// CYBERSECURITY ANALYST — CON EDISON, NYC

DANIEL
FRANCO

Cybersecurity Analyst · Incident Responder · Detection Engineer
Cloud security across Azure + AWS · SIEM · EDR · Purple Team · AppSec

Con Edison DFIR KQL Elastic Sentinel AWS CCP MITRE ATT&CK Purple Team AppSec
TOTAL VISITORS
bash — danny@soc-01 ~ whoami
daniel@soc-01:~$ cat profile.txt
Name : Daniel Franco
Role : Cybersecurity Analyst — Consolidated Edison (Con Ed), NYC
Location : New York City Metropolitan Area
Focus : Threat Hunting, Incident Response, Detection Engineering, Purple Team
Env : Enterprise SIEM, EDR, IDS/IPS, NDR · Cloud: Azure + AWS

daniel@soc-01:~$ ls certs/
Security+.cert Network+.cert CySA+.cert AWS-CCP.cert CCD.cert

daniel@soc-01:~$ tail -1 /var/log/current_status.log
[ACTIVE] Threat hunting | Detection engineering | Open to security opportunities

daniel@soc-01:~$

Core Skills

🔍
Threat Hunting & DFIR

Proactive hunting across SIEM, EDR, and NDR platforms. Memory forensics with Volatility. Disk triage with Eric Zimmerman tools. Cloud forensics in Azure and AWS.

Volatility MFTECmd Autopsy Wireshark
☁️
Cloud Security

Security guidance across cloud and on-prem environments. Investigated multi-stage Azure attacks involving privilege escalation, malicious app registration, and data exfiltration.

Azure Sentinel KQL AWS OT/ICS
📊
Detection Engineering

Custom detection rules and security use cases across enterprise SIEM, EDR, IDS/IPS, and NDR. Reduced MTTD through tuned alerting and log correlation.

Elastic SIEM Sentinel KQL EQL
🔐
Application Security

30+ security assessments on externally facing web apps at Cboe. DAST, SAST, SCA testing. Manual penetration testing. Spearheaded Security Champions Program.

DAST SAST SCA Pen Testing
🛡️
Incident Response

Phishing triage, PII/PHI data privacy incidents, credential compromise prevention. Regulatory compliance across enterprise critical infrastructure environments.

EDR IDS/IPS NDR SIEM
⚔️
Purple Teaming

Cross-functional exercises validating security controls and improving defensive capabilities. Vulnerability management with risk-based prioritization and business impact analysis.

ATT&CK Vuln Mgmt Risk Assessment

Work History

JUN 2024 — PRESENT
Con Edison
New York City Metro
Cybersecurity Analyst
  • Advanced threat hunting and incident response across enterprise SIEM, EDR, IDS/IPS, and NDR platforms
  • Custom detection rules and security use cases to enhance threat visibility and reduce MTTD
  • Triage and analysis of sophisticated phishing campaigns preventing credential compromise and data breaches
  • PII/PHI data privacy incident investigations ensuring regulatory compliance
  • OT/ICS security collaboration with operational technology teams across critical infrastructure
  • Purple team exercises validating security controls and improving defensive capabilities
  • Enterprise-wide vulnerability management with risk-based prioritization
APR 2023 — APR 2024
Cboe Global Markets
New York, NY
Application Security Intern
  • Security assessments on 30+ externally facing web applications, identifying critical vulnerabilities pre-production
  • Manual penetration testing uncovering complex vulnerabilities missed by automated scanning
  • API security posture improvements via endpoint discovery and monitoring solutions
  • Multi-layered testing strategy: DAST, SCA, and SAST across diverse application portfolios
  • Spearheaded the launch of the organization's Security Champions Program
  • Security guidance throughout SDLC from design through deployment
MAY 2022 — SEP 2022
Bloomberg
New York City Metro
IT Contractor
  • End-to-end deployment of complex IT infrastructure across enterprise environments
  • Proactive technical support strategies preventing system issues before business impact
  • Escalated troubleshooting of workstations, servers, networking equipment, and enterprise applications
MAR 2021 — APR 2023
American Info Systems
New York, NY
IT Help Desk
  • Technical support across Windows and Mac environments — hardware, software, and network issues
  • Hardware deployments and system installations minimizing operational downtime
  • Knowledge base documentation and end-user security awareness training

Credentials

CompTIA
Security+
✓ ACTIVE
CompTIA
Network+
✓ ACTIVE
CompTIA
CySA+
✓ ACTIVE
Amazon Web Services
AWS Certified Cloud Practitioner
✓ ACTIVE
Pwned Labs
Amazon Cloud Attack & Defense Bootcamp
✓ ACTIVE
INE / eLearnSecurity
CCD — Certified Cyber Defender
✓ ACTIVE

Get In Touch

Open to discussing security engineering roles, threat intelligence opportunities, or collaborating on detection engineering and DFIR projects.