LEO ZERHUSEN
Pensacola, FL
540-***-**** ***.*.********@*****.***
CYBERSECURITY ANALYTICS PROGRAM MANAGEMENT INTELLIGENCE OPERATIONS Cybersecurity Specialist and Military Veteran with a Top Secret, SCI Security Clearance leveraging 10+ years of experience in network defense, digital network exploitation, and cyber intelligence analysis. Proven ability to lead teams in monitoring and mitigating cybersecurity threats, developing proactive strategies to enhance network security posture. Skilled in intelligence gathering, threat detection, and vulnerability assessment, with a track record of producing actionable intelligence reports to support mission-critical decision-making.
● Threat Detection
● Security Information
● Cybersecurity Incident Response
● Intelligence Analysis
● Vulnerability Assessment
● Defense Cyber Operations
● Risk Management
● Team Leadership
● Digital Network Exploitation
OVERVIEW OF KEY CONTRIBUTIONS
Personnel Operations Personalize communication, foster trust, and resolve conflicts among personnel. Establish strong partnerships with clients and departmental personnel, recognizing the importance of trust and credibility in operations. Program Management Balance long-term objectives and intricate processes effectively. Assimilates cutting-edge ideas, methods, and technologies for swiftly deploying impactful solutions. PROFESSIONAL EXPERIENCE
Team Lead Provalus 2023 – Present
Led a team of 11 analysts in monitoring security alerts and mitigating cybersecurity threats, ensuring timely identification and resolution of risks while developing strategies to enhance client network security posture and tailoring solutions to meet specific security needs.
● Coordinated with clients to understand security requirements, customizing Playbooks and refining processes to boost productivity and effectiveness, creating rules for the Google Chronicle SIEM to improve threat detection accuracy
● Analyzed and resolved issues within the Google Chronicle SOAR system, escalating cases requiring tier 2 or higher resolution as needed, and utilizing cloud technologies like AWS and Microsoft Azure to support security initiatives
● Conducted monthly meetings with personnel, providing mentorship to foster growth and enhance performance, while managing administrative tasks such as timesheets and weekly scheduling to ensure smooth operations
● Applied knowledge of endpoint security, client operating system configurations, and Agile tools to improve team operational efficiency and support security initiatives Delivery Manager Provalus 2022 – 2023
Directed and oversaw 38 personnel across 8 technical support desks for 3 clients, ensuring high-quality service delivery and customer satisfaction, while handling administrative responsibilities such as timesheets, PTO requests, and purchase orders to support efficient resource management.
● Managed multiple accounts generating $1M+ in revenue, maintaining client relationships, meeting unique business needs, and preparing business reports to communicate performance metrics, project updates, and strategic insights
● Conducted monthly meetings with personnel, providing mentorship, addressing professional issues, and fostering growth, while participating in daily client meetings to ensure clear communication and alignment with project goals
● Monitored project milestones and deliverables, while engaging in new employee boot camps to facilitate onboarding, introduce company culture, and teach relevant topics to support workforce development while staying in compliance
● Selected to provide a test team for the evaluation and implementation of a Workforce Management (WFM) program, demonstrating a commitment to innovation and process improvement
● Utilized technologies such as Microsoft Teams, Zoom, ServiceNow, Five9, Monday.com, Bullhorn, and iSolved to streamline communication, collaboration, and project management processes Network Analyst Navy Cyber Protective Team (CPT) 2013 – 2022 Gained experience with the DoD Risk Management Framework (RMF), implementing cybersecurity practices and controls while executing defensive techniques in the cyberspace operational environment to defend Mission Relevant Terrain Cyber (MRT-C). LEO ZERHUSEN PAGE 2 OF 2
(CONTINUED)
● Conducted research and open-source intelligence gathering to create SOPs for the Cyber Protection Team, developing security procedures for sanitizing and releasing system components across multiple security classifications
● Utilized Splunk and Elastic (ELK) Stack SIEM tools to monitor and analyze security events, while researching and applying relevant policies, procedures, and standards to protect information systems and ensure compliance
● Identified critical cyber terrain, proactively detecting, defending against, and eradicating enemy network threat activities, while preserving a vigilant stance to ensure adversaries did not compromise systems in the Mid-East Region
● Collaborated with teams and stakeholders to share information, provide situational awareness, and coordinate defensive actions, while organizing ongoing risk assessments and vulnerability analyses to address security gaps
● Maintained up-to-date knowledge of emerging cybersecurity trends, technologies, and best practices, continuously seeking professional development opportunities to enhance expertise Digital Network Exploitation Analyst Navy Information Operation Command 2002 – 2013 Analyzed 6.5K+ records to produce 40+ intelligence reports for Commander TENTH Fleet and Commander FIFTH Fleet Cyber Operations, supporting informed decision-making.
● Conducted in-depth reviews of 50+ configurations and mapped 800+ devices, significantly enhancing operational development and improving the effectiveness of cyber operations
● Dedicated 900+ hours to analyzing raw intelligence, extracting mission-critical information, and generating actionable insights, resulting in the successful tasking of 40+ high-priority selectors
● Supported 60 cyber operations by providing timely and accurate intelligence, leading to the creation of 130+ product reports that were briefed to National Customers to drive mission success
● Ensured the accuracy, reliability, and relevance of intelligence products by demonstrating exceptional attention to detail and maintaining high standards of quality throughout the reporting process CERTIFICATIONS
CompTIA A+ 2015
CompTIA Security+ 2023
CompTIA Network+ 2015
EC-Council Certified Ethical Hacker 2024
EC-Council Certified Network Defense 2024
TRAINING
Basic Digital Network Analysis 2006
Advanced Digital Network Analysis 2008
Intermediate Digital Network Analysis 2007
A+ PC Repair & Operating Systems Technology 2007 Network+ Introduction To Computer Networking 2007 TECHNICAL COMPETENCIES
Operating Systems: Windows Linux
Microsoft Office 365: Outlook Word Excel PowerPoint Google Workspace: Gmail Google Chronicle (SIEM) Google Chronicle (SOAR) Networking Tools: NMAP CrowdStrike Tanium AirWatch Microsoft Defender ServiceNow