Open to SOC Analyst & detection roles

Antonio Beltran-Miller

Tier 1 SOC Analyst candidate · Alert triage & detection

Security+ certified and moving into a Tier 1 SOC role. I work alerts end to end on LetsDefend, write and tune Splunk detections in a five-VM home lab, and ran a T-Pot honeypot to study live attack traffic.

Available for rotating and off-hours shifts · Onsite in the Detroit metro, hybrid, or remote

Ann Arbor, Michigan GitHub LinkedIn Email

I spent about two and a half years as the only IT person for a 200-person logistics company, so I know what a normal Windows and Active Directory environment looks like and how to keep people working while something is broken.

Cases & projects

Alert triage first, then the lab work behind it

A full alert investigation, the detection lab where I write and tune rules, and the honeypot where I study live attack traffic. Each one says what I built, what it was based on, and what the evidence shows.

Other research: Blind XSS Capture Tool

Credentials

Certifications

Verifiable where a badge exists.

CompTIA Security+

CompTIA

October 2025
Threat detection & responseRisk & vulnerability managementNetwork securityCryptography & PKI
Verify

CompTIA CySA+

CompTIA

In progress · expected October 2026
Behavioral analyticsThreat huntingIncident responseVulnerability management

LetsDefend SOC Analyst Path

LetsDefend

February 2025
SIEM analysisAlert triageMalware analysisIncident response
Verify

Google Cybersecurity Professional

Coursera / Google

November 2024
Python automationLinux & SQLSIEM toolsNIST frameworks
Verify

Also completed: Fortinet Certified Associate (August 2025) · Fortinet FortiGate 7.6 Operator (August 2025) · AWS Security Best Practices (2025) · SailPoint Identity Security Leader (2025)

Background

Experience & education

My IT foundation is two and a half years as the sole IT resource at ALM Freight. Since 2024 I have worked delivery full time while building the lab work above and studying for CySA+.

Dispatcher (sole IT resource)

ALM Freight

Sep 2021 to May 2024
  • ▸Only IT resource for a 200-person, two-site logistics operation with no dedicated IT department.
  • ▸Managed the endpoint fleet across Windows 10 workstations and 42 Android devices via 42Gears MDM, with manual patch management across the full fleet.
  • ▸Administered Active Directory (user provisioning, account management, and group policy), and onboarded new employees from a standardized least-privilege Windows image.
  • ▸Primary technical contact for 200+ drivers, resolving delivery-software and device failures in real time.

Delivery Associate

MMML (Amazon DSP)

Sep 2025 to present

Delivery Associate

DBE Logistics (Amazon DSP)

May 2024 to Aug 2025

Assembly Technician

Contour Windows

Aug 2019 to Aug 2021

B.S. Cybersecurity & Information Assurance

Western Governors University

Online · expected 2027

Contact

Let's talk

I'm looking for a SOC Analyst or detection role and I'm prepared for rotating shifts. Happy to walk through any of these projects live, including what I'd do differently.

Based in Ann Arbor, MI. Open to onsite in the Detroit metro, hybrid, or remote, and ready for rotating and off-hours SOC coverage.