Skip to main content

Open to opportunities — Queens, NY, 11377

Regan GomesCyber Security Professional

Defending healthcare, banking, and enterprise environments for 10+ years — from real-time threat detection in Microsoft Sentinel and Splunk to cloud security, incident response, and MITRE ATT&CK-driven investigations.

Portrait of Regan Gomes, SOC Analyst and cybersecurity professional

10+ yrs

in Security

Queens, NY

0+

Years in Cybersecurity

0%

SLA Compliance Maintained

0%

Reduction in Identity Incidents

0

Industry Certifications

About Me

A decade defending what matters

From banking branches in Dhaka to a 24/7 SOC protecting one of America's largest healthcare insurers.

I am a cybersecurity professional with over 10 years of hands-on experience across SOC analysis, IT security engineering, and security analysis — protecting critical environments in global healthcare insurance, banking, and international IT managed services.

Today I work as a SOC Analyst at Aetna Inc. (a CVS Health company), where I monitor and investigate security alerts across Splunk SIEM, Microsoft Sentinel, and Azure Log Analytics — validating identity-based risks, endpoint detections, and network anomalies that touch sensitive member and claims data. My investigations have helped maintain over 82% SLA compliance for medium and high-severity alerts and reduce repeat identity-related incidents by roughly 11% in a single year.

My toolkit spans real-time threat detection with KQL and SPL, cloud security via Microsoft Defender, identity protection in Azure AD, network traffic analysis with Wireshark, and incident mapping to the MITRE ATT&CK framework. I pair deep technical investigation with clear executive reporting, disciplined documentation, and the collaborative mindset a 24/7 SOC demands.

Personal Strengths

  • Analytical problem-solving
  • Clear executive communication
  • Meticulous documentation
  • Cross-functional collaboration
  • Calm under incident pressure
  • 24/7 SOC shift discipline

Languages

  • English (Professional)
  • Bengali (Native)

At a Glance

  • 10+ years in cybersecurity
  • 19 years total in IT
  • Healthcare, banking & managed services
  • Security+ · CEH · CCNA · A+

Technical Skills

Tools of the trade

A battle-tested stack across SIEM, cloud, endpoint, network, and identity security.

SIEM & Log Management

  • Microsoft Sentinel92%
  • Splunk (SIEM)88%
  • Azure Log Analytics90%
  • KQL (Kusto Query Language)90%
  • SPL70%
  • Security Event Correlation88%

Cloud Security (Azure)

  • Microsoft Defender for Cloud88%
  • Azure Security Center86%
  • Azure AD Identity Protection90%
  • Conditional Access Monitoring85%
  • Cloud Security Monitoring88%

Endpoint & Vulnerability

  • Microsoft Defender for Endpoint90%
  • CrowdStrike Falcon68%
  • Tenable.io84%
  • Nessus86%
  • Vulnerability Assessment85%

Threat Intel & Incident Response

  • MITRE ATT&CK Mapping88%
  • VirusTotal / AlienVault OTX88%
  • IOC Analysis87%
  • Alert Triage & Investigation92%
  • Threat Hunting72%

Network Security

  • Wireshark86%
  • TCPDump68%
  • Network Traffic Analysis85%
  • DNS / HTTP Analysis84%
  • Packet Inspection83%

Identity & Access Security

  • Active Directory Monitoring88%
  • Authentication Log Analysis88%
  • Privileged Access Monitoring84%
  • Account Compromise Detection86%

Systems & Platforms

  • Windows Server88%
  • Microsoft Azure86%
  • Linux Fundamentals72%
  • VMware75%

Scripting & Automation

  • KQL Queries90%
  • PowerShell70%
  • Bash65%
  • Security Automation Support74%

Compliance & Frameworks

  • MITRE ATT&CK88%
  • NIST CSF85%
  • ISO 2700178%
  • PCI-DSS76%
  • HIPAA80%

Experience

Career timeline

19 years in IT — the last decade on the security front line.

  1. Sep 2024 – Present

    SOC Analyst

    Aetna Inc. (CVS Health)Hartford, CT

    24/7 security operations for a global healthcare insurer — monitoring, triaging, and investigating alerts across cloud, endpoint, identity, and network telemetry protecting member and claims data.

    Show responsibilities ↓
    • Monitor daily security alerts in Splunk SIEM and Microsoft Sentinel across Azure, on-prem Windows servers, and healthcare applications processing member and claims data.
    • Validate triggered alerts with KQL in Azure Log Analytics — unusual authentication behavior, failed MFA attempts, and suspicious access to PHI-related systems.
    • Investigate identity risks in Azure AD Identity Protection: risky sign-ins, impossible travel, and conditional access violations.
    • Analyze endpoint detections in Microsoft Defender for Endpoint and CrowdStrike Falcon — process activity, registry changes, and file hashes.
    • Correlate firewall, DNS, and HTTP logs with endpoint alerts; validate suspicious outbound connections with Wireshark/TCPDump.
    • Run IOC checks via VirusTotal and AlienVault OTX and map confirmed behaviors to MITRE ATT&CK.
    • Execute SOC playbooks: account disablement, forced password resets, endpoint isolation, and Tier 2 escalation.
    • Support HIPAA / NIST CSF-aligned monitoring and security review of new Azure workloads for the CVS Health digital integration initiative.

    82%+ SLA compliance maintained for medium/high-severity alerts

    ~11% reduction in repeat identity-related incidents within one year

    • Splunk
    • Microsoft Sentinel
    • KQL
    • Azure AD
    • Defender for Endpoint
    • CrowdStrike
    • Tenable.io
    • Nessus
    • Wireshark
    • ServiceNow
    • MITRE ATT&CK
  2. Nov 2017 – Jun 2023

    IT Security Engineer

    WiproDhaka, Bangladesh

    Security engineering for global managed-services clients — securing the "Wipro Global Cloud Migration" project, vulnerability management at scale, and detection engineering support.

    Show responsibilities ↓
    • Evaluated security requirements for Azure workloads in the Wipro Global Cloud Migration project against internal baselines and NIST standards.
    • Configured and deployed Nessus scanners across distributed network segments to surface unpatched systems and insecure configurations.
    • Monitored security telemetry in Splunk and Azure Log Analytics, detecting brute-force attempts and unauthorized API calls in thousands of daily logs.
    • Triaged incidents in ServiceNow within strict SLAs; investigated suspicious logins via Active Directory authentication log analysis.
    • Inspected packets with Wireshark, identifying suspicious DNS queries indicating malware beaconing.
    • Developed PowerShell scripts automating security log collection from Windows servers across legacy infrastructure.
    • Mapped threat patterns to MITRE ATT&CK to help senior engineers build more accurate detection rules.

    Secured Azure workloads for a global cloud migration program

    Increased log-collection efficiency across legacy infrastructure through automation

    • Nessus
    • Splunk
    • Azure Log Analytics
    • ServiceNow
    • Active Directory
    • Wireshark
    • PowerShell
    • Defender for Endpoint
    • MITRE ATT&CK
  3. May 2015 – Oct 2017

    IT Security Analyst

    AccentureDhaka, Bangladesh

    Security monitoring and analysis for global infrastructure — live event-stream monitoring, phishing triage, access audits, and vulnerability scanning.

    Show responsibilities ↓
    • Monitored live security event streams in Splunk and early Azure Log Analytics for unauthorized access attempts across global infrastructure.
    • Managed security ticket intake in ServiceNow, protecting high-risk patient and financial data through correct categorization.
    • Audited Active Directory permissions in "Project Identity-Secure," eliminating permission creep for offshore teams.
    • Ran scheduled Nessus scans across corporate subnets, flagging Windows servers missing critical patches.
    • Correlated VPN logs with authentication timestamps to separate user error from brute-force attacks.
    • Vetted phishing-mailbox attachments and URLs through VirusTotal and AlienVault OTX.
    • Produced shift-handover documentation and daily status reporting for SOC leadership.

    Cleaned up enterprise-wide AD permission creep in Project Identity-Secure

    • Splunk
    • Azure Log Analytics
    • ServiceNow
    • Active Directory
    • Nessus
    • VirusTotal
    • AlienVault OTX
    • Wireshark
  4. Apr 2010 – Apr 2015

    IT Support Engineer

    Standard CharteredDhaka, Bangladesh

    Frontline IT and security-minded support for banking operations across Dhaka branches.

    Show responsibilities ↓
    • Managed end-to-end deployment and maintenance of banking workstations, securely imaged with financial applications.
    • Served as identity-and-access gatekeeper: Active Directory accounts, folder permissions, and access troubleshooting.
    • Led the "Branch Hardening Initiative" — physically securing server racks and disabling unauthorized USB ports on public-facing terminals to prevent data leakage.
    • Resolved high-priority escalations across Outlook, VPN, and network outages, keeping core banking systems available.

    Hardened branch infrastructure against physical data-leakage vectors

    • Windows
    • Active Directory
    • VPN
    • Banking Systems
    • Hardware Security
  5. Jan 2007 – Mar 2010

    IT Support Assistant

    BJITDhaka, Bangladesh

    Foundation years — workstation builds, patching, antivirus operations, and network support for the "Global Delivery Backbone" project.

    Show responsibilities ↓
    • Built and configured developer workstations (Windows XP/7) supporting the Global Delivery Backbone project.
    • Ran antivirus scans and applied security patches protecting the network from worm infections.
    • Managed Active Directory account resets, email configuration, and server-room network cabling and switch connectivity.
    • Windows XP/7
    • Active Directory
    • Antivirus
    • Networking

Certifications

Professional credentials

Industry-recognized certifications validating security, networking, and systems expertise.

CompTIA Security+

CompTIA

Core security skills: threats, attacks, vulnerabilities, architecture, and operations.

CEH — Certified Ethical Hacker

EC-Council

Offensive security methodology: reconnaissance, exploitation, and countermeasures.

CCNA — Cisco Certified Network Associate

Cisco

Enterprise networking: routing, switching, IP services, and network security fundamentals.

CompTIA A+

CompTIA

Hardware, operating systems, and IT operational fundamentals.

Projects

Hands-on security labs

Personal lab projects built to sharpen detection, response, and analysis skills — the same tradecraft I use professionally.

Personal Lab Project

Home SOC Lab — Microsoft Sentinel

End-to-end detection lab: Windows/Linux VMs shipping logs to Microsoft Sentinel via Azure Monitor Agent, with custom KQL analytics rules mapped to MITRE ATT&CK.

  • Custom KQL analytics rules for brute-force, impossible travel, and privilege escalation
  • Attack simulation with Atomic Red Team
  • Automated incident enrichment with Logic Apps playbooks
  • ATT&CK coverage dashboard in Sentinel workbooks
  • Microsoft Sentinel
  • KQL
  • Azure
  • Atomic Red Team
  • Logic Apps
Personal Lab Project

KQL Detection Rules Library

A curated, documented library of production-style KQL detections for identity attacks, endpoint anomalies, and cloud misconfigurations — each rule tagged with ATT&CK technique IDs.

  • Detections for risky sign-ins, MFA fatigue, and token theft patterns
  • Per-rule documentation: logic, false-positive guidance, response steps
  • Validation queries and test data included
  • KQL
  • Microsoft Sentinel
  • Azure AD
  • MITRE ATT&CK
Personal Lab Project

Phishing Email Analysis Pipeline

Semi-automated triage workflow for suspicious emails: header parsing, URL/attachment detonation checks against VirusTotal and OTX, and verdict reporting.

  • PowerShell/Python header and IOC extraction
  • Automated VirusTotal + AlienVault OTX reputation lookups
  • Standardized analyst verdict report output
  • Python
  • PowerShell
  • VirusTotal API
  • AlienVault OTX
Personal Lab Project

Vulnerability Management Lab

Continuous assessment lab using Nessus Essentials against intentionally vulnerable targets, with risk-ranked remediation reporting and patch-verification rescans.

  • Scheduled authenticated scans of Windows/Linux targets
  • CVSS-based prioritization and remediation tracking
  • Before/after rescan verification workflow
  • Nessus
  • Tenable.io
  • Windows Server
  • Linux
Personal Lab Project

Active Directory Attack & Defense Lab

Purple-team AD lab: simulated Kerberoasting, password spraying, and lateral movement — then building the detections that catch them in Splunk and Sentinel.

  • Domain build-out with tiered admin model
  • Attack simulation with common tooling in an isolated lab
  • Matching detection queries and alert documentation
  • Active Directory
  • Splunk
  • Sentinel
  • PowerShell
  • MITRE ATT&CK
Personal Lab Project

Network Traffic Analysis Casebook

A documented set of PCAP investigations: malware beaconing, DNS tunneling, and data exfiltration patterns analyzed with Wireshark and TCPDump.

  • Annotated PCAP walkthroughs with filters and findings
  • Beaconing and C2 pattern identification methodology
  • Analyst-style incident write-ups for each case
  • Wireshark
  • TCPDump
  • Zeek
  • Network Forensics

Education

Academic foundation

MSc in Computer Science & Engineering

Stamford University Bangladesh

CGPA 3.77 / 4.00

BSc in Computer Science & Engineering

Stamford University Bangladesh

CGPA 3.50 / 4.00

Contact

Let's talk security

Hiring, consulting, or just want to compare notes on detections? My inbox is open.

Get in touch

Find me on

Note: the file name is included in the message; the file itself is sent only when Formspree is configured.