Skip to main content
Lisa Marie MorenoLM
Looking for a job

Lisa Marie Moreno

@lisamariemoreno

SOC Analyst (Blue Team) | Microsoft Sentinel · Defender XDR · KQL | Bilingual ES/EN

Spain
Message

What I'm looking for

Looking for a remote junior SOC Analyst (L1/L2), Security Operations or MDR Analyst role, ideally in a Microsoft Sentinel / Defender environment. CET timezone, bilingual Spanish/English.
Junior SOC analyst working in a multi-client MSSP environment with Microsoft Sentinel, Defender XDR, Entra ID and ServiceNow. I triage and investigate alerts (phishing, malware, suspicious activity), enrich IOCs with VirusTotal, AbuseIPDB and ANY.RUN, tune detection rules to cut false-positive volume, and write operational documentation the team actually uses. Previously SOC Analyst at F2TC Cyber Security (24/7 SOC, Wazuh) and cybersecurity intern at the OAS/CICTE. I also run a detection lab (Wazuh, Sentinel, Shuffle SOAR, Trend Vision One) and I'm preparing the SC-200. Based in Spain (CET), native Spanish, C1 English.

Experience

Work history, roles, and key accomplishments

INNOVATE | AXAITRA GROUP MEMBER logoIM
Current

Security Operations Center Analyst L1

Jun 2026 - Present (4 months)

MSSP environment supporting multiple enterprise clients across Microsoft security stack.

- Actively reduced alert fatigue by identifying and escalating high-frequency false positive patterns, contributing to measurable noise reduction across monitored environments
- End-to-end alert triage and investigation covering malware, phishing, and suspicious activity using Microsoft Defender XDR, Sentine

Proyectos Personales / Lab Independiente logoPI

SOC Home Lab — Independent Security Researcher

Apr 2024 - Jun 2026 (2 years 2 months)

Designed and operates a full SOC lab: Wazuh SIEM (v4.14), Trend Micro Vision One XDR, Shuffle SOAR, Microsoft Defender 365, and Microsoft Sentinel — simulating a real production security operations environment.
Ran ransomware simulation (Infection Monkey) end-to-end: Wazuh detected C2 activity (T1105) and triggered real-time Slack alerts; XDR actively contained encryption that SIEM-only monitoring

Universidad Europea del Atlántico logoUA

Security Analytics (Analista de datos)

Jan 2022 - Sep 2022 (8 months)

Creating dashboards and automated reports with Google Data Studio and extracting data from SQL databases — skills applied directly to the design of SIEM dashboards and the analysis of security logs.

FS

Security Operations Center Analyst

F2TC Cyber Security

Mar 2021 - Dec 2021 (9 months)

24/7 SOC: real-time alert monitoring with Wazuh SIEM; triage and investigation of low- and medium-severity incidents following escalation procedures. Analyzed network, firewall, endpoint and server logs to detect anomalies; reviewed malicious samples and enriched IOCs with VirusTotal. Escalated critical threats and maintained incident documentation, runbooks and risk matrices.

F2TC Cyber Security logoFS

Security Operations Center Analyst

Mar 2021 - Dec 2021 (9 months)

- Real-time monitoring of security alerts using Wazuh SIEM in a 24/7 SOC environment; investigation and triage of low- and medium-severity incidents following standardized escalation procedures.
- Analysis of network, firewall, endpoint, and server logs to detect anomalous behavior; review of the source code of malicious samples using VS Code and enrichment of IOCs

OO

Cybersecurity Program Intern (CICTE)

Organization of American States (OAS)

Nov 2020 - Apr 2021 (5 months)

Supported the implementation of cybersecurity programs across the Ibero-American region. Researched cyber threat trends in Latin America and the Caribbean, supported risk analysis and built risk matrices for regional projects, wrote technical and executive reports, and attended virtual meetings with experts and national authorities.

Organización de los Estados Americanos (OEA) logoOO

Cybersecurity Program Intern (CICTE)

Nov 2020 - Apr 2021 (5 months)

- Implementation of cybersecurity programs throughout the Ibero-American region
- Research on cybersecurity trends and threats in Latin America and the Caribbean
- Support in risk analysis and the creation of risk matrices for regional projects
- Drafting of technical or executive reports on cybersecurity issues
- Participation in virtual meetings with experts and authorities

Advensus logoAD

Customer Service Agent

Jul 2019 - Jul 2020 (1 year)

- I handled customer inquiries in English and Spanish, efficiently resolving issues via phone, chat, and email.
- I maintained a high customer satisfaction rate (>90%) through empathetic service and effective problem-solving.
- I used CRM tools such as Zendesk.
- I consistently met KPIs such as response time and first-contact resolution.

Education

Degrees, certifications, and relevant coursework

TA

The Bridge | Digital Talent Accelerator

Cybersecurity Bootcamp, Cybersecurity / Information Security

2025 - 2026

Grade: 4

Activities and societies: Key training areas: - Offensive Security: Penetration testing, vulnerability analysis, and exploitation. - Defensive Security: Monitoring (SIEM), log analysis, and hardening.

An intensive program offering more than 300 hours of hands-on training based on the “learning by doing” methodology. Specialized training focused on incident response and the protection of critical infrastructure.

GO

Google

Google Cybersecurity

Jun 2026

FO

Fortinet

Fortinet Certified Fundamentals Cybersecurity

Apr 2026 · Expires Apr 2028

ES

EF SET

EF SET English Certificate 67/100 (C1 Advanced)

Apr 2026

CI

Cisco

Junior Cybersecurity Analyst Career Path

Mar 2026

LE

La Mina Startup — INCIBE Emprende

Cybersecurity Bootcamp, Cybersecurity / Information Security

2026 - 2026

Grade: 4

Activities and societies: An incubation program specializing in cybersecurity, launched by INCIBE (Spain’s National Cybersecurity Institute) and run at La Mina Startup in Linares. Training provided by active industry professionals: — SOC managers with experience in real-world operations — Founders and CTOs of cybersecurity companies — Specialists in cloud infrastructure and enterprise security

- Red team
- Blue team

GE

4Geeks Academy España

Web Developer Full Stack, Information Technology

2024 - 2025

CE

CertiProf

SCRUM FOUNDATION PROFESSIONAL CERTIFICATE (SFPC)

Jun 2020

CY

CyberArk

CyberArk Certified Trustee

Jan 2020

RT

Rochester Institute of Technology

Computer Forensics

2020 - 2020

HU

Huawei

HCIA CLOUD COMPUTING

Aug 2020 · Expired Aug 2023

DI

Digium

Digium Certified Asterisk Administrator - dCAA

Feb 2020 · Expired Feb 2022

OR

Oracle

Oracle Cloud Infrastructure Foundations 2020 Certified Associate

May 2020 · Expired Nov 2021

II

Instituto Tecnológico de Las Américas (ITLA)

Higher Technical Degree (Tecnólogo), Information Security

2017 - 2020

Grade: 3.6

Activities and societies: - CTF - Hackathons

Three-year higher technical program (122 credits) in information security. Coursework covered ethical hacking, network, operating system and application security, routing and switching, digital forensics, cryptography, IT security auditing and security policy development, plus a final capstone project and 400 hours of professional internship. Degree issued in Spanish as "Tecnólogo en Seguridad Informática".

OO

Organización de los Estados Americanos (OEA)

Cyberwomen Challenge

Aug 2019

EI

Escuela de Organización Industrial

Actívate en Ciberseguridad

Oct 2019

Interested in hiring Lisa Marie?

You can contact Lisa Marie and 90k+ other talented remote workers on Himalayas.

Message Lisa Marie

People also viewed

View all talent

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan