on watch · federal contract · pittsburgh, pa

Esra Demir

Federal Cyber Threat Detection // Response Analyst
Security Operations Center Analyst

Security+ certified analyst on the federal front line — hunting threats across Splunk, XSOAR, and the cloud, and turning alerts into answers. Five years of watch-floor experience spanning a 24/7 SOC, a national bank's fraud desk, an NHL franchise's first security operations center, and federal healthcare defense. Scroll to descend through the record.

CLEARANCE PUBLIC TRUST · ACTIVE/ CERT COMPTIA SECURITY+/ ROLE FEDERAL CONTRACTOR
scroll to descend
whoami

From biology labs to the federal watch floor.

My route into security wasn't a straight line. A biology degree from Temple University, then six years managing pharmacy operations — an environment where precision, compliance, and calm under pressure were the daily baseline. In 2021 I traded prescriptions for packets and never looked back.

Since then: round-the-clock SOC operations at CyberNow Labs, real-time fraud detection at PNC Bank, building the Pittsburgh Penguins' first Security Operations Center from the ground up, and now hunting threats on a federal healthcare contract as an IBM consultant. Along the way I've become the peer mentor junior SOC analysts call first — because the best security teams run on shared knowledge.

cat career.log

Field log

NOV 2024 → PRESENTFederal Healthcare Client · Consulting Contract
Federal Cyber Threat Detection & Response Analyst

Defending federal healthcare infrastructure

  • Monitor and triage security alerts in Splunk Enterprise Security, creating and tuning correlation rules that cut false positives and sharpen detection accuracy.
  • Hunt threats and enrich IOCs across Splunk ES, Cortex XSOAR, and Prisma Cloud, surfacing malicious activity before it spreads.
  • Triage phishing, malware, and endpoint alerts; document every incident in ServiceNow to client SLAs, with actionable recommendations attached.
  • Author OSINT tooling documentation and automated playbooks that streamline investigations for the whole SOC team.
MAY 2023 → SEP 2024Pittsburgh Penguins · Pittsburgh, PA
Cybersecurity Analyst

Built the franchise's first SOC

  • Spearheaded the organization's first Security Operations Center — frameworks, tooling, and incident response protocols from zero to operational.
  • Ran advanced threat hunting on FortiEDR telemetry and monitored FortiGate traffic to catch abnormal behavior early.
  • Implemented Okta as the core IAM platform with role-based access control, and hardened email through FortiMail Cloud for GDPR and HIPAA compliance.
  • Conducted malware analysis of hacker tooling, turning findings into defenses.
JAN 2023 → MAY 2023PNC Bank — TekSystems · Pittsburgh, PA
Fraud Analyst

Real-time fraud defense at a national bank

  • Investigated suspicious credit card, ACH, and wire activity in real time, intercepting fraud before losses landed.
  • Assessed risk with NICE Actimize and delivered case reports with data-driven recommendations to leadership.
MAR 2021 → JAN 2023CyberNow Labs · Sterling, VA
SOC Analyst

24/7 detection, response, and threat hunting

  • Provided round-the-clock security operations support, analyzing log data in Splunk Enterprise Security and QRadar to expedite remediation.
  • Investigated malware infections and phishing campaigns with CrowdStrike Falcon, SentinelOne, and Proofpoint.
  • Executed vulnerability management across web apps, assets, and IoT with Tenable.io, Nessus, and Netsparker.
NOV 2016 → AUG 2022Walgreens Pharmacy · Canonsburg, PA
Pharmacy Operations Manager · Origin

Where the discipline started

Years of regulated, high-stakes operations and team leadership — the foundation of attention to detail and grace under pressure that now runs every shift on the watch floor.

ls ./toolset

The analyst's arsenal

SIEM & Detection

Splunk Enterprise Security QRadar Cortex XSOAR Prisma Cloud Correlation rule tuning

Endpoint & EDR

CrowdStrike Falcon SentinelOne FortiEDR FortiClient EMS

Network & Firewall

Palo Alto Firewall FortiGate NGFW Wireshark Zenmap OpManager OSI / TCP-IP

Threat Intel & OSINT

VirusTotal Hybrid Analysis Joe Sandbox Urlscan.io CyberChef Cisco Talos Maltego AbuseIPDB MX ToolBox

Vulnerability Management

Qualys Nessus Expert Tenable.io Netsparker OWASP Top 10

Frameworks & Compliance

MITRE ATT&CK Cyber Kill Chain NIST CSF PCI DSS HIPAA GDPR

Identity, Email & Awareness

Okta FortiMail Cloud Proofpoint KnowBe4

Ops & Case Management

ServiceNow Jira Spiceworks NICE Actimize Root Cause Analysis
sha256sum credentials/*

Signed and verified

integrity check: passed · all credentials current
Certifications
CompTIA Security+ CySA+ in process Penetration Testing Fortinet NSE 1 & 2 Google IT Support SkillUp: Cybersecurity & Cybercrime
Clearance & Recognition
  • Public Trust — Active
  • Peer Mentor for Junior SOC Analysts
  • Black Hat USA attendee · 2023 & 2024
  • MLB — CSI meetings · 2023 & 2024
  • B.A. Biology — Temple University
Digital Badges · 2024 – 2026

Sixteen badges and counting

Cybersecurity Fundamentals '24 SOC in Practice '24 Threat Intelligence & Hunting '24 Enterprise Security in Practice '25 Getting Started with Cybersecurity '25 AI Fundamentals '25 Generative & Agentic AI '25 Cloud Computing Fundamentals '25 IT Fundamentals '25 Sustainability & Technology '25 Garage Essentials '25 Garage Foundation '25 Agile Explorer '25 Enterprise Design Thinking Practitioner '25 Government Industry Jumpstart '25 Growth Behaviors '26
ping esra

Open channel

Whether it's a federal security mission, an enterprise SOC, or comparing notes on threat hunting — the line is open and monitored.

BASE PITTSBURGH, PA · CLEARANCE PUBLIC TRUST · STATUS MONITORING