Juashua Villarejos · Cybersecurity Engineer · DHS USCIS SOC

Defending enterprise environments with SOC, IR, and vulnerability management expertise.

Cybersecurity engineer with hands on experience in SOC operations, incident response, identity access management, and vulnerability management supporting a large federal enterprise environment. Proven track record in triaging complex security events, managing KEVs and ISVMs, and managing user accounts and access requests in accordance with least privilege standards to reduce organizational risk. Passionate about protecting privacy and mission critical assets while continuously improving processes, documentation, and team readiness.

Contact

LocationGreater New Orleans Region
Emailjuashua.com@proton.me
Profiles LinkedIn   Blog   GitHub

Highlights

Core Focus
SOC Operations, Incident Response, Vulnerability Management, Identity & Access Management
Environment
Large federal enterprise support

Experience

Cybersecurity Engineer SOC – SADOM

USCIS SOC · Aretec · Stennis Space Center, MS
March 2025 – Current

Information Security Vulnerability Management

  • Review and process Known Exploitable Vulnerabilities (KEVs) to strengthen the agency’s security posture and prioritize remediation.
  • Analyze DHS and USCIS bulletins and technical advisories, translating them into actionable remediation tasks for stakeholders.
  • Manage change records supporting vulnerability remediation while maintaining policy compliance and operational stability.
  • Build and maintain Splunk searches to track ISVM status and remediation, improving visibility and reporting accuracy for leadership.
  • Own the Cisco data call report with weekly updates on vulnerability status and trends for DHS stakeholders.
  • Participate in weekly coordination meetings to improve open vulnerability awareness and response alignment.

Accounts and Access Management

  • Complete onboarding, offboarding, and team change requests, ensuring secure and timely account transitions.
  • Process and validate access requests while enforcing least privilege and approval workflows.
  • Resolve ServiceNow tickets related to account provisioning and removal, reducing backlog and misprovisioned access.
  • Update GitHub documentation and runbooks, improving accuracy and ramp-up time for new team members.
  • Develop SOPs for core workflows to preserve continuity during absences and role transitions.
  • Troubleshoot access and account issues for end users, improving first contact resolution.

Additional Contributions

  • Support operational response tasks including IP and domain blocks, malicious email trace and purge actions, and USB exception requests.
  • Process quarterly phishing exercise results in Splunk and maintain dashboards used for awareness and training.

SOC CSIRT Analyst

USCIS SOC · CSS Evolver Federal · Stennis Space Center, MS
June 2022 – March 2025
  • Monitor network activity, evaluate and escalate security alerts, and coordinate response, containment, eradication, and recovery.
  • Perform network and host-based analysis using SIEM tools.
  • Review and triage DLP alerts while coordinating user training to prevent repeat incidents.
  • Analyze malware and suspicious files using EDR tools and Out-of-Band devices.
  • Handle spam and phishing reports and raise enterprise-wide awareness.
  • Consume and act upon daily Cyber Threat Intelligence reports.
  • Conduct incident response based on standard operating procedures.
  • Investigate network violations and coordinate remediation and training.
  • Lead log analysis for host and network systems.
  • Train new team members on tool usage and incident response procedures.
  • Collaborate across teams to process and remediate classified spills.