- Triaged 200+ simulated events in Splunk Enterprise and Google Chronicle; authored SPL and YARA-L detections, mapped five investigation case studies to MITRE ATT&CK, and documented results with screenshots and analysis notes.
- Created six NIST-aligned incident-response playbooks covering phishing, ransomware, C2, brute force, insider threat, and BEC; practiced packet analysis with Wireshark and network reconnaissance with Kali Linux/Nmap.
Tochi Ugochukwu
Professional Summary
Security+ certified cybersecurity analyst focused on AI-enabled security automation, detection engineering, and incident response. In a Splunk and Google Chronicle home SOC lab, I triage simulated alerts end-to-end, author detection content, map findings to MITRE ATT&CK, and document response actions. I use Python and AI workflows to automate investigations and build evidence-first tooling. Available immediately for SOC Analyst (Tier 1/2) and Security Automation Engineer roles.
Security, AI & Automation Skills
Security Operations & Detection: CompTIA Security+ · Splunk Enterprise / SPL · Google Chronicle / YARA-L · MITRE ATT&CK · NIST Incident Response · Alert Triage · IOC Analysis · Wireshark · Kali Linux · Nmap
AI-Enabled Security Automation: Python · LLM Integration · Prompt Engineering · RAG Workflows · AI-Assisted Investigation · REST APIs · WebSockets · SQLite · Event-Driven Automation
AI Development Tools: Claude Code · OpenAI Codex · Cursor · Gemini · ChatGPT · GitHub Copilot
Systems & Development: TypeScript · JavaScript · Bash · Node.js · Swift · Docker · Git · Linux · Vercel
Security Experience
Selected Engineering Systems
- Designed a live system with API integrations, safety controls, SQLite provenance logging, sanitized public status, and a documented execution-incident postmortem — evidence-first engineering transferable to security operations.
- Built a SwiftUI evidence-capture app with simultaneous front/rear recording, GPS/timestamp metadata, and an encrypted, searchable Evidence Vault for traceability and chain of custody.
Professional Experience
Founded an international logistics and vehicle-export business; built internal automation for operations, lead management, and shipment tracking.
Built and operated a manufacturing and distribution company with an international supply chain.
Monitored facility security systems and produced structured incident documentation while completing cybersecurity training and building automation systems independently.
Certifications & Training
CompTIA Security+ CE (Active, expires 2028) · Google Cybersecurity Professional Certificate · Google IT Support Professional Certificate · TryHackMe: Top 8% global, 172K+ score, 50+ rooms
Availability
Authorized to work in the U.S. — no sponsorship required. Open to on-site (Southern California), hybrid, or remote. Available immediately.