About
Logan Elliott, CASP+
Senior Cybersecurity Analyst
Detection Engineer
Threat Hunter
Professional Summary
ElliottSecurity Platform documents real-world cybersecurity engineering work across detection, hunting, forensics, and automation.
Cybersecurity professional with 5+ years of experience supporting Department of Defense operations across incident response, threat hunting, digital forensics, vulnerability management, detection engineering, and threat intelligence. Led 73% of enterprise cybersecurity incidents and 78% of threat hunting operations across 120+ Air Force and Space Force locations. Built 94% of detection queries used by the analyst team, improving detection fidelity and response efficiency. Strong background in SIEM analysis, malware triage, ICS security, and intelligence-driven defense.
Core Skills
- Threat Hunting
- Incident Response
- Detection Engineering
- Threat Intelligence
- Digital Forensics
- Malware Analysis
- SIEM Analysis
- ICS Security
- Vulnerability Management
- Security Consulting
Platform Focus
- Detection Engineering
- Threat Hunting
- Digital Forensics
- Incident Response
- Homelab Engineering
- Security Automation
- Open Source Projects
Current Focus
Active engineering areas and tooling priorities.
Enterprise Detection Engineering Lab
Threat Hunting
Detection Engineering
Incident Response
DFIR
ELK Stack
Proxmox
Fleet
Velociraptor
Sysmon
Security Automation
Professional Experience
Career timeline including current role, prior positions, and education.
Senior Cybersecurity Analyst
General Dynamics
Mar 2024 – Present
Lead enterprise cybersecurity operations across 120+ Air Force and Space Force locations, securing Industrial Control System environments while driving incident response, threat hunting, and detection engineering at scale.
- Lead 73% of enterprise cybersecurity incidents from triage through containment, eradication, recovery, and root cause analysis.
- Lead 78% of enterprise threat hunting operations across multiple security platforms.
- Develop and maintain 94% of threat detection queries, improving detection fidelity and analyst efficiency.
- Produce daily threat intelligence briefings using CISA KEV, BleepingComputer, SANS, and DFIR research to prioritize emerging threats.
- Perform digital forensics, log correlation, artifact collection, and timeline reconstruction mapped to MITRE ATT&CK.
- Conduct malware sandbox analysis to identify indicators of compromise and malicious behavior.
- Tune Trellix endpoint firewall, threat prevention, and Data Loss Prevention policies.
- Author incident response playbooks, mentor analysts, and prepare executive reporting for security leadership.
System Administrator
General Dynamics
Jul 2023 – Mar 2024
Supported AFNORTH/1AF technology refresh initiatives and enterprise endpoint operations during a critical infrastructure modernization period.
- Led AFNORTH/1AF technology refresh initiative with executive project status reporting.
- Deployed endpoint equipment and resolved hardware and software issues with minimal user disruption.
- Managed technology refresh inventory, tracking hardware assets, deployments, and lifecycle replacements.
System Administrator
Forge Forward
Sep 2022 – Aug 2023
Maintained Navy enterprise systems and infrastructure, combining vulnerability management with Active Directory administration and cross-platform patching.
- Supported 140+ Navy systems and resolved 80+ daily support requests with 85% first-contact resolution.
- Used ACAS to identify, assess, and remediate vulnerabilities across enterprise systems.
- Managed Active Directory administration including user accounts, group policies, and access management.
- Maintained RHEL Ansible playbooks and PowerShell scripts for system administration and automation.
IT Specialist
Florida State University
Oct 2021 – Oct 2022
Provided enterprise endpoint support, Active Directory administration, and physical network infrastructure maintenance for campus IT operations.
- Delivered enterprise endpoint support and Active Directory administration.
- Installed, maintained, and troubleshot physical network rack infrastructure including cable management and hardware replacements.
Education
B.S. Cybersecurity and Information Assurance
Western Governors University
Bachelor of Science in Cybersecurity and Information Assurance, building the academic foundation for enterprise security operations, forensics, and defense work.
Certifications
CompTIA credentials supporting enterprise security operations.
CompTIA CASP+
EarnedCompTIA PenTest+
EarnedCompTIA CySA+
EarnedCompTIA Security+
EarnedTechnology Stack
Security platforms, infrastructure, query languages, and forensic tooling from professional operations.
Microsoft Defender for Endpoint
Security
Elastic Security
Security
Trellix
Security
ACAS
Security
HBSS
Security
Cisco ASDM
Security
Windows Server
Platform
Active Directory
Platform
RHEL
Platform
SCCM
Platform
WSUS
Platform
PowerShell
Development
KQL
Development
ES|QL
Development
MITRE ATT&CK
Security
Digital Forensics
Forensics
Threat Hunting
Skills
Detection Engineering
Skills
Malware Analysis
Forensics
IOC Analysis
Forensics
Sandbox Analysis
Forensics