┌──(alejandro㉿sec-ops)-[~]
└─$ whoami --verbose
> Name : Alejandro Zavala Zenteno
> Role : Jr. Cybersecurity Professional & (soon to be) Computational Systems Engineer
> Cert : ISC2 Certified in Cybersecurity (CC) · 2026–2029
> Base : Morelia, Michoacán · Mexico [UTC-6]
> Focus : SOC Operations | Detection Engineering | SIEM/XDR | Observability | IR
> Status : [ Seeking remote security roles · Open to opportunities ]
┌──(alejandro㉿sec-ops)-[~]
└─$ cat featured_projects.md
🟢 docker-monitoring-stack · | ✅ wazuh-soc-homelab · |
┌──(alejandro㉿sec-ops)-[~]
└─$ cat skill_matrix.txt
[ Security Operations ]
SIEM/XDR ██████████░ Wazuh · OpenSearch · Splunk · Elastic Stack · Active response
Detection Eng ████████░░░ XML rules · Behavioral TTPs · Telemetry analysis · Rule tuning
SOC Workflow ███████░░░░ Alert triage · Reporting · Escalation · SOC KPIs · Workbooks & lookups
Threat Hunt ████████░░░ FIM · Auth correlation · Discovery · C2 detection · IDS fundamentals
Incident Resp ████████░░░ TheHive v5 · Triage runbooks · Containment SOPs · EDR basics · Kill chain
Frameworks ████████░░░ MITRE ATT&CK · Cyber Kill Chain · Pyramid of Pain · NIST CSF · ISO 27001
[ Observability / DevOps ]
Metrics ███████░░░░ Prometheus · cAdvisor · PromQL · Custom dashboards
Logging ███████░░░░ Loki · Promtail · LogQL · Centralized pipelines
Visualization ████████░░░ Grafana · OpenSearch Dashboards · KPI engineering
Orchestration ████████░░░ Docker Compose · Multi-container stacks · Service discovery
[ Infrastructure ]
Linux █████████░░ Ubuntu hardening · Debian · Bash scripting · syslog pipelines
Containers ████████░░░ Docker · Docker Compose · WSL2 · IaC credential management
Windows ██████░░░░░ PowerShell · WazuhSvc · AD basics
[ Networking ]
Protocols ███████░░░░ TCP/IP · OSI Model · DNS · SSH · VPN (Sophos)
Hardware ██████░░░░░ Cisco · Ruckus · Switches · Routers
Analysis ██████░░░░░ Wireshark · Nmap · Firewall config · iptables
[ Offensive (lab only) ]
Tools ██████░░░░░ Hydra · Nmap · Nikto · Metasploit · Kali · Reverse shells
┌──(alejandro㉿sec-ops)-[~]
└─$ systemctl status learning.service
● learning.service - Continuous Skill Development
Loaded: loaded (/etc/systemd/system/learning.service; enabled; preset: enabled)
Active: active (running) since Mon 2026-01-01; always
Main PID: 1337 (always_learning)
Status: "Building toward remote SOC Analyst & Detection Engineering roles"
Tasks: 4 (focused)
Memory: 100%
CPU: full-throttle
Active units:
● detection-engineering-lab.target active (expanding custom ruleset)
● docker-observability-phase-4.service active (performance analysis & diagnostics)
● tryhackme-soc-level-1.path active (blue team path in progress)
● english-technical-writing.service active (daily)
Queued for start:
○ comptia-security-plus.target queued
○ blueteam-labs-ctfs.service queued
○ kql-sentinel-fundamentals.service queued
┌──(recruiter㉿interested)-[~]
└─$ cat hire_alejandro.txt
[ Open to ]
• Jr. SOC Analyst (Tier 1 / Tier 2)
• Detection Engineer (Junior)
• Blue Team / Threat Hunter (Junior)
• Security Operations · Observability-adjacent roles
[ Availability ]
• Full-time · Remote-first (worldwide)
• Timezone : America/Mexico_City (UTC-6) — flexible overlap with LATAM / US / EU-early
• Languages : Spanish (native) · English (technical proficient)
• Start date : Immediate · Notice period: none
[ Fastest way to reach me ]
→ LinkedIn DM (usually reply within 24h)
→ See contact badges below
┌──(alejandro㉿sec-ops)-[~]
└─$ cat /etc/motd
"The goal is not to be better than everyone else,
but to be better than you were yesterday."
Building in public · Documenting every step · Failing forward.