CHINONSO NWANGWU
Cybersecurity Engineer Federal Cybersecurity Specialist
D.C, USA +1-410-***-**** ***********@*****.*** linkedin.com/in/chinonso-nwangwu/ Active TS/SCI Clearance DHS Suitability Eligible PROFESSIONAL SUMMARY
Cybersecurity Engineer and Hunt & Incident Response SME with 8+ years of experience supporting federal civilian, DoD, military and critical infrastructure environments. Strong background in threat hunting, incident response, SOC operations, SIEM detection engineering, EDR analysis, vulnerability prioritization, RMF and cyber defense operations. Proven ability to lead full lifecycle investigations from hypothesis-driven hunts and forensic triage through containment, eradication, reporting and executive stakeholder briefings. Experienced in identifying advanced persistent threats, nation-state activity, lateral movement, privilege escalation, command-and-control traffic, malware behavior and living- off-the-land techniques using Splunk, Microsoft Sentinel, CrowdStrike Falcon, FireEye, Wireshark, Snort, YARA, Sigma and MITRE ATT&CK. Cleared TS/SCI professional with strong federal mission alignment, DHS/CISA experience and hands-on expertise supporting national-level cyber defense objectives. TECHNICAL SKILLS
Cybersecurity Operations: Threat Hunting, Incident Response, SOC Operations, Cyber Defense, CND, IR Lifecycle, Malware Triage
SIEM & Detection Engineering: Splunk SPL, Microsoft Sentinel KQL, Elastic, RSA NetWitness, Sigma Rules, Correlation Rules, Alert Tuning
Endpoint & Network Security: CrowdStrike Falcon, Microsoft Defender, FireEye, Trellix, Wireshark, PCAP, NetFlow, Snort, SILK, FirePower
Threat Intelligence & APT Analysis: MITRE ATT&CK, TTP Mapping, Nation-State Threats, Volt Typhoon, China-Nexus APTs, C2 Analysis, LOLBins
Vulnerability & Risk Management: Nessus, ACAS, CVE Analysis, CISA KEV, RMF, NIST 800-53, NIST 800-61, FISMA, DoD IA Controls
Identity & Access Security: Active Directory, Entra ID, IAM Telemetry, Privilege Escalation Detection, Access Control Review, Zero Trust
Automation & Reporting: Python, PowerShell, REST APIs, Regex, SOAR Workflows, INARs, CSAs, Executive Reports, Technical Briefings
PROFESSIONAL EXPERIENCE
AgovX
Cybersecurity Engineer April 2026 – Present
Lead cybersecurity engineering, threat detection, incident response and risk reduction activities across federal- focused environments, supporting secure operations aligned with NIST, RMF, DoD and DHS cybersecurity requirements.
Engineered and tuned 25+ SIEM detection rules using Splunk SPL, Microsoft Sentinel KQL, MITRE ATT&CK mappings, Sigma logic and threat intelligence indicators to improve visibility across endpoint, identity, cloud and network telemetry.
Investigated 80+ monthly security alerts involving suspicious authentication, privilege escalation, lateral movement, malware behavior, command-and-control activity and living-off-the-land techniques.
Supported vulnerability risk prioritization for 120+ findings by correlating CVEs, Nessus/ACAS results, CISA KEV intelligence, exploitability, asset criticality and operational impact.
Developed technical documentation, detection logic, hunt notes, incident summaries, executive briefings and remediation recommendations for security leadership, engineering teams and mission stakeholders.
Collaborated with SOC analysts, system owners, infrastructure teams and leadership to strengthen defense-in- depth controls, improve alert fidelity, reduce false positives and mature cyber defense workflows. Zolon Tech - DoD Defense Media Activity (DMA)
Independent Security Consultant October 2025 – April 2026
Served as cybersecurity SME supporting DoD security posture improvement, detection maturity, incident response readiness and enterprise defense-in-depth strategy.
Assessed current-state security capabilities across 6+ control areas, including logging, SIEM coverage, endpoint telemetry, vulnerability management, incident response readiness and access control governance.
Developed a scalable security roadmap covering SIEM deployment, endpoint integration, centralized logging, IR process improvement and detection engineering maturity, improving leadership visibility into enterprise cyber risk.
Delivered 10+ executive summaries, technical reports and security recommendations to mixed technical and non-technical stakeholders, supporting risk-based remediation and leadership decision-making.
Advised senior directors and technical teams on cybersecurity architecture, control gaps, countermeasure implementation and remediation planning aligned with RMF, DoD IA controls, CND policies and mission needs. Cybersecurity and Infrastructure Security Agency (CISA) Threat Hunting Branch
Cyber Threat Hunter Hunt & Incident Response SME May 2022 – September 2025
Served as Hunt & Incident Response SME across 250+ Federal Civilian Executive Branch and SLTT networks, executing the full cyber hunt lifecycle from hypothesis development through investigation, containment support and executive reporting.
Conducted 40+ proactive threat hunts targeting advanced persistent threats, nation-state activity, China-nexus actors, Volt Typhoon tradecraft, lateral movement, beaconing, persistence and living-off-the-land activity.
Authored 30+ Initial Network Activity Reports, executive summaries, technical findings and remediation recommendations that supported rapid containment and informed national-level defensive posture decisions.
Contributed to 15+ CISA Cybersecurity Advisories by analyzing threat actor TTPs, validating detection opportunities, documenting indicators and recommending defensive countermeasures.
Used Splunk, CrowdStrike Falcon, FirePower, SILK, Wireshark, PCAP, NetFlow and endpoint telemetry to pivot across host and network data and identify intrusions that bypassed traditional signature-based detection.
Developed and operationalized custom Snort, YARA and hunt detections mapped to MITRE ATT&CK techniques, improving visibility into APT behaviors across partner and federal environments.
Applied offensive security knowledge of SQL injection, XSS, buffer overflow, replay attacks, covert channels, ROP attacks, credential abuse and privilege escalation to contextualize adversary behavior.
Mentored 8+ junior analysts on hunt methodology, detection engineering, triage standards, analytic tradecraft, reporting quality and IR documentation best practices. Department of State - Zachary Piper Solutions
SOC Tier II Analyst / Incident Responder Lead March 2020 – May 2022
Led Tier II SOC and incident response activities in a 24/7 global security operations environment, providing escalation support and technical direction during high-severity incidents.
Reduced mean time to respond by 35% by creating repeatable incident response playbooks, improving triage workflows and standardizing documentation for containment and remediation actions.
Engineered and tuned 45+ Splunk SPL and Microsoft Sentinel KQL correlation rules to detect credential access, privilege escalation, suspicious authentication, malware activity and command-and-control traffic.
Performed forensic triage and root cause analysis for 150+ endpoint, identity and network security events using CrowdStrike Falcon, FireEye, Wireshark, firewall logs, DNS activity and packet captures.
Analyzed Active Directory logs, Entra ID signals, IAM telemetry and access patterns to identify unauthorized access, risky privilege changes and account compromise indicators.
Built Python and REST API integrations between security platforms to streamline investigations, reduce analyst workload and improve cross-tool visibility for incident response teams.
Partnered with Tier III engineers, infrastructure teams and security leadership to execute containment, eradication, recovery and post-incident improvement actions while maintaining CND policy compliance. TEKsystems
Army Network Operations / U.S. Army Cyber Command SOC Analyst May 2019 – March 2020
Monitored classified and unclassified Army network environments using Splunk, ACAS, IDS/IPS alerts, endpoint logs and network telemetry to detect suspicious activity and intrusion attempts.
Triaged 100+ monthly security alerts involving malware indicators, anomalous network activity, unauthorized access attempts, vulnerability findings and suspicious host-based behavior.
Supported RMF, DoD IA and CND requirements by documenting security events, validating indicators, escalating confirmed incidents and maintaining accurate incident records for Tier III review.
Collaborated with network engineers and cyber defense teams on 25+ remediation actions involving vulnerability mitigation, access control improvements, containment support and operational security reporting. U.S. Marine Corps
Non-Commissioned Officer (NCO) May 2015 – May 2019
Led teams of 5–12 personnel in mission-critical operational environments, enforcing accountability, security discipline and compliance with military information assurance requirements.
Supported classified environment operations across 4 years of service by following cybersecurity policies, access control standards, operational security procedures and secure communication practices.
Troubleshot LAN/WAN connectivity, network performance and endpoint issues in high-pressure environments, helping maintain operational readiness for 24/7 mission support activities.
Coordinated with cross-functional mission teams to maintain secure operations, equipment readiness, communication reliability and compliance with military security protocols. EDUCATION
Master of Science in Cybersecurity
University of Maryland, Baltimore County Jan 2022 – Aug 2023 Bachelor of Science in Computer Networks & Cybersecurity Minor: Information Systems Management - University of Maryland Global Campus march 2019 – may 2021 CERTIFICATIONS
CompTIA Security+
CompTIA CySA+
CompTIA CASP+
COMPLIANCE & FRAMEWORK ALIGNMENT
DoD 8140.01, IAT Level II, IASAE II, CSSP Analyst, CSSP Incident Responder, NIST CSF 2.0, NIST 800-53, NIST 800-61, RMF, FISMA, DoD IA Controls, CND Policies, MITRE ATT&CK, CISA KEV, Zero Trust, Defense-in-Depth, Incident Response Lifecycle
TECHNICAL SKILLS
Endpoint Security: EDR Investigation, Windows Event Logs Network Security: TCP/IP, HTTP, DNS, Firewall Logs Detection Engineering: YARA, Custom Hunt Playbooks Threat Hunting: Hypothesis-Driven Hunts, Lateral Movement, Persistence Vulnerability Management: Risk Prioritization, Remediation Tracking IAM & Access Controls: Authentication Logs
Operating Systems: Windows Server, Windows Workstations, Linux/Unix, System Hardening, Forensic Triage Other Tools: ServiceNow, GovCloud, DHS HIRT-Aligned Platforms, Knowledgebase Documentation