Cybersecurity @ UTSA

Nicolas Portilla Gomez

Detection engineering on a cloud security foundation.

Fresh off an incident detection & response internship at Marathon Petroleum — EDR triage, SOAR playbooks, threat intel, and OT monitoring — and building a library of platform-agnostic Sigma detections mapped to MITRE ATT&CK. Graduating December 2026.

  • CompTIA Security+
  • AWS Cloud Practitioner
  • Microsoft AZ-900
  • Google Cybersecurity Cert
  • AZ-104 · in progress
pathway.log

The detection engineering pathway

Every entry below is real, dated, and verifiable — cloud foundations first, then cloud security, then the SOC, now detections.

  1. 2024 — 2025 [INFO]

    Cloud foundations

    Earned AWS Cloud Practitioner, Microsoft AZ-900, and the Google Cybersecurity Certificate. Built core skills in Azure, AWS, networking, and Python.

  2. AUG — DEC 2025 [INFO]

    Cloud security engineering · Trevenx

    Implemented an AWS SIEM pipeline forwarding GuardDuty findings through S3 into OpenSearch for real-time analysis, dashboards, and high-severity alerting.

  3. MAY — AUG 2026 [ALERT]

    Security operations · Marathon Petroleum

    Owned alerts end-to-end in a flat SOC: triage in CrowdStrike Falcon and Microsoft Defender, SOAR playbooks in Google SecOps, threat intel enrichment, and OT monitoring in Dragos.

  4. NOW [ACTIVE]

    Detection engineering practice

    Writing platform-agnostic Sigma rules mapped to MITRE ATT&CK, each documented with detection logic, expected false positives, and tuning notes. Working toward AZ-104.

  5. NEXT [QUEUED]

    Fall 2026 → first full-time role

    Graduating from UTSA in December 2026 (BBA Cybersecurity, 3.72 GPA). Targeting detection engineering and SOC roles where I can keep shipping detections.

rules/

Detection work

An early-stage, growing library of platform-agnostic Sigma rules mapped to MITRE ATT&CK. One rule converts to KQL (Sentinel), SPL (Splunk), or YARA-L (Google SecOps). The point isn't collecting rules — it's demonstrating detection thinking: technique → log source → logic → fidelity and tuning. Every rule that lands here is fully documented before the next one starts.

Detection Tactic Technique Log source
Windows Security event log cleared Defense Impairment T1685.005 Windows Security (1102)
Shadow copy deletion via vssadmin Impact T1490 Windows process creation
Browse the rules & write-ups →

Each rule ships with a write-up covering detection logic, expected false positives, and tuning notes.

cloud/

Cloud projects

Detections are only as good as your understanding of the environment they run in. These builds are the cloud foundation underneath the security work.

AWS

AWS SIEM log analysis pipeline

Cloud-native SIEM built during my Trevenx internship — GuardDuty findings forwarded through S3 and Firehose into OpenSearch for centralized log analysis, real-time dashboards, and high-severity alert triggers. Lives under the Trevenx org.

  • GuardDuty
  • OpenSearch
  • S3
  • Firehose
  • VPC
Azure

Azure administration lab series (AZ-104)

14 documented labs across the full AZ-104 surface — identity, governance, networking, storage, compute, containers, data protection, and monitoring. Each lab is written up as its own report; browse the index below.

  • Entra ID
  • RBAC
  • ARM / Bicep
  • AKS
  • Azure Monitor
experience/

Where I've done the work

Cybersecurity Incident Detection & Response Intern

May 2026 — Aug 2026

Marathon Petroleum

  • Owned security alerts end-to-end in a flat SOC — triage and investigation in CrowdStrike Falcon and Microsoft Defender through remediation and closure.
  • Investigated and contained threats with Falcon Real Time Response; built automated CrowdStrike workflows backed by PowerShell and Python.
  • Executed SOAR playbooks in Google SecOps; enriched investigations with Recorded Future and VirusTotal; analyzed phishing in Proofpoint.
  • Monitored OT security alerts in Dragos, extending coverage across IT and OT; supported IAM in Entra ID and GCP with least privilege.

Cloud Security Intern

Aug 2025 — Dec 2025

Trevenx

  • Selected to the intern team for sustained open-source contributions across EDR, threat modeling, cloud security, and compliance automation.
  • Implemented the GuardDuty → S3 → OpenSearch SIEM pipeline for real-time log analysis and visualization.

EMT-B

Dec 2022 — Sep 2025

Allegiance Mobile Health

  • 100+ emergency responses: rapid triage, cross-team coordination, and calm decision-making under real pressure — the original incident response training.

Detection & response

  • CrowdStrike Falcon
  • Microsoft Defender
  • Google SecOps
  • Sigma
  • MITRE ATT&CK
  • Dragos (OT)
  • Recorded Future
  • Proofpoint

Cloud & identity

  • Azure
  • AWS
  • Entra ID
  • GCP IAM
  • Wiz
  • Docker

Automation & analysis

  • Python
  • PowerShell
  • Bash
  • SQL
  • Git
  • Wireshark

Frameworks & process

  • NIST CSF
  • ISO 27001
  • OWASP
  • ServiceNow
  • Agile
contact/

Get in touch

Open to Fall 2026 internships and entry-level detection engineering or SOC roles. The fastest way to reach me is email or LinkedIn.