Page 03
Working experience
What I actually work on day-to-day — alert triage, vulnerability scanning, and endpoint remediation.
Junior Security Analyst
Working within the university's SOC to monitor, investigate, and remediate security events across campus systems, using a mix of SIEM, vulnerability management, and endpoint protection tooling.
185+
Devices under vulnerability management
3
SIEM incidents investigated, week one
12+
Security tools & platforms in active use
- Incident investigation — triage and document security incidents in a cloud-native SIEM, from initial alert review through supervisor-facing written findings
- Vulnerability management — manage agent-based vulnerability scanning workstations and asset tagging by hostname and IP, scan scheduling with completion notifications, and remediation proposals for findings.
- Phishing & smishing analysis — manual investigation of reported messages: header analysis, URL reputation checks via threat intelligence platforms, and social engineering indicator review, with recommendations written in plain language for non-technical staff
- Endpoint security — investigate and remediate endpoint threats using an enterprise EDR platform, including pre-deployment readiness checks confirming provisioning software and agent enrollment before machines ship
- Email security — work across the inbound mail inspection chain: transport rules, ATP scanning, AI-based behavioral detection, and DLP/data classification, plus DMARC and SPF for domain spoofing prevention
- Documentation & reporting — track findings and remediation through an ITSM ticketing platform, including DHS-format incident reporting; cross-reference indicators of compromise via threat intelligence tools and map findings to MITRE ATT&CK
Supervisor / Assistant Manager
Running store operations day-to-day, with a lot more IT and systems work than the title suggests — most of it centered on keeping retail hardware and network infrastructure online, plus compliance auditing and shift leadership.
24/7
Store systems kept operational
3
Regulated log types audited per shift
Key
Holder — opening, closing, escalations
- Infrastructure & connectivity — maintain the store's low-voltage data cabinet, keeping routers, switches, and patch panels stable so the network stays up for POS, fuel systems, and back-office operations
- System administration — troubleshoot the connection between POS register clients and the back-office store server, resolving polling errors and database sync issues that interrupt transactions
- Hardware maintenance — diagnose and repair failures on critical retail hardware including barcode scanners, thermal receipt printers, and fuel pump communication interfaces, minimizing downtime during trading hours
- Incident triage under pressure — isolate whether a failure is hardware, network, or software before escalating, and keep transactions moving with a workaround while the root cause gets resolved
- Vendor & escalation management — coordinate with corporate IT support and third-party service technicians, documenting symptoms and steps already taken so escalations don't restart from zero
- Compliance & auditing — run and audit shift documentation, tobacco and lottery logs, safe counts, and cash handling to meet regulatory and corporate requirements
- Access & asset control — manage key holder responsibilities, safe access, and opening/closing procedures, enforcing separation of duties on cash handling
- Team leadership & training — lead shifts, onboard new staff on POS and store systems, and handle customer and operational escalations during high-traffic periods
Daily toolkit
Tool stack
SIEM
Vulnerability Scanner
Agent-Based Scanning
EDR
ITSM / Ticketing
Cloud Platform
Threat Intelligence
IP Reputation
Sandbox Analysis
MITRE ATT&CK
DDI / IPAM
Email Header Analysis
DMARC Analysis
NVD / CVE Research