Resume

Jacob Asare

SOC Analyst 1 |Cybersecurity Analyst 1| Junior EDR Alert Monitoring & Incident Response| Pen Tester 1

Woodbridge, VA  |   571-778-2840   |   asarejayke@gmail.com   |    https://sites.wp.odu.edu/jacobasare/ | https://www.linkedin.com/in/jacob-asare

PROFESSIONAL SUMMARY

Cybersecurity professional combining 13+ years of security operations experience with hands-on technical training through a B.S. in Cybersecurity (3.97 GPA, expected Fall 2026). CompTIA Security+ certified, with lab-validated experience across the full security lifecycle: threat modeling (STRIDE/DREAD), network reconnaissance and vulnerability scanning (Nmap, NSE scripts), exploitation (Metasploit), OSINT (Shodan, WHOIS, Netcraft), dynamic malware analysis (Any.Run), and digital forensics (Autopsy, OSForensics, WinHex). Skilled at translating technical findings into clear, structured documentation for both technical and non-technical stakeholders — a strength built over a decade of real-time incident monitoring, triage, and escalation in high-stakes environments. Seeking an entry-level SOC Analyst, EDR Alert Monitoring, Cybersecurity Analyst or Penetration Testing role where rigorous documentation habits, sound judgment under pressure, and hands-on offensive/defensive lab experience deliver immediate value.

CORE COMPETENCIES

▪ Penetration Testing & Ethical Hacking▪ Vulnerability Assessment & Scanning
▪ Threat Modeling (STRIDE / DREAD)▪ OSINT & Passive Reconnaissance
▪ Digital Forensics & Evidence Handling▪ Malware Analysis (Dynamic Sandbox)
▪ Network Traffic Analysis (Wireshark, Nmap)▪ MITRE ATT&CK Mapping
▪ EDR Alert Triage & Investigation▪ Incident Response & Documentation
▪ Python Scripting & Linux CLI▪ Stakeholder Communication & Reporting

TECHNICAL SKILLS

Offensive Security: Nmap (host discovery, port/service scanning, NSE vulnerability & brute-force scripts), Metasploit Framework (exploit selection, payload configuration, session management), DNS enumeration (dig, host, dnsenum, zone transfer testing)

OSINT & Recon: Shodan (exposed device/CVE discovery), WHOIS & Netcraft (domain/IP intelligence), ICS/IoT exposure analysis, MITRE ATT&CK Enterprise Matrix mapping

Malware Analysis: Any.Run dynamic sandbox analysis, Malware Bazaar sample retrieval, IOC identification, HTTP/DNS traffic review, C2 and propagation behavior analysis

Digital Forensics: Autopsy (disk imaging, write-blocking, evidence acquisition), OSForensics (cloud-sync artifact analysis — Dropbox, Google Drive, OneDrive), WinHex (MAC timestamps, artifact inspection), Windows Prefetch analysis, FAT/NTFS/ext file recovery, chain-of-custody documentation

Monitoring & Response: EDR concepts, Intrusion Detection Systems, Microsoft Sentinel (familiar), Microsoft Azure (familiar), alert triage & true/false-positive validation, security playbooks

Scripting & Platforms: Python, Windows PowerShell, Linux command line, Wireshark, TCP/IP fundamentals, GitHub

CERTIFICATIONS

  • CompTIA Security+

HANDS-ON LABS & PROJECTS

  • Penetration Testing Lab (Metasploitable 2 and Kali Linux): Built DFDs and applied STRIDE/DREAD threat modeling to map trust boundaries; ran Nmap reconnaissance and NSE vulnerability scans across FTP, HTTP, SMB, and RPC services; selected and executed Metasploit exploits to achieve remote command execution, with exploit-to-payload justification documented in a structured technical report.
  • OSINT & Exposed-Asset Assessment: Used Shodan to identify internet-exposed IoT/ICS devices (including Modbus/port 502 systems), CVEs, and misconfigurations; performed WHOIS/Netcraft lookups for infrastructure intelligence and mapped findings to MITRE ATT&CK techniques with recommended mitigations.
  • Malware Behavioral Analysis (Cloud Sandbox): Retrieved Mirai and VIPKeylogger samples from Malware Bazaar and detonated them in Any.Run; analyzed HTTP requests, DNS queries, and network connections to extract IOCs and map behavior to ATT&CK techniques, contrasting botnet propagation versus credential-theft tactics.
  • Digital Forensics Investigation: Acquired forensic disk images in Autopsy under write-blocking principles; recovered deleted files and metadata from FAT/NTFS/ext file systems; analyzed Windows Prefetch execution artifacts and cloud-sync logs (Dropbox, Google Drive, OneDrive) to reconstruct user activity and file-upload timelines.
  • S-DES Encryption Tool (Python): Developed a Python implementation of the Simplified Data Encryption Standard, including an SVG diagram of the algorithm and a recorded technical walkthrough of the encryption/decryption workflow.
  • Self-Directed Practice: Completed offensive and defensive security exercises on TryHackMe, Hack The Box, and Let’s Defend, including CTF challenges and independent study of Microsoft Sentinel and Azure.

PROFESSIONAL EXPERIENCE

Security Shift Supervisor                                                                                                   2011 – 2024

Allied Universal Security Protection Service | National Academy of Sciences (NAS), Washington, DC

  • Monitored security alarms and access control logs in real time, investigating anomalous events and validating true/false positives — directly analogous to EDR alert triage.
  • Authored structured incident reports for every event, mirroring the documentation rigor required for security playbooks and incident tickets.
  • Supervised a security team, coordinating response and remediation across shifts and ensuring consistent handoff of open issues.
  • Proactively identified and escalated physical vulnerabilities, preventing losses to assets valued at over $100M.
  • Adjusted procedures under pressure to protect a high-profile executive during a sensitive event, reflecting sound judgment in time-critical decisions.

Dispatcher / Security Officer                                                                                               2007 – 2011

Securitas Security Services | Crystal City, VA

  • Detected, documented, and reported a wanted suspect to law enforcement, resulting in successful apprehension.
  • Identified and reported facility water leaks early, minimizing operational downtime and asset damage.
  • Coordinated emergency response across Fire, Police, and Security departments during active incidents.
  • Maintained organized, audit-ready incident records; recognized multiple times as Officer of the Month and Officer of the Year.

Middle School Mathematics Teacher                                                                                       2003 – 2006

Ghana Education Service (GES) | Ghana

  • Delivered structured, curriculum-aligned lessons, building analytical and problem-solving skills transferable to technical troubleshooting.
  • Tracked student progress through detailed, ongoing assessment reporting; recognized as Best Mathematics Teacher in the District (2004).

EDUCATION

Bachelor of Science in Cybersecurity — Old Dominion University, Norfolk, VA       Expected Fall 2026

GPA: 3.97 Cumulative

Post-Secondary Teacher’s Certificate “A”, Mathematics — University of Cape Coast, Ghana

Graduated: 2003

ADDITIONAL SKILLS

Communication • Interpersonal Relationship Skills • Customer Service • Problem Solving • Adaptability • Team Collaboration • Attention to Detail • Time Management • Leadership