Alex Morgan
Defensive security · always watching

Find the threat.
Protect what matters.

I turn noisy security signals into decisive action, building detection logic, investigating incidents and helping teams make security measurable without slowing the mission.

SIEM / SOARThreat HuntingIncident ResponseCloud Security
01 / Security mindset

Curious by default.
Calm under pressure.

Good defence is part engineering, part investigation and part communication. I build systems that help people see risk earlier and respond with confidence.

My approach starts with visibility: know what matters, establish useful telemetry, then create detections that tell a clear story. From there, I validate assumptions through threat hunting and turn findings into durable controls.

I care about the human side of security too: crisp incident notes, practical remediation plans and security guidance that teams can actually adopt.

37 detections shipped
12 incident playbooks
4 years defending systems
EVENT auth.anomaly.detected
SRC 10.24.18.7
USER a.morgan
RISK 91 / critical
RULE impossible_travel
ACTION session.revoked
STATUS contained
02 / Expertise

The defensive toolkit.

Role-specific capabilities presented as a security operations map rather than generic skill percentages.

⚡

Threat Detection

Detection engineering, behavioral analytics, Sigma-style logic and alert tuning that reduces noise.

🛡️

Incident Response

Triage, containment, evidence handling, root-cause analysis and post-incident hardening.

🔍

Threat Hunting

Hypothesis-led hunts across identity, endpoint, network and cloud telemetry.

☁️

Cloud Defense

Identity controls, logging strategy, workload protection and cloud attack-path reviews.

🤖

Security Automation

SOAR workflows and lightweight automation that turn repetitive response steps into reliable actions.

💬

Risk Communication

Translate technical findings into prioritized, decision-ready recommendations for stakeholders.

03 / Experience

Signals, systems, resilience.

A compact timeline focused on outcomes, ownership and the security problems solved.

Senior Cybersecurity Analyst

Own detection quality across identity and endpoint telemetry; lead high-severity investigations and coach analysts through structured incident response.

Cyber Defense Analyst

Built a threat-hunting program around adversary behaviors, introduced reusable detection patterns and partnered with platform teams on telemetry coverage.

SOC Analyst

Triaged security alerts, investigated suspicious activity and helped convert recurring incidents into documented response playbooks.

04 / Case studies

Defence, made tangible.

Selected security initiatives showing how investigation becomes measurable improvement.

Detection engineering

Identity Attack-Path Watch

Connected impossible-travel, MFA fatigue and privilege-change signals into a single investigation path, cutting time-to-triage by 42%.

Threat hunting

Quiet Beacon Hunt

Built a hypothesis-driven hunt for low-and-slow command-and-control behavior across endpoint telemetry.

Incident response

Containment Playbook

Standardized escalation, evidence capture and containment decisions for high-risk account compromise.

05 / Credentials

Built on disciplined practice.

Credentials and continuous learning that support hands-on defensive work.

CompTIA Security+Security fundamentals · 2022
CERTIFIED
Blue Team Level 1Defensive operations · 2023
CERTIFIED
Cloud Security FoundationsIdentity and workload protection · 2024
TRAINING
Incident Response Lab SeriesForensics and containment · 2025
LAB WORK
06 / Contact

Let us make the signal useful.

Have a security challenge, detection backlog or response process that needs a sharper edge? Send a note.

Professional contact

For security operations, detection engineering and defensive architecture conversations.

Emailalex.morgan@example.com
LocationChicago, IL
AvailabilityOpen to security-focused opportunities
in GH