J

Jonathan suldo

About

Detail

Senior Cybersecurity Engineer | Cloud Security Engineer
Dallas, Texas, United States

Contact Jonathan regarding: 
work
Full-time jobs

Timeline


work
Job
school
Education

Résumé


Jobs verified_user 0% verified
  • Guidewire
    Senior Cybersecurity Engineer, Vulnerability Management Consultant (Tier 2)
    Guidewire
    Apr 2026 - Current (7 months)
    • Own end-to-end vulnerability and exposure management across cloud, infrastructure, and application environments for a nine-business-unit enterprise, carrying 764 findings through validation, deduplication, enrichment, prioritization, and remediation closure.
    • Validated cloud security posture policy coverage against the enterprise AWS hardening standard across 669 controls and 214 custom alerts, introducing a mapped-versus-enforced distinction that reset the reported coverage position from 232/669 (34.7%) to a defensible 192/669 enforced (28.7%), reconciled against four compliance-framework exports.
    • Extended that validation with service-alias canonicalization (89 raw labels to 84 canonical), editable match-confidence banding,
  • DTCC
    Cybersecurity Engineer — Risk & Compliance
    DTCC
    May 2024 - Dec 2025 (1 year 8 months)
    • Mapped regulatory requirements to policies, standards, procedures, and existing control frameworks.
    • Reviewed cybersecurity policies and procedures to identify compliance gaps and define remediation needs.
    • Maintained the library of applicable cybersecurity laws, regulations, requirements, and resulting controls.
    • Monitored regulatory change and assessed the control-environment enhancements each change required.
    • Prepared program status reporting for governance forums and senior management.
    • Supported impact assessments for new and changing regulatory requirements.
    • Evaluated new initiatives and business ventures for cybersecurity compliance readiness.
  • N
    Senior Cybersecurity Engineer
    Nissan Financial — TMCS
    May 2023 - Feb 2024 (10 months)
    • Led security architecture governance aligned to business and technology strategy.
    • Partnered with cross-functional teams to define security requirements for application and system architectures.
    • Conducted risk assessments, developed mitigation strategies, and communicated findings to project teams and leadership.
  • I
    Penetration Testing & DevSecOps Engineer (Contract Engagement)
    Iron Wood Cyber
    Jun 2022 - Apr 2023 (11 months)
    • Integrated AWS CloudTrail, GuardDuty, VPC Flow Logs, and application logs into Splunk for centralized monitoring.
    • Developed correlation rules detecting failed authentication, privilege escalation, and suspicious API activity.
    • Automated security playbooks and response workflows through SOAR for real-time threat mitigation.
    • Deployed QRadar compliance dashboards for HIPAA and NIST 800-171 and integrated CrowdStrike endpoint telemetry.
    • Built Terraform modules for IAM hardening and automated remediation.
    • Implemented managed detection and response through CrowdStrike to strengthen endpoint visibility.
  • Bank of America
    Cybersecurity Architect (Contract Engagement)
    Bank of America
    Sep 2021 - Jun 2022 (10 months)
    • Established processes and supporting infrastructure for enterprise vulnerability management programs.
    • Managed security operations in a large-scale environment aligned to enterprise policy.
    • Led endpoint proxy and data loss prevention initiatives, reducing endpoint vulnerabilities by 20%.
    • Designed security architecture for Kubernetes and microservices environments.
  • Cloudelligent
    Cloud Security Engineer & Administrator (Contract Engagement)
    Cloudelligent
    Jul 2021 - Nov 2022 (1 year 5 months)
    • Deployed AWS IAM Identity Center with MFA enforcement and conditional access controls.
    • Implemented Microsoft Entra ID conditional access policies enforcing identity and device compliance.
    • Applied AWS PrivateLink and Service Control Policies to restrict access to critical services.
    • Integrated Splunk with AWS Security Hub for real-time cloud security monitoring.
    • Applied NIST, CIS, and ISO-aligned controls to strengthen cloud posture across AWS and Azure.
    • Configured AWS Security Hub, GuardDuty, Config Rules, and Macie to improve compliance monitoring and threat detection.
    • Supported penetration testing, DLP, and continuous threat hunting activities.
    • Automated security checks with AWS Config Rul
  • Celanese
    Senior SOC Analyst
    Celanese
    Apr 2020 - Jun 2021 (1 year 3 months)
    • Led threat detection, incident response, and vulnerability management using Splunk, QRadar, CrowdStrike, Defender ATP, and UEBA tooling.
    • Investigated APT, ransomware, phishing, and insider threat activity under the NIST 800-61 incident response lifecycle.
    • Performed AWS and Azure cloud security assessments, remediated misconfigurations, and enforced IAM best practice.
    • Developed custom detection rules, YARA signatures, and automation scripts to improve SOC efficiency and reduce false positives.
    • Led insider threat investigations using DLP and behavioral analytics to identify unauthorized access and policy violations.
    • Delivered executive reporting, risk assessments, post-incident reviews, and SOAR playbooks
  • I
    Senior Security Administrator & SOC Analyst
    Independent Consulting (via Upwork)
    Nov 2017 - Apr 2020 (2 years 6 months)
    • Led enterprise security monitoring and incident response in a 24/7 SOC supporting AWS and on-premises environments.
    • Strengthened SOC operations, SIEM monitoring, and incident response while supporting NIST 800-53, CIS, ISO 27001, PCI-DSS, HIPAA, and SOX controls.
    • Managed L2 and L3 SOC analysts and improved detection and response performance, reducing MTTD by 35% and MTTR by 40%.
    • Designed SIEM rules, dashboards, and alerts in Splunk, QRadar, and Microsoft Sentinel.
    • Conducted threat intelligence analysis using MITRE ATT&CK to improve detection coverage against APTs and emerging threats.
    • Automated alert triage and threat enrichment with Python, APIs, and SOAR playbooks, reducing false positives by 50%.
  • A
    Senior Information Security Analyst & Lead Penetration Tester
    Arma-Net Labs, LLC
    Jul 2014 - Nov 2017 (3 years 5 months)
    • Maintained the enterprise risk register and documented mitigation and risk-acceptance artifacts.
    • Managed compliance engagements under NIST, ISO 27002, COBIT, SOX, PCI-DSS, and FISMA.
    • Led secure SDLC design reviews supporting secure application deployment.
    • Conducted web application testing and developed security evaluation test plans.
    • Monitored SIEM, IDS/IPS, DLP, and FIM technologies to detect and escalate security incidents.
    • Performed penetration testing against complex networks and web applications and delivered actionable remediation reports.
    • Led vulnerability assessments and prepared detailed security assessment reports for stakeholders.
    • Supported incident response and coordinated remed
  • B
    Network Security Analyst | SCADA Cybersecurity Engineer
    Braeden Engineering
    Apr 2008 - Apr 2014 (6 years 1 month)
    • Performed black-box and white-box penetration testing on ICS and embedded critical-asset components.
    • Conducted vulnerability assessments, design reviews, and code reviews for oil and gas asset management systems.
    • Supported security operations across UNIX/Linux and Windows platforms, network services, encryption technologies, and enterprise applications.
    • Maintained security governance policies, standards, guidelines, procedures, and controls.
    • Monitored next-generation firewalls, UTM, SIEM, HIDS, and NIDS platforms and performed continuous assessments.
    • Delivered recommendations to strengthen enterprise security architecture.
    • Provided desktop support for office and factory-floor systems across approx
  • L
    Non-Commissioned Officer, Command Section, 256th
    Louisiana Army National Guard — Command Section
    Jan 2000 - Jan 2008 (8 years 1 month)
    • Served in the Command Section of the 256th, including 18 months deployed in support of Operation Iraqi Freedom, providing protection and support for senior leadership.
    • Purple Heart recipient.
Education verified_user 0% verified
  • S
    Master of Science — Cybersecurity
    SANS Institute of Technology
    In Progress
  • C
    CISSP — Certified Information Systems Security Professional
    Jan 2024
  • C
    Certified Ethical Hacker
    Jan 2022
  • C
    CompTIA Security+
    Jan 2020
  • C
    CompTIA Network+
    Jan 2019
  • P
    Python for Penetration Testing — SPSE
    Jan 2018
  • C
    CompTIA A+
    Jan 2018
  • University of Louisiana at Lafayette
    Bachelor of Science — Marketing and Technology
    University of Louisiana at Lafayette
    Jan 2008
This is a community-created genome.