Christian Carrasco
IT Operations & Security Leader
christiancarrasco.dev · linkedin.com/in/cybercc · github.com/labwithchristian
IT operations and security leader with ten plus years in enterprise environments. Five years as incident manager and operations lead on assignment at Toyota Motor North America, a year as a SOC analyst and lead SIEM administrator, and five years administering systems and identity in a HIPAA-regulated healthcare environment. Supported audit and control testing across SOX, PCI DSS, HIPAA, CMS, and ISO 27001.
- Experience
- Ten plus years in enterprise IT
- Focus
- IT operations and security
- Languages
- English and Spanish, fluent
- Studying
- CISSP, target November 2026
Experience#
Beyondsoft Consulting
2021 to 2026- Operations Manager2022 to 2026
- Senior Lead Systems Analyst2021 to 2022
- Incident manager for high-impact production events on a global client account: set severity, coordinated the response, decided when to escalate, and briefed client executives.
- Led a five-person engineering team with a shared backlog and on-call rotation; owned hiring, one-on-ones, SLA performance, and vendor contracts.
- Ran incident and problem management and coordinated change and maintenance windows.
- Led post-incident reviews that turned recurring failures into preventive controls.
- Audited client AWS accounts for exploitable firewall and DNS misconfigurations, and remediated DDoS vectors through AWS Shield, WAF, and CDN.
- Administered Entra ID conditional access and MFA, and owned the SSL certificate lifecycle.
- Supported the annual SOC review against ISO 27001.
TelevisaUnivision
2019 to 2020- Information Security Analyst
- Triaged SIEM alerts across networks, endpoints, and servers, correlating events to reconstruct incident timelines.
- Investigated spear-phishing campaigns aimed at senior staff and delivered end user security awareness training.
- Lead LogRhythm administrator: built correlation rules, wrote custom parsers for malformed log sources, and mapped detection coverage to MITRE ATT&CK.
- Planned and executed the SIEM migration onto a restructured server architecture, then validated coverage so monitoring did not silently degrade.
- Supported SOX and PCI DSS audit and control testing.
Cigna HealthCare
2014 to 2019- System Administrator
- Level 3 escalation point for a support team of four serving roughly 350 employees in a HIPAA-regulated environment.
- Administered Active Directory and Azure AD, Exchange permissions, Group Policy, and MFA, applying least privilege at provisioning and treating revocation at termination as a controlled step.
- Built the standard PXE images and SOPs behind onboarding and offboarding, and deployed security agents through SCCM.
- Supplied access records and audit evidence through HIPAA and CMS audit cycles.
Commonwealth-Altadis
2013 to 2014- IT Support Specialist
- Imaged and deployed more than 300 machines supporting a sales force of over 1,500 agents.
- Provisioned Active Directory accounts and OU changes, and kept ServiceNow asset and user records accurate.
Certifications#
Security
- Certified Ethical Hacker (CEH)
- CompTIA Security+
Cloud
- AWS Certified Cloud Practitioner
Network
- Cisco CCNA Routing & Switching
Process
- ITIL v4 Foundation
- CompTIA Project+
In progress
- CISSP (target November 2026)
Compliance and Frameworks#
Regulatory
- SOX
- PCI DSS
- HIPAA
- CMS
- ISO 27001
Frameworks
- NIST 800-53
- NIST CSF
- MITRE ATT&CK
- ITIL v4
Practice
- Control design and operating effectiveness testing
- User access reviews
- Formal risk acceptance
- Findings tracked to closure in ServiceNow
- Audit evidence
Tools and Platforms#
Cloud
- AWS
- AWS Shield and WAF
- Microsoft Azure
Microsoft
- Entra ID
- Active Directory
- Microsoft 365
- Exchange
- Group Policy
Security
- LogRhythm
- Rapid7
- Wireshark
Operations
- ServiceNow
- Dynatrace
- PagerDuty
- Jenkins
Infrastructure
- SCCM
- PXE imaging
- VMware
- Cisco
- Linux
Education and Competitions#
Western Governors University
2017 to 2021- B.S. Network Operations and Security
- Competency-based degree covering network design, network operations, and network and cloud security, with industry certifications built into the program. Completed while working full time.
National Cyber League
2019 to 2020- Individual Game, Cyber Skyline
- Proctored, hands-on skills assessment scored on accuracy and completion across ten challenge modules.
- Fall 2019: 1,470 of 3,000 points at 72.9% accuracy. Strongest in OSINT, cryptography, wireless access exploitation, network traffic analysis, password cracking, and log analysis.