Portrait of Brandon Roos McClinton
Open to SOC Analyst · Cloud Security · DevSecOps roles

Brandon
Roos
McClinton

Security practitioner with 7+ years across IT operations and security. Founder of Cyber Obsidian, a managed security and IT practice helping small businesses improve endpoint protection, monitoring, and incident readiness — Google Workspace security monitoring, SentinelOne EDR, incident investigation and reporting. U.S. Citizen · Clearance-Eligible.

New York metro · Remote · Open to relocation (Northern Virginia / DC)

7+
Years IT / Security
15K+
Messages Screened / Mo
4,956
Tickets Resolved / Yr
Top 7%
HTB CTF 2026 Finish
brandon@blueteam: ~

01 · Career

Experience

Seven-plus years across IT operations and security — currently running a managed security practice end to end.

Founder & Security Engineer

Jan 2025 – Present
Cyber Obsidian · Managed Security Services Provider (MSSP) · Remote

Managed security for small-business clients — Google Workspace security monitoring, SentinelOne EDR, phishing and spoofing detection, endpoint threat containment, and incident response.

Google Workspace SentinelOne EDR Email Security Incident Response MFA / 2SV

IT Support & Academic Technology Specialist

Apr 2020 – Present
Liberty University · Remote

Tier 3 escalation point after Help Desk Tier 1/2 intake — 4,956 tickets per year at a 99% resolution rate, resolved within a 24-hour SLA in ServiceNow. Carries post-resolution CSAT accountability across the full ticket lifecycle, alongside Canvas LMS administration, LTI integrations, and third-party vendor evaluation.

ServiceNow Tier 3 Escalation SLA / CSAT Canvas LMS LTI Integrations Vendor Assessment

IT Support Specialist

Sep 2018 – Oct 2020
Thomas Road · Lynchburg, VA

Cross-platform IT support — hardened Windows, macOS, and Linux endpoints with security baselines and least-privilege controls, resolved server and network issues, and led database migrations.

Windows macOS Linux System Hardening Least Privilege

Full work history on LinkedIn →


02 · Work

Featured Projects

Hands-on security engineering — detections built, attacked, and validated in a purpose-built lab, plus tooling for real incident-response workflows.

Architecture

cyberobsidian.com — Architecture & Security

Production Next.js 16 / TypeScript site for my MSSP, hardened end to end: CSP and full security-header set, server-side Turnstile bot verification, input validation with header-injection defense, rate limiting, and RFC 9116 security.txt. Architecture public, source private.

View Repo →
DevSecOps

CI/CD Security Gate Pipeline

GitHub Actions pipeline enforcing four merge-blocking security gates — SAST (Semgrep), dependency scanning (pip-audit), secret scanning (Gitleaks), and container image scanning (Trivy) — around a Python hash-identification CLI. Found and triaged 23 HIGH/CRITICAL findings (12 unique CVEs) in the base container image, confirmed via Trivy's Fixed Version output that no patches existed, and documented the accepted risk in a dated .trivyignore rather than silencing the gate. Enforcement is real: GitHub branch protection requires all four checks to pass, verified with a live test pull request.

View Repo →
Analysis

Phishing Campaign Analysis

Phishing email analysis and campaign-results interpretation — identifying at-risk teams and building a targeted security-awareness training plan.

View Repo →
Research

Keystroke Logging & Detection Study

Security research analyzing input-capture techniques (MITRE ATT&CK T1056.001) with a focus on detection via Sysmon and SIEM telemetry.

View Repo →

03 · Tooling

Skills & Tools

The stack I work with daily — across detection, identity, network defense, scripting, and cloud.

SIEM & Detection
Splunk Wazuh Elastic ELK Microsoft Sentinel Sigma MITRE ATT&CK Atomic Red Team
CI/CD & DevSecOps
GitHub Actions Semgrep (SAST) pip-audit (SCA) Gitleaks Trivy Docker Branch Protection
Network Security
Wireshark Nmap pfSense Suricata Twingate (Zero Trust)
Identity & Cloud Security
Microsoft Entra ID Microsoft 365 Google Workspace
Endpoint & Vulnerability
SentinelOne CrowdStrike Sysmon Nessus OpenVAS
AI & Automation
Ollama Apify n8n
Programming & Scripting
Python PowerShell Bash Java C++ SQL
Web Development
Next.js React JavaScript TypeScript Cloudflare Git
Infrastructure & Cloud
Proxmox VE Docker Portainer AWS Microsoft Azure Google Cloud Windows Server Linux Kali Linux

04 · Credentials

Certifications & Training

CompTIA Security+ SY0-701
Currently in progress — core exam for SOC and security analyst roles
In Progress
Oracle Cloud Infrastructure 2025 Certified AI Foundations Associate
OCI core services · AI/ML fundamentals · Generative AI on cloud infrastructure
Verified
Google Cybersecurity Certificate
Incident response · SIEM tools · Network security fundamentals
Verified
Google Data Analytics Certificate
Data analysis · SQL · Visualization and reporting
Verified
Hack The Box
Active — working through Starting Point; building skills in enumeration, exploitation fundamentals, and security analysis.
HTB Cyber Apocalypse CTF 2026
Competed as Cyber Obsidian; solved 73/136 challenges, finishing 462nd of 6,744 teams (top ~7%).
NIST CSF
Self-study of the NIST Cybersecurity Framework — risk management, security controls, and compliance-aligned security posture.
Home Lab
Continuous hands-on practice in threat detection, network segmentation, and incident response in a personal virtualized environment.

05 · Education

Education

M.S., Information Technology — Software Design & Management
Liberty University
Featured coursework: Secure Software Engineering (CSIS 611), Software Development Management (CSIS 641), Software Design (CSIS 643)
Expected 2026
B.S., Information Technology — Data Networking and Security
Liberty University · NSA/DHS CAE in Cyber Defense–designated program
2023

Let's connect.

I'm actively pursuing SOC Analyst, Cloud Security, and DevSecOps roles. If you're a recruiter or hiring manager, reach out on LinkedIn — I respond quickly to connection requests with a note.

New York metro · Remote · Open to relocation (Northern Virginia / DC)