SOC Analyst at ·🟢 Open to work
Nima Weatherly portrait

Security operations and incident response, focused on practical detection

I build and tune SIEM monitoring, triage alerts, and investigate incidents using Wazuh, Splunk, and Microsoft Sentinel.

Work samples

My portfolio shows SIEM deployments, Splunk investigations, Nessus vulnerability assessments, and a secure hybrid cloud design, all with alert triage, event correlation, and documented remediation

  • Secure Hybrid Cloud Networking Solution
    Secure Hybrid Cloud Networking Solution
    Secure Hybrid Cloud Networking Solution

    Designed a secure hybrid cloud environment integrating on-premises infrastructure with Microsoft Azure, configuring VLAN segmentation, NSGs, and firewall policies to reduce attack surface. Performed connectivity, routing, and firewall validation testing; produced architecture diagrams and documentat

    Microsoft AzureVLANNSGsFirewall
  • SIEM Monitoring & Security Operations Lab
    SIEM Monitoring & Security Operations Lab

    Deployed and configured Wazuh SIEM in a virtualized environment; built detection rules for failed authentication attempts and file integrity monitoring. Performed alert triage, event correlation, and log analysis to investigate suspicious activity, applying concepts across Wazuh, Splunk, and Microso

    WazuhSplunkMicrosoft Sentinel

About me

I build and tune SIEM monitoring, triage alerts, and investigate incidents using Wazuh, Splunk, and Microsoft Sentinel.

I am an Information Security professional with hands-on experience in SIEM-based security monitoring, alert triage, and incident investigation. My background includes vulnerability management and governance aligned with NIST RMF, along with over six years of military leadership and systems administration. I focus on building detection and monitoring capabilities using Wazuh, Splunk, and Microsoft Sentinel, correlating events, and translating technical findings into clear documentation. I am purs

Experience

Customer Support / Technical Support Specialist

Transcom · Aug 2019 - Oct 2020

Travel Sales & Customer Support Specialist

Sykes · Dec 2017 - Aug 2019

Family Caregiver

Family Caregiver · Mar 2002 - Dec 2017

Information Systems Operator-Analyst (Shop Foreman)

U.S. Army · Feb 2001 - Jul 2002

Multichannel Communications Systems Operator / Personnel Support (MOS 31R)

U.S. Army · Mar 1996 - Feb 2001

Education

Western Governors University

Bachelor of Science in Cloud and Network Engineering (Azure Track) · Class of 2026

Colorado Technical University

Associate of Science in General Studies · Class of 2011

Kenzie Academy (Southern New Hampshire University)

Full Stack Web Development Certificate

Skills

SIEM MonitoringAlert TriageEvent CorrelationRoot Cause AnalysisThreat DetectionLog AnalysisNIST RMFVulnerability ManagementRisk AssessmentSecurity ControlsPolicy ComplianceAudit ReadinessMicrosoft AzureAzure Virtual NetworksNSGsAWSMicrosoft 365Active DirectoryLinuxMicrosoft SentinelSplunkWazuhTenable NessusWiresharkPowerShellOSI ModelTCP/IPDNSTLS/SSL

Secure Hybrid Cloud Networking Solution

Designed a secure hybrid cloud environment integrating on-premises infrastructure with Microsoft Azure, configuring VLAN segmentation, NSGs, and firewall policies to reduce attack surface. Performed connectivity, routing, and firewall validation testing; produced architecture diagrams and documentat

Microsoft AzureVLANNSGsFirewall

Overview

Secure Hybrid Cloud Networking Solution
View all works

SIEM Monitoring & Security Operations Lab

Deployed and configured Wazuh SIEM in a virtualized environment; built detection rules for failed authentication attempts and file integrity monitoring. Performed alert triage, event correlation, and log analysis to investigate suspicious activity, applying concepts across Wazuh, Splunk, and Microso

WazuhSplunkMicrosoft Sentinel
View all works

Splunk Security Log Analysis

Analyzed Windows Security logs in Splunk to investigate authentication anomalies, developing SPL searches and dashboards to support threat detection and incident response.

SplunkSPL

Overview

Splunk Security Log Analysis
View all works

Vulnerability Assessment & Remediation (Tenable Nessus Lab)

Conducted vulnerability scans using Tenable Nessus, prioritizing findings by CVSS-based severity and documenting remediation recommendations by risk impact. Remediated a high-severity vulnerability involving outdated Splunk software; validated resolution through follow-up scans and applied risk-acce

Tenable NessusSplunk

Overview

Vulnerability Assessment & Remediation (Tenable Nessus Lab)
View all works

VIRTUAL EXPERIENCE PROGRAMS (FORAGE)

Deloitte Cybersecurity: Investigated authentication and web activity logs to identify security incidents and correlate suspicious behavior. PwC - Cyber Security Consulting: Conduc

Overview

VIRTUAL EXPERIENCE PROGRAMS (FORAGE)
View all works