Sunny Nguyen
Open to Opportunities

Sunny Nguyen

Security Analyst

Specializing in Incident Response & Digital Forensics

English · Vietnamese

SOC Analysis·IR / DFIR·Threat Detection·AI Security·Security Engineering·Vulnerability Assessment·SIEM·Python·Cloud (AWS)

About Me

Target Role

SOC / IR / DFIR

Education

MS Cybersecurity

MS GPA

4.0

Clearance

Eligible (US)

Currently
MS Cybersecurity Management @ University of UtahIT Security Consultant @ Sunny IT SolutionsOpen to Security Engineer & SOC / IR roles

I'm a security professional pursuing a Master of Science in Cybersecurity Management at the University of Utah, with a background in Information Systems and hands-on experience in Incident Response and Digital Forensics.

My work centers on detecting, analyzing, and responding to security threats — from investigating endpoint anomalies and dissecting malware behavior, to applying frameworks like NIST and MITRE ATT&CK in real-world environments. I've operated in HIPAA-compliant healthcare settings where data protection, regulatory compliance, and accurate escalation are non-negotiable.

Beyond the day-to-day, I stay sharp through CTF competitions, HackTheBox and TryHackMe labs, and personal security projects. I'm bilingual in English and Vietnamese, and I bring a collaborative, detail-oriented mindset to every team I work with.

I'm actively seeking roles in SOC analysis, incident response, and DFIR where I can contribute immediately and continue growing as a defender.

Technical Skills

Incident ResponseDigital ForensicsThreat DetectionVulnerability AssessmentSecurity MonitoringLog AnalysisSIEM (Splunk / Sentinel)RBAC & Auth SystemsNetwork SecurityWiresharkNmapBurp SuiteKali LinuxActive DirectoryPythonTypeScript / Next.jsClaude APIOllamaAWSn8nLinuxGit / GitHub

Work Experience

IT Security Consultant & Software Developer

Sunny IT Solutions

Sep. 2025 – Present
  • Conducted network assessments and vulnerability scans for small business clients — identified misconfigurations, unpatched systems, and authentication weaknesses; delivered remediation reports and implemented fixes.
  • Designed and deployed secure internal web applications with RBAC, SMS 2FA with device trust, bcrypt hashing, OTP rate limiting, account lockout, and tamper-evident audit logging.
  • Built custom internal tooling replacing manual workflows (inventory tracking, sales analytics, order management) — deployed as live operational systems for active clients.

Digital Forensics / Incident Response Mentee

Ensign Services, Inc.

Mar. 2025 – Aug. 2025
  • Shadowed experienced responders to develop hands-on understanding of digital forensics, malware analysis, and real-time incident escalation protocols.
  • Completed training in cybersecurity fundamentals, including threat intelligence and response frameworks such as NIST and MITRE ATT&CK.

Help Desk Analyst

Ensign Services, Inc.

Jan. 2025 – Aug. 2025
  • Investigated and resolved escalated network and endpoint issues, collaborating with cross-functional teams to minimize downtime and maintain secure system performance.
  • Operated in a highly regulated HIPAA-compliant environment, supporting enforcement of data protection policies and contributing to risk mitigation efforts.

Software Engineer Intern

Tongues: Language Games

Nov. 2023 – Apr. 2024
  • Developed and maintained backend systems using Python, ensuring efficient and scalable code.
  • Implemented AI prompting techniques to enhance user interactions; conducted code reviews and debugging to maintain high-quality software standards.

Education

Jan. 2026 – Mar. 2027

Master of Science in Cybersecurity Management

University of Utah

GPA: 4.0

Relevant Courses

Networking & Servers · Cybersecurity Management · Web-Based Applications · Cloud Computing · Secure Network Operations · Vulnerability Management · Cybersecurity Risk and Compliance · Project Management

2020 – 2025

Bachelor of Science in Information Systems

Minor in Management

University of Utah

Relevant Courses

Data Structures & Java · Programming with Python · Business Data Mining · A.I. for Business Processes · Database Fundamentals · Strategic Management · International Management · Managing and Leading

Summer 2023

Eccles Global Study Abroad

Japan & Korea

University of Utah

Relevant Courses

Systems Analysis & Design · Strategy and A.I.

Projects

AI SOC Agent

Security

Built an AI agent that triages security alerts, queries logs, enriches with threat intelligence, and posts analyst-ready summaries to Slack and Jira. Uses MCP, Notion runbooks, and persistent agent memory. Implements the read-only investigation, staged response pattern for safe automation.

PythonClaude APIn8nMCPWazuh / OpenSearch

Secure Internal Operations Platform

Security

Production-grade internal business platform built for a confidential client. Features 3-tier RBAC, SMS 2FA with device trust, bcrypt hashing, OTP rate limiting, account lockout, tamper-evident audit logging, and Stripe webhook signature verification. Includes a full analytics suite and staff management.

Next.js 15TypeScriptSupabaseStripeTwilio Verify

AI Healthcare Request System

Software Dev

Hackathon project built around a real Intermountain Health workflow. Replaced a manual Microsoft Form → email → spreadsheet process with an AI-powered intake and classification system. Features a public requestor form and admin dashboard with automated AI triage.

ReactTailwind CSSClaude API

ElderShield

Security

Accessibility-focused web app that prompts A.I. to help seniors spot phishing, scams, and fraud in messages and calls — with simple explanations and actionable tips.

PythonOllamaFlaskReact

Enterprise Security Homelab

Security

Simulated real-world attacks and defenses across virtual machines. Gained hands-on experience in incident detection, response, log analysis, and system hardening.

SplunkKali LinuxWindows ServerWiresharkActive Directory

Cyberpunk Portfolio

Software Dev

A mobile-friendly retro-cyberpunk themed personal portfolio website built with React and Vite, featuring animated UI effects and a hacker-style loading sequence.

ReactViteStyled ComponentsFramer Motion

Freaky Foodies

Software Dev

A full-stack food review web application. Users can browse, submit, and manage restaurant and dish reviews through a clean, interactive interface.

ReactNode.jsSQLExpress

Girlfriend Texter

Software Dev

A scripted automation tool for generating and sending contextual replies. Built for fun — demonstrates practical use of Python scripting and text processing.

Python

Game Day Analytics

Data Analytics

Analyzed the effectiveness of Super Bowl advertisements using data mining techniques. Explored engagement metrics, brand sentiment, and viewership trends.

PythonPandasMatplotlibJupyter

Certifications

Defensive Security

SOC & analyst-track certifications

Cloud

Cloud platform certifications

  • AWS Certified Solutions Architect – Associate (SAA)In Progress

CTFs & Labs

TryHackMe

Active participant in TryHackMe challenges and learning paths focused on defensive security, SOC analysis, and incident response skills.

HackTheBox

Regular participant in HackTheBox labs and learning paths covering a wide range of cybersecurity topics, from web exploitation to Active Directory attacks.

Love At First Breach CTF 2026

Red team focused capture-the-flag competition. Applied offensive techniques including enumeration, exploitation, and privilege escalation across a range of challenges.

LA CTF 2026

Annual cybersecurity competition hosted by ACM Cyber at UCLA. Competed across web, forensics, and cryptography challenge categories.

DoD Cyber Sentinel Skills Challenge 2025

DoD-sponsored competition assessing skills across Forensics, Malware/Reverse Engineering, Networking & Reconnaissance, OSINT, and Web Security.

Industrial Intrusion CTF 2025

Simulated an ICS/OT industrial control systems intrusion. Solved 30+ tasks spanning OSINT, web exploitation, reverse engineering, Node-RED, and Modbus protocol challenges to bypass authentication and gain control of a security gate.

Let's Connect

Open to security analyst, SOC, and IR/DFIR opportunities. Feel free to reach out — I'd love to connect.

© 2026 Sunny Nguyen · sunnyitsolutions.com · Built with Next.js