAM, VPC)

Automation & tooling

PythonBashPowerShelln8nGPT-4 APIVirusTotal / AbuseIPDBMetasploitBurp Suitemitmproxy
Credentials

Certifications

Verifiable where a badge exists. In-progress items are marked as such, so nothing aspirational is dressed up as earned.

CompTIA Security+

CompTIA

October 2025
Threat detection & responseRisk & vulnerability managementNetwork securityCryptography & PKI
Verify

CompTIA CySA+

CompTIA

In progress · expected October 2026
Behavioral analyticsThreat huntingIncident responseVulnerability management

LetsDefend SOC Analyst Path

LetsDefend

February 2025
SIEM analysisAlert triageMalware analysisIncident response
Verify

Google Cybersecurity Professional

Coursera / Google

November 2024
Python automationLinux & SQLSIEM toolsNIST frameworks
Verify

Fortinet Certified Associate

Fortinet

August 2025
FortiGate configurationVPN (IPsec/SSL)IPS/IDSSecurity policy
Verify

Fortinet FortiGate 7.6 Operator

Fortinet

August 2025
FortiGate 7.6 operationsFirewall managementSystem monitoring
Verify

AWS Security Best Practices

AWS Training

2025
CloudWatch & GuardDutyVPC securityIAMMonitoring & alerting
Course completion (no public badge)

SailPoint Identity Security Leader

SailPoint

2025
Identity governanceAccess managementIAM strategy
Verify
Background

Experience & education

I am early in my security career and would rather say so plainly. My IT foundation is the ALM Freight role; the delivery jobs are how I have paid the bills while studying.

Dispatcher (sole IT resource)

ALM Freight

Sep 2021 – May 2024
  • ▸Only IT resource for a 200-person, two-site logistics operation with no dedicated IT department.
  • ▸Managed the endpoint fleet across Windows 10 workstations and 42 Android devices via 42Gears MDM, with manual patch management across the full fleet.
  • ▸Administered Active Directory (user provisioning, account management, and group policy), and onboarded new employees from a standardized least-privilege Windows image.
  • ▸Primary technical contact for 200+ drivers, resolving delivery-software and device failures in real time.

Delivery Associate

MMML (Amazon DSP)

Sep 2025 – present

Delivery Associate

DBE Logistics (Amazon DSP)

May 2024 – Aug 2025

Assembly Technician

Contour Windows

Aug 2019 – Aug 2021

B.S. Cybersecurity & Information Assurance

Western Governors University

Online · expected 2027

Contact

Let's talk

I'm looking for a SOC Analyst or detection role and I'm prepared for rotating shifts. Happy to walk through any of these projects live, including what I'd do differently.

Based in Ann Arbor, MI. Open to onsite in the Detroit metro, hybrid, or remote, and ready for rotating and off-hours SOC coverage.