Danielle Okafor
Cybersecurity Analyst · Columbus, OH · danielle.okafor@example.com · linkedin.com/in/danielleokafor
Summary
Cybersecurity analyst with 5 years across SOC operations, detection engineering, and incident response. Cut mean time to triage 55% at 2K alerts/week by tuning Splunk detections and authoring 30 SOAR playbooks; led response on 12 P1 incidents including a ransomware containment with zero data loss. Strong on MITRE ATT&CK-mapped detection coverage, EDR (CrowdStrike), and translating findings for non-security leadership. Security+ and CySA+; GCIH in progress.
Professional Experience
Cybersecurity Analyst II · Meridian Health Network
May 2023 – Present
- Cut mean time to triage 55% (34 to 15 minutes) across 2K alerts/week by tuning Splunk correlation searches and killing the 12 noisiest low-value detection rules.
- Led containment on 12 P1 incidents, including a ransomware intrusion isolated within 40 minutes of detection — zero data loss and no ransom engagement, per the after-action review.
- Authored 30 SOAR playbooks (Phantom) automating enrichment and containment for the top alert classes, saving the SOC an estimated 25 analyst-hours/week.
- Raised MITRE ATT&CK detection coverage from 34% to 71% of prioritized techniques by building 45 new detections mapped and tested against Atomic Red Team.
- Cut phishing-report-to-quarantine time from 4 hours to 12 minutes by deploying automated header analysis and one-click mailbox purge for 8,000 users.
SOC Analyst I · Ravencrest Managed Security
Jun 2021 – Apr 2023
- Triaged 60+ alerts/shift across 14 client environments (Splunk, Microsoft Sentinel), maintaining a 96% true-positive escalation accuracy score.
- Detected and escalated a live business-email-compromise attempt that stopped a $240K fraudulent wire transfer for a client.
- Wrote the tier-1 triage guide for 9 common alert types, cutting new-analyst ramp time from 8 weeks to 5.
Projects
Home detection lab
- Run a documented lab (Security Onion, Sysmon, Atomic Red Team) publishing detection write-ups for 20+ ATT&CK techniques; two write-ups cited in a SANS community newsletter.
Technical Skills
- Detection & response: SIEM (Splunk, Microsoft Sentinel), EDR (CrowdStrike Falcon), SOAR (Splunk Phantom), MITRE ATT&CK, incident response, threat hunting, phishing analysis
- Platform & frameworks: NIST CSF / 800-61, Python (automation), KQL & SPL, network analysis (Wireshark, Zeek), vulnerability management (Tenable), Active Directory / Entra ID
Certifications & Education
- B.S. Cybersecurity, Ohio State University — May 2021
- CompTIA CySA+ — Mar 2023 · CompTIA Security+ — Nov 2020
- SANS GCIH (GIAC Certified Incident Handler) — in progress, exam Dec 2026