About

// PERSONNEL FILE

NICHOLAS A. SOUTHERN

CYBERSECURITY ANALYST  |  SOC / GRC / INCIDENT RESPONSE
CLEARANCE: ACTIVE TS/SCI
ID: NAS-982-202-ALPHA
LOC: GREATER_ORLANDO_FL
STATUS: AVAILABLE_REMOTE
Nicholas Southern
[ IMG_SCAN_COMPLETE ]
ROLE:AI Cybersecurity Specialist
AFFILIATION:Invisible Technologies (Contract)
EXPERIENCE:6+ Years
CLEARANCE:Active TS/SCI
EDUCATION:B.S. Cyber — WGU (Dec 2026)
ORIGIN:USAF — Ramstein AB
TARGETING:SOC / GRC / ISSM / Cyber Analyst (Remote)
NEXT CERT:CISSP (in progress)
— “DISCIPLINED DEFENSE. STRATEGIC SECURITY.” —
“I translate noise into signal. Every alert, every log line, every compliance control — they’re sentences in a language I’ve spent six years learning to read. My job is not just to detect; it’s to translate technical risk into decisions leadership can actually act on.”

// MISSION BRIEF

Operational Cybersecurity Analyst with 6+ years across 24/7 Network Operations Centers, incident response, and classified DoD environments. I’ve spent my career on the watch floor — tuning SIEMs, hunting threats, hardening endpoints, and shepherding RMF packages through accreditation. I’m now focused on remote SOC Analyst, GRC Analyst, and Cybersecurity Analyst roles where deep operational reps and a TS/SCI clearance carry real weight.

// THE FOUNDATION: USAF — RAMSTEIN AB

My discipline wasn’t learned in a classroom; it was forged in the United States Air Force at Ramstein Air Base, Germany. As a NOC Engineer / Systems Administrator, I ran 24/7/365 network defense operations across classified DoD networks, handled Tier 1/Tier 2 triage and incident response, and hardened 241 systems inside a 24-hour sprint to mitigate emergent compliance directives — zero rework on follow-up audit. Rotational shifts, holiday duty, and high-tempo mission support are not a learning curve for me — they are the baseline.

// CURRENT ENGAGEMENT

I’m currently a remote AI Cybersecurity Specialist with Invisible Technologies, red-teaming Large Language Models against prompt injection, adversarial manipulation, and data-leakage vectors. Before that, I was Senior Multi-Functional Security Analyst at Lockheed Martin, engineering Splunk dashboards, enforcing NIST 800-171 across RHEL and Windows estates, and serving as primary incident handler for system deviations.

// OPERATIONAL CAPABILITIES

SOC OPERATIONS
Incident triage, threat hunting, log analysis, root-cause investigation, 24/7 watch-floor ops.
SIEM & EDR
Splunk dashboard engineering, correlation tuning, McAfee HBSS, ACAS, false-positive reduction.
GRC & COMPLIANCE
NIST 800-53, NIST 800-171, RMF packages, STIG hardening, Drata, ATO documentation.
AI SECURITY
LLM red-teaming, prompt-injection defense, adversarial ML, RLHF safety tuning.
SYSTEMS
Red Hat Enterprise Linux, Windows Server, Active Directory, Azure, Bash scripting.
INCIDENT RESPONSE
DoD reporting timelines, IOC validation, forensic endpoint analysis, containment workflows.

// CERTIFICATIONS & CREDENTIALS

GIAC GSEC GIAC GFACT CompTIA Security+ CE CompTIA Network+ N10-009 CompTIA A+ ITIL 4 Foundation DoD 8570 Compliant CISSP (in progress)

// OPERATING DIRECTIVES

  • >> ZERO TRUST PROTOCOL: Trust nothing. Verify everything. This applies to network packets, vendor promises, identity claims, and the LLM telling you it’s safe.
  • >> SIGNAL OVER NOISE: Compliance artifacts and alert volume are not security. Every control I touch must map to a measurable reduction in real adversary capability.
  • >> MOMENTUM IS DEFENSE: A static posture is a degrading posture. If detections, dashboards, and runbooks aren’t getting sharper week over week, the threat is.
  • >> TRANSLATE OR LOSE: Technical risk that leadership can’t act on may as well not exist. My job is to compress complexity into decisions.

// AVAILABILITY

Open to remote SOC Analyst, GRC Analyst, and Cybersecurity Analyst roles. Comfortable with rotational shifts, on-call, and federal/regulated environments. TS/SCI active. Located in Greater Orlando, FL.

Scroll to Top