Antonio Beltran-Miller
SOC Analyst · Detection & Automation · Bug Bounty Researcher
Security+ certified professional transitioning into a SOC role. I build detections and automation in my home lab, deploy honeypots to capture real-world threat telemetry, and conduct bug bounty research to analyze practical intrusion techniques.
I spent about two and a half years as the only IT person for a 200-person logistics company, so I know what a normal Windows and Active Directory environment looks like and how to keep people working while something is broken.
Since then I have been building toward security operations on purpose: a Splunk, n8n, and GPT-4 alert-triage pipeline in my lab, distributed T-Pot honeypots for live attack data, and responsible bug bounty disclosure. I would rather show a smaller number I can defend than a big one I cannot.
Where I'm ready to contribute
Things I built, and what they taught me
Home-lab detection work and bug bounty research. Each write-up is honest about what I built, what I based it on, and what the screenshots actually show.
Investigation write-ups
Short reports on real honeypot events and an incident response case, written the way I would hand them to another analyst.
Tools I actually use
Grouped by what I reach for, not rated on a scale. Most of these show up in the projects above.
SIEM & detection
Security operations
Systems & cloud
Automation & tooling
Certifications
Verifiable where a badge exists. In-progress items are marked as such, so nothing aspirational is dressed up as earned.
CompTIA Security+
CompTIA
CompTIA CySA+
CompTIA
LetsDefend SOC Analyst Path
LetsDefend
Google Cybersecurity Professional
Coursera / Google
Fortinet Certified Associate
Fortinet
Fortinet FortiGate 7.6 Operator
Fortinet
AWS Security Best Practices
AWS Training
SailPoint Identity Security Leader
SailPoint
Experience & education
I am early in my security career and would rather say so plainly. My IT foundation is the ALM Freight role; the delivery jobs are how I have paid the bills while studying.
Dispatcher (sole IT resource)
ALM Freight
- ▸Only IT resource for a 200-person, two-site logistics operation with no dedicated IT department.
- ▸Managed the endpoint fleet across Windows 10 workstations and 42 Android devices via 42Gears MDM, with manual patch management across the full fleet.
- ▸Administered Active Directory (user provisioning, account management, and group policy), and onboarded new employees from a standardized least-privilege Windows image.
- ▸Primary technical contact for 200+ drivers, resolving delivery-software and device failures in real time.
Delivery Associate
MMML (Amazon DSP)
Delivery Associate
DBE Logistics (Amazon DSP)
Assembly Technician
Contour Windows
B.S. Cybersecurity & Information Assurance
Western Governors University
Online · expected 2027
Contact
Let's talk
I'm looking for a SOC Analyst or detection role and I'm prepared for rotating shifts. Happy to walk through any of these projects live, including what I'd do differently.
Based in Ann Arbor, MI. Open to onsite in the Detroit metro, hybrid, or remote, and ready for rotating and off-hours SOC coverage.




