Open to SOC Analyst & Security Operations roles Built with Claude, prompt engineered by me

Nate Sharpley

IT Support Engineer moving into Security Operations

I build blue team environments in a home lab and learn them by breaking them. Most recently a full SOC stack, from the log pipeline through to a written investigation on every alert it raised. Four certifications earned, four lab projects finished, and a roadmap I am still working through in order.

Orange County, California sharpleynate@gmail.com
0
Certifications earned
0
Lab projects completed
0
Days building the SOC
0
Degrees in progress
About

Built to detect,
not just to watch.

Most security work fails quietly. Logs nobody reads, alerts nobody tunes, playbooks nobody tests. I work the other way around. Build the pipeline, write the detection, break it on purpose, then prove it catches what it was written for.

Detection over dashboards

Every detection I write maps to a MITRE ATT&CK technique, gets tested against telemetry from my own lab, then gets tuned. A rule that fires on everything protects nothing.

Identity is the first boundary

I built the domain before I built the sensors. Users, groups, Group Policy, and audit logging came first, because you cannot detect abuse of a directory you have never set up yourself.

Automate what repeats

Enrichment, case creation, notification. If an analyst does it the same way twice it belongs in a workflow, and humans keep the judgement calls. This is the layer I am building right now.

Documentation is the deliverable

Every project ships with a writeup covering what broke, what I fixed, and how I investigated. If I cannot explain the failure, I do not claim the skill.

Certifications

Four earned,
the rest in order.

Fundamentals first, then analyst level detection, then the SIEM platform, then cloud architecture and cloud security. Everything below is marked honestly. Earned means passed and verifiable on Credly. In progress means I am sitting it next.

CompTIA Network+ N10-009 CompTIA Earned
CompTIA Security+ SY0-701 CompTIA Earned
Microsoft Azure Fundamentals AZ-900 Microsoft Earned
CompTIA CySA+ CS0-003 CompTIA Earned
Splunk Core Certified Power User SPLK-1002 Splunk In progress
Splunk Enterprise Certified Admin SPLK-1003 Splunk Planned
Azure Solutions Architect Expert AZ-305 Microsoft Planned
Azure Security Engineer Associate AZ-500 Microsoft Planned
GIAC Python Coder GPYC GIAC / SANS Planned
Terraform Associate TA-003 HashiCorp Planned
Projects

Built, broken,
then rebuilt.

A blue team environment assembled from nothing, in order. Lab, identity, telemetry, detection. Four are finished and documented. The last three are where I am working now, and they are labelled as such. All of it is a personal home lab, not production work, and I would rather say that here than have you find out in the interview.

Capabilities

What I actually work with.

Everything in this section comes from a project I finished or a certification I hold. What I am still learning is in its own block underneath, kept separate on purpose.

Detection Writing

Writing, mapping, and tuning the logic that separates an incident from background noise. Learned by building the rules in my own lab and testing them against simulated attacks.

MITRE ATT&CKSysmonElastic rulesKQL basicsRule tuning

SOC Workflow

Triage, investigation, and the writeup that makes the next analyst faster. Practised end to end on a lab queue, and backed by CySA+ on the theory side.

Alert triageInvestigation writeupsosTicketEvent timelinesCySA+

Identity and Windows

Domain design, Group Policy, and the audit configuration that makes directory abuse visible in the first place.

Active DirectoryGroup PolicyWindows ServerPowerShellAudit policy

Networking

Traffic flow, segmentation, and trust boundaries. The part that decides whether a compromised host can reach anything worth reaching.

TCP/IPSubnettingVLANsDNS and DHCPSegmentationNetwork+

Systems and Virtualisation

Building, breaking, and rebuilding environments on demand. Every lab on this page was stood up and torn down more than once.

VMwareHyper-VLinuxDockerSnapshotsAzure fundamentals

AI and Prompt Engineering

Using models deliberately as part of the workflow, with the output checked before it counts. Detailed in the panel below.

ClaudePrompt engineeringOutput validationWorkflow automation
Learning now

What I am building toward

Listed separately because it has not earned a place above yet. This is the next stretch of the roadmap, in the order I am working through it.

Splunk SPL Wazuh Shuffle SOAR TheHive Microsoft Sentinel Defender for Cloud Entra ID Terraform Python for security
Prompt Engineering

Building with AI, on purpose.

I treat AI the way I treat every other tool in the stack. Deliberately, with my hand on the wheel, and with the output verified before it counts for anything. This entire site was designed and built with Claude, directed by me through iteration rather than a single lucky prompt.

The same workflow runs through my security work. Drafting and stress testing detection logic, turning raw investigation notes into a writeup somebody else can follow, and working through concepts faster than reading alone would allow. The skill is not typing a question into a box. It is knowing what to ask, what to throw away, and where the model is confidently wrong. Security teams that figure that out early move faster than the ones still arguing about whether to allow it.

How I use it
Claude Prompt engineering Detection drafting Report generation Output validation Study and review Workflow automation
Background

How I got here,
and how I work.

A support and operations foundation, rebuilt deliberately toward security. The helpdesk years are not a detour. They are where the instinct for how systems actually break came from.

Education

  • In progress
    B.S. Information Technology
    Western Governors University

    Competency based programme covering networking, systems administration, scripting, applied statistics, and IT project management. Accelerated with transfer credit.

  • In progress
    M.S. Business Management
    Western Governors University

    Graduate work bridging technical security operations and the business side of risk. Governance, budgeting, and communicating security posture to people who do not read alert queues.

Experience

  • Current
    Technical Support and Operations
    Epson

    Front line troubleshooting across hardware, networking, and remote access. Daily practice at the thing security interviews actually test: isolating a fault from incomplete information, then explaining it to someone who is not technical.

  • Previous
    IT Support
    Long Beach Unified School District

    End user support and device management at scale across a large public institution. Imaging, account administration, and connectivity issues across multiple sites.

  • Ongoing
    Independent Security Lab
    Self directed

    Continuous build and break work on my own time. Every completed project on this site was designed, deployed, documented, and tuned by me.

Rule 01

Foundation before automation

Identity and telemetry get built and understood first. Nothing gets automated on top of a system I cannot explain.

Rule 02

Document what broke

Every project carries the failure, the fix, and the investigation path. The writeup is part of the build, not an afterthought.

Rule 03

No shortcuts in the order

Certifications and projects are sequenced on purpose. Nothing gets skipped because it looks slow or unglamorous.

Rule 04

Say what is not done yet

In progress is labelled in progress. A portfolio that overstates itself falls apart in the first technical interview.

Where I fit

I am looking for my first security seat, and I have done the homework to be useful on day one rather than starting from zero. I have built the stack myself, written and tuned the detections, worked a queue end to end in the lab, and I bring a few years of real support experience with users, escalation, and troubleshooting under pressure. I am not going to tell you I have production SOC time, because I have not had the seat yet. What I will tell you is that I am the person who spends an evening figuring out why one rule fired twice, and then writes it up so nobody else has to.

SOC Analyst, Tier 1 Security Analyst Junior Security Analyst Technical Support Engineer, Tier 2 Cloud Support and Operations

Working toward Cloud Security Analyst and Security Operations Engineer as the Splunk and Azure certifications land.

Contact

Come say hello.

Whether you are hiring, comparing notes on detection work, or just curious how something on this page was put together, I would genuinely like to hear from you.

No form, no autoresponder, no recruiter funnel. Just my inbox, and I read all of it.

sharpleynate@gmail.com

I usually reply within a day

or find me here
Available now Orange County, CA Open to relocation Remote friendly

Thanks for scrolling all the way down here. If any of this was useful to you, that already made it worth building.
Nate