SOC Analyst  |  Detection Engineering  |  Security Automation
Raylee Hawkins
SOC T1/T2 Detection Engineering Security Automation North Alabama · Huntsville
📍 North Alabama (Huntsville preferred) Raylee@hawkinsops.com 📞 (256) 328-3711 GitHub hawkinsops.com LinkedIn
Available for SOC / Detection roles
324,074
Cases Processed
ledger-verified
8,574
Escalations (Analyst-Ready)
reviewable artifacts
8/8
Host Coverage
0 mismatches
210
Detection Rules (+ 10 IR Playbooks)
103σ · 28W · 79SPL
324,074
Alerts Ingested
AutoSOC
Pipeline
~88%
Auto-Closed
8,574
Escalated
0
Reconcile Errors
Ledger-backed pipeline  ·  reproducible results  ·  no hand-edited metrics
30-Second Talk Track
I build and operate automated SOC pipelines that classify, triage, and validate alerts at scale. SignalFoundry — my AutoSOC engine — processes Wazuh alerts through a deterministic triage loop: ~88% auto-close rate, enforced redaction, reconciliation gates before anything publishes, and 8,574 escalation packs staged as auditable artifacts. Before security I ran production floors — 30+ operators, 12-hour shifts, IATF audit compliance. The domain changed. The control logic didn't. I'm not replacing analysts. I can do triage work and build tooling that makes investigations more consistent.
I am comfortable operating as a Tier 1 SOC analyst while continuing to build automation that reduces analyst workload and improves triage consistency.
01
Skills
Detection
Sigma rule authoring
Wazuh XML rule blocks
Splunk SPL detections
MITRE ATT&CK mapping
Alert triage workflow
🔧Tooling
Python (pipeline scripts)
PowerShell / fish shell
Git + GitHub Actions
Wazuh API
Cloudflare Pages / CI
🗺Frameworks
MITRE ATT&CK
SOC triage methodology
IR fundamentals
Evidence-first workflow
Reconciliation gates
🔬Lab / Infra
Proxmox VE
Windows / Linux telemetry
Wazuh Manager
Splunk Enterprise
Reproducible test runs
02
Security Operations Lab
Detection Engineer · Security Automation
HawkinsOperations — Independent SOC Lab (Live Pipeline)

Summary

Security Skills

Operations Skills

Work History

Detection Engineer / SOC Operations — HawkinsOps (Sep 2025 – Present)

AI Model Evaluator — Outlier / DataAnnotation (Dec 2025 – Present)

Team Lead Supervisor — Unipres Alabama, Inc. (Mar – Dec 2025)

Tier-1 Nissan supplier · Steele, AL · Hot stamp & laser (safety-critical B-pillars, roof rails)

Team Lead — Fehrer Automotive North America (Jan 2024 – Feb 2025)

Tier-1 Mercedes / BMW / VW / Tesla · Gadsden, AL · Foam production

Quality Control — Carrington Foods (Previous)

Tier-1 U.S. Armed Forces supplier · Saraland, AL · SQF Ed. 9 "Excellent" / Platinum Award

Transferable Skills — Manufacturing → Security

Incident triage under pressure

Production floor fault isolation → SOC alert classification and escalation

Shift-handoff discipline

24/7 pass-down communication → SOC ticket continuity and coverage control

Quality-gate enforcement

IATF/ISO/SQF compliance → CI-gated verification, proof-control artifacts

Root-cause isolation

Production troubleshooting → Infrastructure vs. application fault diagnosis

Documentation rigor

SOP authoring, audit-ready records → Evidence-pack assembly, case studies

Team leadership under stress

30+ operators, mandatory 12-hr shifts → Calm execution under incident pressure

What My Reference Says

"Raylee does not just learn tools — she builds around systems. Systems thinking is evident in endpoint telemetry, alert handling, validation steps, and supporting documentation. She takes technical ideas, expands them, and turns them into complete systems."

Josh Carlton, IT Manager, Unipres Alabama (25-year IT veteran). Donated dual Tesla V100 GPUs for portfolio infrastructure. Full reference letter available.

Certifications & Training

Education

Community

Additional

Download PDF   |   Plain-text (ATS)