Jose Antonio CalderonCyber security engineer
I'm a cybersecurity engineer with six years of experience. My skillset ranges from networking to incident response and forensics. I have prior experience with multiple security platforms. EDR tools: Crowdstrike Cortex Microsoft Defender SIEM tools: Splunk Qradar Sentinel Elastic Humio Email security platforms: Abnormal Proofpoint Network vendors: Palo Alto Cisco The use of these tools is often applied to provide insight on various incidents ranging from data protection (DLP), phishing campaigns, and malware detection (Ransomware, Trojans, Rootkits). This includes the creation of custom use cases to fit specific IoCs fed by intelligence sources (private and open source), as well as detecting anomalous behavior within infrastructure and client platforms.
Tech stack
Azure (4)
Splunk (4)
Security (2)
Management (2)
Windows (2)
Linux (2)
Networking (1)
Microsoft Windows (1)
Elasticsearch (1)
CrowdStrike (1)
JIRA
Cyber Security
Python
Windows PowerShell
Experience
Cyber Security EngineerSynopsys Inc
06/2024 - Currently

Here's the corrected text: As part of the CSIRT team (Cybersecurity Incident Response Team), my usual responsibilities are the following: - Handle the entire incident cycle: Preparation, Detection, Analysis, Containment, Eradication, and Recovery. This is accomplished using various security tools, including log analysis via Elasticsearch, endpoint event analysis through Crowdstrike or MS Intune, and real-time response to events linked to the initial incident. - Review reported cases through phishing mechanisms and analyze IoCs found within reported emails. Execute actions for IoCs identified as malicious. - Document investigation processes and improve current security controls. - Review proprietary tools' code to maintain security and sanitization. - Analyze forensic artifacts during containment to build incident timelines. - Exchange information with vendors regarding detected intelligence feeds that might have negative impacts.

CrowdStrike
Microsoft Windows
Elasticsearch
Azure
Cyber Security Consultant RADeloitte
10/2021 - 08/2024

- Incident analysis and management in XSOAR platform - Responding to requirements and alerts in ticketing service (Jira) - Active threat hunting and management on EDR platforms (MS Defender, Crowdstrike, Carbon Black, Crowdstrike) - Active search for possible anomalies or security risks to comply with customer guidelines. - Active threat hunting or possible modification of use cases on SIEM platforms (Splunk QRadar, Azure Sentinel)

Azure
Splunk
Level 2 Cybersecurity Analyst EntelEntel
03/2021 - 10/2021

- Handling and response to incidents through ticketing services - Triage and management of alerts with varying severity levels. - Active search for potential risks, vulnerabilities, or anomalies in SIEM platforms (McAfee Nitro, Splunk). - Designing use cases for new security requirements and adjusting threat scope for new clients. - Proactive hunting tasks to provide feedback on possible active risk campaigns on client platforms.

Splunk
Field EngineerProvida AFP
03/2020 - 03/2021

Responsible for implementation, administration and continuity process at Networking Department.

Networking
NOC EngineerNSP Chile
10/2019 - 03/2021

• Administration and monitoring of Cisco equipment through PRTG/LogicMonitor. • Ticket handling and support for Cisco products (Security, Wireless, Enterprise). • Management and configuration of VPNs on ASA/Firepower Firewalls. • Implementation and design of new networking projects

Management
Security
Cyber Security AnalystInfoSec Addicts
08/2018 - 10/2019

- Scanning and setup of Virtual Machines focused on Pentesting. - Multiple security mechanism integrity tests using various tools including: nmap, nikto, Wireshark, Nessus, Metasploit. - Privilege escalation across different operating systems (Windows and Linux distributions) for vulnerability detection.

Linux
Windows
Education
Cisco networking apreenticeCisco Networking Academy
02/2016 - 02/2017
Electronic Engineering: TelecomunicationsDr. Rafael Belloso Chacín
06/2014 - 05/2018