About

Logan Elliott, CASP+

Senior Cybersecurity Analyst

Detection Engineer

Threat Hunter

Threat Hunting · Incident Response · DFIR · Threat Intelligence

Panama City Beach, FL · Active Secret Clearance

Professional Summary

ElliottSecurity Platform documents real-world cybersecurity engineering work across detection, hunting, forensics, and automation.

Cybersecurity professional with 5+ years of experience supporting Department of Defense operations across incident response, threat hunting, digital forensics, vulnerability management, detection engineering, and threat intelligence. Led 73% of enterprise cybersecurity incidents and 78% of threat hunting operations across 120+ Air Force and Space Force locations. Built 94% of detection queries used by the analyst team, improving detection fidelity and response efficiency. Strong background in SIEM analysis, malware triage, ICS security, and intelligence-driven defense.

Core Skills

  • Threat Hunting
  • Incident Response
  • Detection Engineering
  • Threat Intelligence
  • Digital Forensics
  • Malware Analysis
  • SIEM Analysis
  • ICS Security
  • Vulnerability Management
  • Security Consulting

Platform Focus

  • Detection Engineering
  • Threat Hunting
  • Digital Forensics
  • Incident Response
  • Homelab Engineering
  • Security Automation
  • Open Source Projects

Current Focus

Active engineering areas and tooling priorities.

  • Enterprise Detection Engineering Lab

  • Threat Hunting

  • Detection Engineering

  • Incident Response

  • DFIR

  • ELK Stack

  • Proxmox

  • Fleet

  • Velociraptor

  • Sysmon

  • Security Automation

Professional Experience

Career timeline including current role, prior positions, and education.

  1. Senior Cybersecurity Analyst

    General Dynamics

    Mar 2024 – Present

    Lead enterprise cybersecurity operations across 120+ Air Force and Space Force locations, securing Industrial Control System environments while driving incident response, threat hunting, and detection engineering at scale.

    • Lead 73% of enterprise cybersecurity incidents from triage through containment, eradication, recovery, and root cause analysis.
    • Lead 78% of enterprise threat hunting operations across multiple security platforms.
    • Develop and maintain 94% of threat detection queries, improving detection fidelity and analyst efficiency.
    • Produce daily threat intelligence briefings using CISA KEV, BleepingComputer, SANS, and DFIR research to prioritize emerging threats.
    • Perform digital forensics, log correlation, artifact collection, and timeline reconstruction mapped to MITRE ATT&CK.
    • Conduct malware sandbox analysis to identify indicators of compromise and malicious behavior.
    • Tune Trellix endpoint firewall, threat prevention, and Data Loss Prevention policies.
    • Author incident response playbooks, mentor analysts, and prepare executive reporting for security leadership.
  2. System Administrator

    General Dynamics

    Jul 2023 – Mar 2024

    Supported AFNORTH/1AF technology refresh initiatives and enterprise endpoint operations during a critical infrastructure modernization period.

    • Led AFNORTH/1AF technology refresh initiative with executive project status reporting.
    • Deployed endpoint equipment and resolved hardware and software issues with minimal user disruption.
    • Managed technology refresh inventory, tracking hardware assets, deployments, and lifecycle replacements.
  3. System Administrator

    Forge Forward

    Sep 2022 – Aug 2023

    Maintained Navy enterprise systems and infrastructure, combining vulnerability management with Active Directory administration and cross-platform patching.

    • Supported 140+ Navy systems and resolved 80+ daily support requests with 85% first-contact resolution.
    • Used ACAS to identify, assess, and remediate vulnerabilities across enterprise systems.
    • Managed Active Directory administration including user accounts, group policies, and access management.
    • Maintained RHEL Ansible playbooks and PowerShell scripts for system administration and automation.
  4. IT Specialist

    Florida State University

    Oct 2021 – Oct 2022

    Provided enterprise endpoint support, Active Directory administration, and physical network infrastructure maintenance for campus IT operations.

    • Delivered enterprise endpoint support and Active Directory administration.
    • Installed, maintained, and troubleshot physical network rack infrastructure including cable management and hardware replacements.
  5. Education

    B.S. Cybersecurity and Information Assurance

    Western Governors University

    Bachelor of Science in Cybersecurity and Information Assurance, building the academic foundation for enterprise security operations, forensics, and defense work.

Certifications

CompTIA credentials supporting enterprise security operations.

CompTIA CASP+

Earned
View credential

CompTIA PenTest+

Earned
View credential

CompTIA CySA+

Earned
View credential

CompTIA Security+

Earned
View credential

Technology Stack

Security platforms, infrastructure, query languages, and forensic tooling from professional operations.

  • Microsoft Defender for Endpoint

    Security

  • Elastic Security

    Security

  • Trellix

    Security

  • ACAS

    Security

  • HBSS

    Security

  • Cisco ASDM

    Security

  • Windows Server

    Platform

  • Active Directory

    Platform

  • RHEL

    Platform

  • SCCM

    Platform

  • WSUS

    Platform

  • PowerShell

    Development

  • KQL

    Development

  • ES|QL

    Development

  • MITRE ATT&CK

    Security

  • Digital Forensics

    Forensics

  • Threat Hunting

    Skills

  • Detection Engineering

    Skills

  • Malware Analysis

    Forensics

  • IOC Analysis

    Forensics

  • Sandbox Analysis

    Forensics