DEFEND // DETECT // RESPOND
Blue Team
Turn signals into decisions, incidents into lessons, and risk into a security program.
- 01 · ENTRY
SOC Analyst — Tier 1

Read logs, triage SIEM/EDR alerts, investigate phishing and escalate with evidence.
SIEMEDRMITRE ATT&CKBuild: investigate a public log dataset and publish an incident timeline.
Security+ · BTL1 · SC-200
- 02 · OPERATOR
Incident Responder / SOC Tier 2

Investigate endpoints and networks, contain threats, collect evidence and run playbooks.
DFIRThreat huntingContainmentBuild: a ransomware response playbook with decision points.
BTL2 · GCIH when employer-funded
- 03 · SPECIALIST
Detection Engineer / Threat Hunter

Engineer detections, map ATT&CK coverage and reduce false positives with tested rules.
SigmaKQL / SPLPurple teamBuild: a documented detection pack with test telemetry.
SC-200 · GCIA / GCDA by specialization
- 04 · LEAD
Security Engineer / Blue Team Lead

Design defensive architecture, IAM, cloud controls, segmentation and measurable SOC operations.
ArchitectureCloud securityMentoringBuild: a prioritized target architecture and risk-reduction plan.
AZ-500 · AWS Security · CISSP with experience
- 05 · EXECUTIVE
Security Manager → CISO

Own governance, budget, third-party risk, crisis communication and security strategy.
RiskGovernanceLeadershipBuild: an annual security program with objectives, scenarios and metrics.
CISSP · CISM · CRISC—pick for the role




