Nana Annor
Dumfries Va *****
****.*****@******.*** 571-***-****)
Secret/Top Secret (Active)
PROFILE:
SOC Incident Response Analyst with over five years of cybersecurity experience supporting DoD enterprise environments. Skilled in monitoring and triaging security alerts, conducting incident investigations, and coordinating response activities to protect mission-critical systems. Experienced in SIEM, EDR, and forensic analysis to detect threats, contain incidents, and support recovery efforts. Proficient in analyzing network and endpoint logs, identifying indicators of compromise (IOCs), and producing detailed incident and forensic reports for leadership. Holds active Secret Clearance with strong knowledge of incident response lifecycle, MITRE ATT&CK framework, and DoD cybersecurity policies.
EDUCATION:
● Northern Virginia Community College – Health Informatics (in Progress)
● Virginia Nova workforce – Security+ CE, CompTIA March 2020
● CompTIA Security+ certification
● CompTIA CySA+
Core Skills:
Security Alert Triage & Analysis Digital Forensics & Evidence Handling
Vulnerability Identification & Mitigation Incident Documentation & Reporting OSINT & Threat Intelligence Validation Threat Detection & Threat Hunting IOC Identification & Log Analysis IDS/IPS & Network Security Monitoring Zero Trust MITRE ATT&CK Framework DoD Cybersecurity Compliance Cross-Functional Incident Coordination Vulnerability Management Security Control Assessment Cloud Security Monitoring (AWS/Azure) Azure Government Post- Incident Review (PIR)
SOC Incident Response Analyst
February 2023 – Present
Capital Police Washington DC
Contracted through Paragon System
In this position my role involves identifying IT security vulnerabilities, developing risk management strategies, and ensuring compliance with regulatory standards. My general responsibilities include the following:
• Conduct incident investigations including analysis, classification, containment, eradication, and recovery actions.
• Analyze vulnerability scan results to identify false positives, determine risk severity, and coordinate remediation strategies with engineering and operations teams.
• Analyze endpoint, firewall, server, and cloud logs to identify indicators of compromise (IOCs) and potential threats.
2 Page
• Monitor and triaged security alerts generated by SIEM, EDR, IDS/IPS, and enterprise security platforms to detect malicious activity.
• Support digital forensic investigations through evidence collection, preservation, and preliminary analysis in accordance with DoD procedures.
• Prepare detailed incident and forensic reports and provided status briefings to government leadership and stakeholders.
• Collaborate with IT and cybersecurity teams to implement mitigation measures such as patching vulnerabilities and blocking malicious traffic.
• Participate in post-incident reviews to improve detection capabilities and strengthen response procedures.
• Developed and maintain SOC playbooks, runbooks, and incident response documentation.
• Perform OSINT research and threat intelligence enrichment to enhance incident analysis and threat detection.
• Queries classified environments to identify newly discovered vulnerabilities impacting operational networks.
Cybersecurity Analyst
November 2021-February 2023
Deloitte Herndon, VA
Contracted through Direct Viz Solutions
• Conducted comprehensive threat assessments and remediate 95% of critical vulnerabilities within SLA timelines, significantly reducing the attack surface and strengthening overall security posture.
• Provide training and awareness to the staff regarding security best practices. Create comprehensive reports and presentations for various audiences, including technical teams and senior management.
• Engage in proactive threat hunting to identify potential threats such as Man-in-the-Middle
(MitM) Attacks, Data breaches, unauthorized logins and login attempts, credential stuffing.
• Review Vulnerability scans to detect unpatched software and systems including Windows/Linux servers, SharePoint Servers, ASP.Net servers and internal WordPress platforms.
• Attend meetings with Server and Active Directory teams based on findings such as weak passwords or password expiration policy settings and especially improperly patched user laptops.
• Maintain detailed and accurate records of security incidents, actions taken, and outcomes.
• Conduct audits to ensure that our unit follows Compliance and regulatory guidelines.
• Update Shift hand off documents to reflect on any incidents that occurred during the shift. Security Operation Analyst
May 2019 – November 2021
Four Pillars Consulting
• In this position my responsibilities included continuous monitoring of network using SIEM tools such as Splunk ES for application monitoring in search of login discrepancies, unauthorized login attempts, business analytics, performance metrics and volume as well as compliance purposes. My general responsibilities included but are not limited to the following:
• Monitoring and analyzing Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) to identify security issues for remediation.
• Conducting security scanning, analyzing results for vulnerability management, and coordinating 3 Page
remediation efforts with team members.
• Worked with both internal analyst and technical leads, to assist in updating, and maintaining documentation including technical processes, standard operating procedures, and system/security artifacts.
• Wrote queries using SPL to extract data from Splunk logs of various systems. Built reports, dashboards and provided documentation of incidents occurring during log capture events.
• Analyze raw data and logs from assets supporting Network Security Services, Endpoint Security Services, and Cybersecurity Data Analysis Services.
• Performing ongoing monitoring of implemented security controls, mitigation of system vulnerabilities, testing of security controls including disaster recovery, performance of self- assessments for low level (security rating) systems, and track and close POA&Ms.
• Responsible for vulnerability management, patching and scanning, incidence response, auditing of over 200 user systems and accounts.
• Update documentation including Incidence response playbooks based on learned lessons post incident review. These documents capture incident description, detection methods, response steps, escalation procedures and communication plans.