Security Operations · SOC Shift Lead

SOC leadership built from the data center up.

Eight years across IT operations and security. Now leading shift coverage in a multi-tenant MSSP — mentoring analysts and building the runbooks, training environments, and tools that turn shift knowledge into team capability.

/ dashboard · live

The full picture.

Credentials, projects, activity, capabilities, and writing — the things that hold up under scrutiny.

// credentials · 04 active

Full list →

CompTIA

Security+

Verify

CompTIA

CySA+

Verify

EC-Council

CEH

Verify

Microsoft

Azure Fundamentals

Active

// throughline

Making tribal SOC knowledge teachable.

My background runs from county government IT and vocational instruction through data center administration at Aptum. I eventually moved into an InfoSec analyst role there before joining CyberSheath in 2022.

Read the long version →

// project

Active

BASTION

KQL investigation toolkit that ends the rebuild-from-scratch loop

  • 20+ KQL hunt templates
  • 7 detection categories
  • Single-file HTML deploy
Case study →

// project

Active

CARL

Offline SOC knowledge base that captures what lives in analysts' heads

  • 500+ knowledge entries
  • 8 dispatch engines
  • 11 alert playbooks
Case study →

// project · featured

Active

KQL Sentinel Lab

Synthetic Sentinel environment for analysts to practice on real attack data

  • 55 attack scenarios
  • 14 MITRE techniques
  • 6 tactic groups
Case study →

// capabilities

Full breakdown →

What I work on.

Leadership & Mentorship

  • Shift leadership
  • Junior analyst mentoring
  • Incident command
  • Stakeholder communication

Enablement & Training

  • Onboarding curriculum
  • Runbook authorship
  • Lab and training environment design
  • Knowledge base curation

Detection & Response

  • KQL
  • Microsoft Sentinel
  • Google SecOps
  • Alert triage

SOC Operations

  • Coverage planning
  • Analyst coaching
  • Alert volume tuning
  • Metrics reporting

// now · may 2026

More →

Currently on the desk.

Running shift coverage at CyberSheath — coordinating triage across analysts, owning runbook drift, and pulling escalations when the queue gets noisy. Refining detection content in Sentinel and Google SecOps with a focus on tuning out the alerts that always end in dismissal.

// experience · recent

Full history →
  • Oct 2022 – Present Current

    CyberSheath · Cyber Security Analyst · SOC Shift Lead

  • May 2021 – Oct 2022

    Aptum · Information Security Analyst

  • Jun 2019 – May 2021

    Aptum · Data Center Administrator

/ activity · 661 contributions

Building in the open.

@SaltyCarl ↗

May 2025 – May 2026

0 contributions on 2025-05-040 contributions on 2025-05-050 contributions on 2025-05-060 contributions on 2025-05-070 contributions on 2025-05-080 contributions on 2025-05-090 contributions on 2025-05-100 contributions on 2025-05-110 contributions on 2025-05-120 contributions on 2025-05-130 contributions on 2025-05-140 contributions on 2025-05-150 contributions on 2025-05-160 contributions on 2025-05-170 contributions on 2025-05-180 contributions on 2025-05-190 contributions on 2025-05-200 contributions on 2025-05-210 contributions on 2025-05-220 contributions on 2025-05-230 contributions on 2025-05-240 contributions on 2025-05-250 contributions on 2025-05-260 contributions on 2025-05-270 contributions on 2025-05-280 contributions on 2025-05-290 contributions on 2025-05-300 contributions on 2025-05-310 contributions on 2025-06-010 contributions on 2025-06-020 contributions on 2025-06-030 contributions on 2025-06-040 contributions on 2025-06-050 contributions on 2025-06-060 contributions on 2025-06-070 contributions on 2025-06-080 contributions on 2025-06-090 contributions on 2025-06-100 contributions on 2025-06-110 contributions on 2025-06-120 contributions on 2025-06-130 contributions on 2025-06-140 contributions on 2025-06-150 contributions on 2025-06-160 contributions on 2025-06-170 contributions on 2025-06-180 contributions on 2025-06-190 contributions on 2025-06-200 contributions on 2025-06-210 contributions on 2025-06-220 contributions on 2025-06-230 contributions on 2025-06-240 contributions on 2025-06-250 contributions on 2025-06-260 contributions on 2025-06-270 contributions on 2025-06-280 contributions on 2025-06-290 contributions on 2025-06-300 contributions on 2025-07-010 contributions on 2025-07-020 contributions on 2025-07-030 contributions on 2025-07-040 contributions on 2025-07-050 contributions on 2025-07-060 contributions on 2025-07-070 contributions on 2025-07-080 contributions on 2025-07-090 contributions on 2025-07-100 contributions on 2025-07-110 contributions on 2025-07-120 contributions on 2025-07-130 contributions on 2025-07-140 contributions on 2025-07-150 contributions on 2025-07-160 contributions on 2025-07-170 contributions on 2025-07-180 contributions on 2025-07-190 contributions on 2025-07-200 contributions on 2025-07-210 contributions on 2025-07-220 contributions on 2025-07-230 contributions on 2025-07-240 contributions on 2025-07-250 contributions on 2025-07-260 contributions on 2025-07-270 contributions on 2025-07-280 contributions on 2025-07-290 contributions on 2025-07-300 contributions on 2025-07-310 contributions on 2025-08-010 contributions on 2025-08-020 contributions on 2025-08-030 contributions on 2025-08-040 contributions on 2025-08-050 contributions on 2025-08-060 contributions on 2025-08-070 contributions on 2025-08-080 contributions on 2025-08-090 contributions on 2025-08-100 contributions on 2025-08-110 contributions on 2025-08-120 contributions on 2025-08-130 contributions on 2025-08-140 contributions on 2025-08-150 contributions on 2025-08-160 contributions on 2025-08-170 contributions on 2025-08-180 contributions on 2025-08-190 contributions on 2025-08-200 contributions on 2025-08-210 contributions on 2025-08-220 contributions on 2025-08-230 contributions on 2025-08-240 contributions on 2025-08-250 contributions on 2025-08-260 contributions on 2025-08-270 contributions on 2025-08-280 contributions on 2025-08-290 contributions on 2025-08-300 contributions on 2025-08-310 contributions on 2025-09-010 contributions on 2025-09-020 contributions on 2025-09-030 contributions on 2025-09-040 contributions on 2025-09-050 contributions on 2025-09-060 contributions on 2025-09-070 contributions on 2025-09-080 contributions on 2025-09-090 contributions on 2025-09-100 contributions on 2025-09-110 contributions on 2025-09-120 contributions on 2025-09-130 contributions on 2025-09-140 contributions on 2025-09-150 contributions on 2025-09-160 contributions on 2025-09-170 contributions on 2025-09-180 contributions on 2025-09-190 contributions on 2025-09-200 contributions on 2025-09-210 contributions on 2025-09-220 contributions on 2025-09-230 contributions on 2025-09-240 contributions on 2025-09-250 contributions on 2025-09-260 contributions on 2025-09-270 contributions on 2025-09-280 contributions on 2025-09-290 contributions on 2025-09-300 contributions on 2025-10-010 contributions on 2025-10-020 contributions on 2025-10-030 contributions on 2025-10-040 contributions on 2025-10-050 contributions on 2025-10-060 contributions on 2025-10-070 contributions on 2025-10-080 contributions on 2025-10-090 contributions on 2025-10-100 contributions on 2025-10-110 contributions on 2025-10-120 contributions on 2025-10-130 contributions on 2025-10-140 contributions on 2025-10-150 contributions on 2025-10-160 contributions on 2025-10-170 contributions on 2025-10-180 contributions on 2025-10-190 contributions on 2025-10-200 contributions on 2025-10-210 contributions on 2025-10-220 contributions on 2025-10-230 contributions on 2025-10-240 contributions on 2025-10-250 contributions on 2025-10-260 contributions on 2025-10-270 contributions on 2025-10-280 contributions on 2025-10-290 contributions on 2025-10-300 contributions on 2025-10-310 contributions on 2025-11-010 contributions on 2025-11-020 contributions on 2025-11-030 contributions on 2025-11-040 contributions on 2025-11-050 contributions on 2025-11-060 contributions on 2025-11-070 contributions on 2025-11-080 contributions on 2025-11-090 contributions on 2025-11-100 contributions on 2025-11-110 contributions on 2025-11-120 contributions on 2025-11-130 contributions on 2025-11-140 contributions on 2025-11-150 contributions on 2025-11-160 contributions on 2025-11-170 contributions on 2025-11-180 contributions on 2025-11-190 contributions on 2025-11-200 contributions on 2025-11-210 contributions on 2025-11-220 contributions on 2025-11-230 contributions on 2025-11-240 contributions on 2025-11-250 contributions on 2025-11-260 contributions on 2025-11-270 contributions on 2025-11-280 contributions on 2025-11-290 contributions on 2025-11-300 contributions on 2025-12-010 contributions on 2025-12-020 contributions on 2025-12-030 contributions on 2025-12-040 contributions on 2025-12-050 contributions on 2025-12-060 contributions on 2025-12-070 contributions on 2025-12-080 contributions on 2025-12-090 contributions on 2025-12-100 contributions on 2025-12-110 contributions on 2025-12-120 contributions on 2025-12-130 contributions on 2025-12-140 contributions on 2025-12-150 contributions on 2025-12-160 contributions on 2025-12-170 contributions on 2025-12-180 contributions on 2025-12-190 contributions on 2025-12-200 contributions on 2025-12-210 contributions on 2025-12-220 contributions on 2025-12-230 contributions on 2025-12-240 contributions on 2025-12-250 contributions on 2025-12-260 contributions on 2025-12-270 contributions on 2025-12-280 contributions on 2025-12-290 contributions on 2025-12-300 contributions on 2025-12-310 contributions on 2026-01-010 contributions on 2026-01-020 contributions on 2026-01-030 contributions on 2026-01-040 contributions on 2026-01-050 contributions on 2026-01-060 contributions on 2026-01-070 contributions on 2026-01-082 contributions on 2026-01-090 contributions on 2026-01-100 contributions on 2026-01-110 contributions on 2026-01-120 contributions on 2026-01-130 contributions on 2026-01-142 contributions on 2026-01-150 contributions on 2026-01-160 contributions on 2026-01-170 contributions on 2026-01-182 contributions on 2026-01-191 contribution on 2026-01-201 contribution on 2026-01-210 contributions on 2026-01-220 contributions on 2026-01-230 contributions on 2026-01-240 contributions on 2026-01-250 contributions on 2026-01-260 contributions on 2026-01-273 contributions on 2026-01-2832 contributions on 2026-01-298 contributions on 2026-01-300 contributions on 2026-01-310 contributions on 2026-02-010 contributions on 2026-02-020 contributions on 2026-02-030 contributions on 2026-02-040 contributions on 2026-02-052 contributions on 2026-02-060 contributions on 2026-02-070 contributions on 2026-02-080 contributions on 2026-02-090 contributions on 2026-02-100 contributions on 2026-02-110 contributions on 2026-02-121 contribution on 2026-02-130 contributions on 2026-02-140 contributions on 2026-02-1510 contributions on 2026-02-1614 contributions on 2026-02-170 contributions on 2026-02-180 contributions on 2026-02-190 contributions on 2026-02-204 contributions on 2026-02-219 contributions on 2026-02-2215 contributions on 2026-02-235 contributions on 2026-02-2414 contributions on 2026-02-252 contributions on 2026-02-266 contributions on 2026-02-270 contributions on 2026-02-280 contributions on 2026-03-012 contributions on 2026-03-023 contributions on 2026-03-036 contributions on 2026-03-0410 contributions on 2026-03-0531 contributions on 2026-03-062 contributions on 2026-03-0711 contributions on 2026-03-083 contributions on 2026-03-090 contributions on 2026-03-104 contributions on 2026-03-1148 contributions on 2026-03-1218 contributions on 2026-03-130 contributions on 2026-03-140 contributions on 2026-03-1521 contributions on 2026-03-167 contributions on 2026-03-179 contributions on 2026-03-189 contributions on 2026-03-195 contributions on 2026-03-200 contributions on 2026-03-210 contributions on 2026-03-221 contribution on 2026-03-232 contributions on 2026-03-240 contributions on 2026-03-2527 contributions on 2026-03-260 contributions on 2026-03-270 contributions on 2026-03-280 contributions on 2026-03-290 contributions on 2026-03-300 contributions on 2026-03-311 contribution on 2026-04-0117 contributions on 2026-04-020 contributions on 2026-04-030 contributions on 2026-04-040 contributions on 2026-04-050 contributions on 2026-04-060 contributions on 2026-04-071 contribution on 2026-04-0812 contributions on 2026-04-090 contributions on 2026-04-100 contributions on 2026-04-110 contributions on 2026-04-120 contributions on 2026-04-136 contributions on 2026-04-143 contributions on 2026-04-150 contributions on 2026-04-169 contributions on 2026-04-170 contributions on 2026-04-1817 contributions on 2026-04-190 contributions on 2026-04-200 contributions on 2026-04-210 contributions on 2026-04-2258 contributions on 2026-04-233 contributions on 2026-04-240 contributions on 2026-04-250 contributions on 2026-04-260 contributions on 2026-04-278 contributions on 2026-04-2818 contributions on 2026-04-2924 contributions on 2026-04-300 contributions on 2026-05-010 contributions on 2026-05-020 contributions on 2026-05-0336 contributions on 2026-05-0431 contributions on 2026-05-0543 contributions on 2026-05-0614 contributions on 2026-05-078 contributions on 2026-05-08
LessMore

/ contact

Got an interesting SOC problem?

I'm always open to hiring conversations, collaboration, or comparing notes on detection programs and SOC tooling.