Security analysis grounded in evidence.

Hands-on lab and project experience across security operations, network analysis, incident investigation, Windows/Linux infrastructure, and telemetry integration.

Portrait of Jacob Macdonnell
Jacob MacdonnellSecurity Analyst
Security OperationsNetwork AnalysisIncident InvestigationEndpoint & Log Analysis

Professional summary

Security operations-focused analyst with hands-on lab and project experience in incident investigation, network analysis, Windows/Linux infrastructure, and telemetry integration. In controlled labs and course simulations, I correlate endpoint, network, memory, and Windows event evidence to reconstruct attack chains, determine scope, and document containment-focused recommendations. Supporting work demonstrates Python automation, cross-platform troubleshooting, and clear technical documentation.

Technical skills

Security Operations & Incident Investigation

Alert triage, incident investigation, scope expansion, IOC enrichment, playbooks/runbooks, containment recommendations, incident reporting, MITRE ATT&CK, PICERL in labs and course simulations.

SIEM, Endpoint & Identity

Wazuh SIEM/XDR, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration; Microsoft Learn SC-200 labs covering Microsoft Sentinel/KQL and Defender XDR/Defender for Endpoint; Splunk/SPL in guided labs.

Network Analysis & Digital Forensics Labs

Wireshark, Zeek, RITA, PCAP analysis, TCP/IP, DNS, HTTP/S, C2 beacon analysis, Volatility 3, Procmon, Regshot, malware triage.

Systems & Infrastructure

Windows 11, Windows Server 2022, Ubuntu/Linux, Active Directory/DNS, VMware, network segmentation, static addressing, LVM, Netplan.

Cloud & Platforms

AWS security labs covering S3, IAM, IMDS/SSRF, AWS CLI, and ScoutSuite configuration assessment; GCP and Azure fundamentals.

Scripting & Automation

Python, PowerShell, SQL, Git/GitHub, triage automation, log parsing, evidence extraction.

AI-Assisted Development

ChatGPT/Codex, Claude Code, Google Antigravity.