Esra Demir
Security+ certified analyst on the federal front line — hunting threats across Splunk, XSOAR, and the cloud, and turning alerts into answers. Five years of watch-floor experience spanning a 24/7 SOC, a national bank's fraud desk, an NHL franchise's first security operations center, and federal healthcare defense. Scroll to descend through the record.
From biology labs to the federal watch floor.
My route into security wasn't a straight line. A biology degree from Temple University, then six years managing pharmacy operations — an environment where precision, compliance, and calm under pressure were the daily baseline. In 2021 I traded prescriptions for packets and never looked back.
Since then: round-the-clock SOC operations at CyberNow Labs, real-time fraud detection at PNC Bank, building the Pittsburgh Penguins' first Security Operations Center from the ground up, and now hunting threats on a federal healthcare contract as an IBM consultant. Along the way I've become the peer mentor junior SOC analysts call first — because the best security teams run on shared knowledge.
Field log
Defending federal healthcare infrastructure
- Monitor and triage security alerts in Splunk Enterprise Security, creating and tuning correlation rules that cut false positives and sharpen detection accuracy.
- Hunt threats and enrich IOCs across Splunk ES, Cortex XSOAR, and Prisma Cloud, surfacing malicious activity before it spreads.
- Triage phishing, malware, and endpoint alerts; document every incident in ServiceNow to client SLAs, with actionable recommendations attached.
- Author OSINT tooling documentation and automated playbooks that streamline investigations for the whole SOC team.
Built the franchise's first SOC
- Spearheaded the organization's first Security Operations Center — frameworks, tooling, and incident response protocols from zero to operational.
- Ran advanced threat hunting on FortiEDR telemetry and monitored FortiGate traffic to catch abnormal behavior early.
- Implemented Okta as the core IAM platform with role-based access control, and hardened email through FortiMail Cloud for GDPR and HIPAA compliance.
- Conducted malware analysis of hacker tooling, turning findings into defenses.
Real-time fraud defense at a national bank
- Investigated suspicious credit card, ACH, and wire activity in real time, intercepting fraud before losses landed.
- Assessed risk with NICE Actimize and delivered case reports with data-driven recommendations to leadership.
24/7 detection, response, and threat hunting
- Provided round-the-clock security operations support, analyzing log data in Splunk Enterprise Security and QRadar to expedite remediation.
- Investigated malware infections and phishing campaigns with CrowdStrike Falcon, SentinelOne, and Proofpoint.
- Executed vulnerability management across web apps, assets, and IoT with Tenable.io, Nessus, and Netsparker.
Where the discipline started
Years of regulated, high-stakes operations and team leadership — the foundation of attention to detail and grace under pressure that now runs every shift on the watch floor.
The analyst's arsenal
SIEM & Detection
Endpoint & EDR
Network & Firewall
Threat Intel & OSINT
Vulnerability Management
Frameworks & Compliance
Identity, Email & Awareness
Ops & Case Management
Signed and verified
- Public Trust — Active
- Peer Mentor for Junior SOC Analysts
- Black Hat USA attendee · 2023 & 2024
- MLB — CSI meetings · 2023 & 2024
- B.A. Biology — Temple University
Sixteen badges and counting
Open channel
Whether it's a federal security mission, an enterprise SOC, or comparing notes on threat hunting — the line is open and monitored.