Joel A.

Manager, Cybersecurity Operations

Missouri City, Texas, United States

About

With over 12 years of experience in cybersecurity, I focus on enhancing organizational security through exposure management, risk assessment, and information security practices. At Confidential-Oil & Gas, my work includes expanding vulnerability management programs, implementing advanced security tools such as External Attack Surface Management and CNAPP, and monitoring emerging threats to mitigate risks effectively. Holding multiple GIAC certifications, I am committed to fostering collaboration across teams, refining risk prioritization methodologies, and driving initiatives to fortify the company's attack surface. My mission is to contribute to a resilient cybersecurity posture by integrating cutting-edge technologies and fostering a proactive approach to threat mitigation.

Experience

  • Customer Advisory Board at Tenable
    Apr 2026 - Present · 4 mos

  • Manager, Cybersecurity Operations at Confidential-Oil & Gas
    Aug 2021 - Present · 5 yrs

    ◆ Expanded the vulnerability management program by increasing the scope of assessed platforms, enhancing the risk prioritization methodology, and boosting stakeholder engagement in remediation efforts across the company. ◆ Implemented and administered the company's External Attack Surface Management tool, Cloud Native Protection Platform (CNAPP), Web Application Scanner, and network vulnerability scanner to identify risks through frequent scans of the company's attack surface. ◆ Monitored government and industry bulletins and threat intelligence for recently disclosed vulnerabilities and attacks that could potentially be used against the company. ◆ Analyzed all scan results and recommended appropriate remediation actions based on impact to the company. ◆ Created dashboards and reports for various stakeholders to view risk trends and remediation progress. ◆ Coordinated with stakeholders across the company to prioritize and remediate identified risks. ◆ Created realistic email templates for the company’s phishing awareness program to train employees to identify and report actual malicious emails. ◆ Tuned security tools used for Security Incident and Event Management (SIEM), Network Detection and Response (NDR), and Endpoint Detection and Response (EDR), and vulnerability scanning to reduce/eliminate false positives. ◆ Created process for and performed threat hunts based on threat intel (recent attacks, IOCs, and attacker specific Tactics, Techniques, Procedures). ◆ Responded as needed to incidents such as phishing campaigns, unauthorized logons, malicious network traffic, etc.

  • Specialist, Security Engineering at Plains All American
    Dec 2017 - Aug 2021 · 3 yrs 9 mos

    ◆ Performed internal and external network scans and reported vulnerabilities, misconfigurations, and other relevant findings to the responsible organizations for remediation improving overall security posture ◆ Responded to alerts for potential incidents such as phishing campaigns, unauthorized logons, unauthorized network scans, etc. ◆ Created company IT security awareness training to improve employees’ awareness of cybersecurity best practices and company policies. ◆ Implemented, administered, and tuned security tools used for vulnerability scanning, endpoint protection (XDR), log aggregation/correlation (SIEM), email security, web filtering, and file integrity monitoring. ◆ Monitored related government and industry bulletins and threat intel research for recently disclosed vulnerabilities and attacks to determine applicability to the company’s environment ◆ Performed threat hunts based on threat intel (recent attacks, IOCs, and attacker specific Tactics, Techniques, Procedures)

  • Booz Allen Hamilton ()
    • Information Security Consultant
      Apr 2014 - Dec 2017 · 3 yrs 9 mos

      ◆ Maintain situational awareness of cyber activity by reviewing reports of new vulnerabilities, malware, or other potential threats that could impact the organization ◆ Assess client organization's IT security risk and make recommendations to reduce or remediate it ◆ Scan network infrastructure and endpoint devices for vulnerabilities such as missing security updates, un-secure configurations, and malware ◆ Recommend changes to improve compliance in preparation for third party security audits ◆ Review and update security policy documents including System Security Plans, Incident Response Plans, and Contingency/Disaster Recovery Plans ◆ Performed NIST-based compliance audits to recommend an Authority-to-Operate (ATO) ◆ Analyzed the IT security impact of architecture and requirements changes ◆ Created informational dashboards for C-Level management to understand organization's current security posture and the associated risk

    • Software Architect
      Mar 2007 - Apr 2014 · 7 yrs 2 mos

      ◆ Oversaw all aspects of developing custom applications including requirements gathering, design, development, testing, deployment, and sustaining operations. ◆ Determined use cases and business needs for web applications, software models, and process automation tools. ◆ Created custom Java applications to perform engineering analyses 120x faster making the process 93% more efficient ultimately saving $600,000 in labor costs. ◆ Created software tools to automate processes and generate required documentation in MS Office formats. ◆ Tested newly implemented application upgrades to find defects prior to the push to production. ◆ Led efforts to upgrade client's legacy analytic tools from being spreadsheet based to object oriented software applications.

  • Communication Systems Engineer at United Space Alliance
    Aug 2003 - Mar 2007 · 3 yrs 8 mos

    ◆ Monitored and controlled NASA spacecraft's information gathering and communications systems. ◆ Diagnosed the root cause of avionics equipment failures and implemented corrective action plans. ◆ Trained and evaluated new team members on technical systems. ◆ Created detailed hardware schematics of avionics equipment for reference and failure analysis. ◆ Performed User Acceptance Testing (UAT) of critical software for NASA Space Shuttle missions.