Cybersecurity profile · Professional experience
Russel Cyril R. Guiao
Senior Consultant · Cyber Security Analyst L2
Cybersecurity professional working across SOC operations, incident response, threat hunting, threat intelligence, client engagement, and network operations.
Experience
CyberQ Group, Pasig City, Philippines
Senior Consultant – Cyber Security Analyst L2
May 2024 – Present
- Shift Management & Analyst Support: Oversee shift operations, ensuring smooth workflows and proper analyst coverage. Responsible for managing Level 1 analysts by monitoring their investigations and handling escalated alerts. Conduct in-depth investigations on suspicious activities and provide real-time support to analysts.
- Process Improvement: Streamline SOC operations by organizing brown bag sessions for knowledge transfer, fostering continuous learning within the team. Regularly update playbooks and knowledge bases to ensure analysts have access to the latest procedures and threat information. Fine-tune alert rules and detection mechanisms to reduce false positives and improve detection accuracy.
- Incident Response: Act as a point of contact for on-demand incident response, assisting clients in investigating and mitigating malicious activities within their environments. Collaborate with clients to contain threats and provide remediation strategies.
- Threat Hunting: Proactively search for potential threats by analyzing network traffic, logs, and suspicious files or domains. Initiate hunts based on threat intelligence, behavioral anomalies, and emerging attack patterns to identify hidden threats within client environments.
- Threat Intelligence: Produce weekly threat intelligence reports, offering insights into emerging vulnerabilities, Indicators of Compromise (IoCs), and attack techniques. Deliver ad-hoc intelligence reports during urgent situations or high-profile vulnerabilities to help clients strengthen their defenses.
- Client Reporting & Communication: Present comprehensive monthly security reports to clients, tailored to both technical and non-technical audiences. Summarize security events, open incidents, and threat landscapes, while offering actionable recommendations to enhance client security postures.
- Ticket Auditing & Compliance: Conduct regular ticket audits to ensure SOC adherence to SLAs and company standards. Verify that alerts are thoroughly investigated, documented, and closed according to established protocols.
- GRC Support: Assist in Governance, Risk, and Compliance (GRC) tasks by contributing to the creation of certification documents. Support the company’s compliance efforts by ensuring security practices align with industry standards.
- Security Solutions & Tooling: Explore, test, and deploy security tools as part of Proof of Concept (POC) exercises. Investigate open-source security solutions to expand the SOC’s toolkit and capabilities.
- Ad-Hoc Client Support: Provide support for professional services requested by clients, such as custom technical assistance or specific investigations outside routine operations.
Tools & Technologies: Microsoft Defender, Azure Sentinel, SenseON, CrowdStrike
Logs: Palo Alto, Sonicwall, Office365, Network logs, Cisco, Avanan, Panda Security & etc
Verizon Inc, Alabang Muntinlupa, Philippines
Senior Consultant – Cyber Security Analyst II
February 2022 – March 2024
- Projects/Events: Cyber Security Incident Response Team – Assigned as senior threat analyst for Fédération internationale de football for corp and events: FIFA World Cup 2022, FIFA Women’s World Cup 2023.
- Monitor security alerts. Receives alerts and escalations from SOC to further investigate cyber security incidents.
- Log investigation, Analysis and recommendation on Service Now ticketing system for proper documentation.
- Identify IOCs in Phishing emails and other malicious attacks for blocking and further investigation.
- Create and Develop Playbook/Knowledge-base in Standard Operating Procedures in a SOC environment.
Ticketing: Service Now
SIEM & Tools: Splunk, Securonix SNYPR, Edgecast, Proofpoint, Anomali Threatstream, Azure Active Directory, Microsoft Defender Cloud Apps, WDATP/MDATP, Cisco Secure Endpoint, Cisco Umbrella, Palo Alto XSOAR, Zscaler Cloud, Zscaler Deception, Crowdstrike
Dnata/Emirates, Clark Field, Angeles City Pampanga
Cyber Security Analyst
Feb 2021 – Oct 2021
- Monitor organization from different security alert use cases (e.g. web exploits, Malicious file & internal user’s policy violation).
- Monitor organization’s networks for security breaches and investigate violations.
- Triage and identify IOCs in Phishing attacks via email for blocking and further forensic investigation.
- Prepare documented reports for security breaches and the extent of damage caused by attacks.
- Investigate, recommend and deploy virtual patching solutions.
- Block IOCs and suspicious threat actors once identified malicious intent.
Reporting: Daily Shift change report, Ticketing KPI report.
SIEM & Tools: Splunk, Mimecast, WDATP/MDATP, Etisalat Security
Uzado via Sargas Inc, Clark Field, Angeles City Pampanga
Security Analyst
Dec 2019 – Feb 2021
- Monitor and analyze traffic and alerts. Investigate and perform in-depth analysis of exploits.
- Provide network expertise to support timely and effective decision making of when to declare an incident.
- Conduct proactive threat research. Review security events that are populated in a Security Information and Event Management (SIEM) system.
- Analyze a variety of network and host-based security appliance logs to determine the correct remediation actions and escalation paths for each incident.
- Independently follow procedures to contain analyze and eradicate malicious activity.
- Document all activities during an incident and provide leadership with status updates.
High Tech Low Voltage, Nashville, TN (remote)
Network Field Operations Manager
July 2018 – August 2019
- Responsible for field operations in Google Fiber’s Nashville market (ISP/OSP).
- Works closely with Google Fiber NOC engineers and our field technicians to rectify issues.
- Conduct weekly strategic meeting with Google Fiber internal employees and admin for projects, expansions and ticket updates.
- Responsible for invoicing processed tickets and projects to Google.
Google Fiber via Concentrix services, Taguig, Metro Manila
NOC Engineer
November 2016 – May 2018
- Monitor network stability and performance of Google Fiber Network to ensure 24×7 operation.
- Report operational state of the network on a daily, weekly and monthly basis.
- Validate problem descriptions and perform detailed diagnosis.
- Raise and drive trouble tickets with telecommunications carriers to resolve service issues.
Converge ICT, Clark Field, Angeles City Pampanga
NOC Engineer / Network Engineer
August 2014 – November 2016
- Responsible for Troubleshooting, Scaling and Improving the whole GPON and DOCSIS network.
- Experienced testing and working with several home broadband modems.
- Experienced configuring GPON and DOCSIS routers.
- Involved in planning expansion to different cities.
- Worked closely with RF (Radio frequency) team to troubleshoot and maintain links.
- Lead onsite network engineer to bring up and connect Batangas and Tagaytay area in Converge’s network.
Education
Holy Angel University
BS Information Technology, Network Admin
June 2010 – April 2014
Angeles City Pampanga, Philippines
Certifications
Juniper Networks Certified Associate – JUNOS
ID: K93D3FRYXEFQQJGJ
Juniper Networks Certified Associate – Cloud
ID: C49MXCF58E4EQ8W1