Esteban Castillo
@estebancastillo1
Cyber Threat Detection & Response analyst bridging IT and OT security to keep enterprises resilient against evolving threats.
What I'm looking for
I’m an IT and OT professional focused on leveraging technology to drive innovation and operational excellence. I dedicate myself to delivering secure, resilient, and efficient solutions by bridging traditional IT infrastructure with critical OT environments.
At IBM, I serve as a Tier 2 Analyst for the Honda Motor Co., Ltd. account, monitoring critical industrial environments and helping secure ICS and SCADA systems. I work with industrial protocols such as Modbus, BACnet, EtherNet/IP, and OPC UA to identify network security risks, firewall configuration gaps, and intrusion detection opportunities within OT.
My background centers on SOC workflows—detection, investigation, and incident response—supported by SIEM and OT visibility tools. I use IBM QRadar, Claroty, Nozomi Networks, and Palo Alto Cortex XSIAM, applying threat actor tactics, techniques, and procedures with frameworks like MITRE ATT&CK, and performing deep packet inspection with Wireshark/PCAP analysis to analyze logs and system behavior.
I previously worked as an IBM SIEM Cybersecurity Analyst (Senior) for Bank of America and Bancolombia, where I analyzed events and alerts, correlated activity, tuned detections, and provided client recommendations to enhance security posture. I also bring an execution mindset from earlier L1 support, consulting, and QA work—always combining accurate troubleshooting with continuous learning.
Experience
Work history, roles, and key accomplishments
Serve as a Tier 2 analyst for the Honda Motor Co., Ltd. account, monitoring ICS/OT environments and securing industrial networks. Use OT protocols and SIEM/OT visibility tooling to identify risks, investigate intrusions, and analyze network traffic for threats.
Supported OT/ICS threat detection and incident workflows by triaging and analyzing events across enterprise environments. Operated security platforms and provided guidance to improve confidentiality, integrity, and availability of OT/ICS assets.
Analyzed alerts, network flows, and events for Bank of America and Bancolombia accounts, correlating activity and tuning detections. Produced incident escalations and security recommendations, and delivered client presentations based on traffic trends and anomalies.
Software Engineer (Support)
Tek Experts
Jul 2013 - Mar 2017 (3 years 8 months)
Provided L1 support for enterprise SiteScope (data collection platform) via phone, email, and WebEx, troubleshooting Windows/Linux servers and related infrastructure. Reproduced issues in-house and resolved customer problems within product and third-party scope.
Technical Consultant (L1)
Malek
Jul 2012 - Apr 2013 (9 months)
Delivered application support and ticket management for Malek Consultant and external clients, including access provisioning and user management. Supported Google Workspace and Microsoft Office 365, performing migrations from Microsoft Exchange to Google Workspace.
IT Consultant (Fortinet)
Business Solution Consulting BSC
Feb 2012 - Jul 2012 (5 months)
Served as an IT consultant on Fortinet pre-sales and implementation activities for internal and external customers. Installed and configured Fortinet security solutions and managed UTM profiles, firewall policies, web/email filtering, and anti-spam controls.
Tested internal dental software to validate functionality and quality across releases. Documented enhancement findings and communicated issue details and improvements to developers.
Education
Degrees, certifications, and relevant coursework
Universidad Metropolitana Castro Carazo
Cybersecurity Specialist, Cybersecurity and Networking
2024 - 2025
Completed a Cybersecurity Specialist program with a focus on networking at Universidad Metropolitana Castro Carazo from 2024 to 2025.
Universidad Fidélitas
Bachelor’s Degree, Systems Engineering
2016 - 2019
Earned a Systems Engineering bachelor's degree at Universidad Fidélitas from 2016 to 2019.
Greencore Technical
Linux Admin Server Basic, Linux Administration
Completed a basic Linux server administration course at Greencore Technical in 2014.
Universidad Cenfotec
Technical career, Technology Information and Communication
2012 - 2013
Completed a technical career in Technology Information and Communication at Universidad Cenfotec from 2012 to 2013.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Esteban?
You can contact Esteban and 90k+ other talented remote workers on Himalayas.
Message EstebanFind your dream job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
