I learn by doing the thing. These platforms and courses give me immersive worlds where I can test a technique, misunderstand it, break it, and put it back together. Each pass deepens my understanding and makes the next explanation stronger.

Hands-on platforms

Offensive security and CTF practice

  • TryHackMe: Web application pentesting, red teaming, AI security, network exploitation, privilege escalation, Active Directory, and seasonal CTF work.
  • Hack The Box: Standalone challenges, competitive events, and multi-category CTF work, including Cyber Apocalypse 2026.
  • CIAT Cybersecurity Club: I serve as vice president. Its CTF Club meets weekly for hands-on practice across SkillBit (MetaCTF), OffSec CTFs, Hack The Box, NACL competitions and gymnasiums, Google CTFs, and US CyberGames.

The work moves between individual challenge solving, team competitions, post-competition gymnasiums, King of the Hill, and internal lab environments.

Defensive security and analysis

  • LetsDefend: SOC-style alert triage, investigation, and incident documentation.
  • Home-lab monitoring and DFIR: Windows EVTX and Sysmon analysis, Hayabusa, Cowrie session logs, Splunk development, and packet analysis with Wireshark.
  • Malware-analysis labs: Static and dynamic analysis, IOC documentation, incident timelines, and MITRE ATT&CK mapping.
  • Detection engineering: AISMON rules and CLI workflows for identifying suspicious patterns in Sysmon events.

Cloud and AI platforms

  • AWS Academy: Cloud Foundations training completed in July 2026.
  • Microsoft Learn: Azure and AI learning paths with hands-on resource deployment.
  • Microsoft Foundry: Resource and project configuration, GPT-4o GlobalStandard deployment, content guardrails, and API authentication.

Active training and certification preparation

  • Red Siege, Penetration Testing: Beyond the Basics: In progress.
  • Red Siege, Understanding Kerberos: In progress.
  • Cisco Ethical Hacker: In progress.
  • CompTIA AI Prompting Essentials: In progress.
  • CompTIA CyberDefense Pro: In progress.
  • Just Hacking Training and WiCyS Cyber Competency Builder: Enrolled in Script-Based Malware Analysis and Web App Pentesting, Jr. Analyst.
  • Antisyphon ACE-T Core Certification: Preparing for the 100-question exam and hands-on cyber range assessment.
  • Microsoft Azure Fundamentals (AZ-900): Exam voucher secured.
  • Microsoft Azure Administrator (AZ-104): Planned.
  • AWS Certified Cloud Practitioner (CLF-C02): Planned following completion of AWS Academy Cloud Foundations.

Certifications and completed programs

Current certifications

  • ISC2 Certified in Cybersecurity: Active through May 2029.
  • CompTIA Security+ ce: Active through October 2028.
  • CompTIA Network+ ce: Active through October 2028.
  • CompTIA A+ ce: Active through January 2029.

Stackable certifications

  • CompTIA IT Operations Specialist (CIOS): Active through October 2028.
  • CompTIA Secure Infrastructure Specialist (CSIS): Active through October 2028.

Selected completed programs

  • AWS Academy Cloud Foundations
  • Just Hacking Training and WiCyS Cyber Competency Builder: AI Cyber Defense Ops
  • EC-Council ADG Verified in Defend
  • Antisyphon Training: Workshop, How to Build Pressure-Proof Pretexts

TryHackMe learning paths

  • Web Application Red Teaming
  • Web Application Pentesting
  • AI Security
  • Jr Penetration Tester (Legacy)
  • Web Fundamentals (Legacy)
  • SOC Level 1
  • Pre Security

Selected Microsoft Learn achievements

Completed modules cover cloud computing, Azure architecture, Microsoft Entra ID, enterprise desktop administration, and introductory machine-learning concepts.

Selected events attended

  • BSides Albuquerque
  • New Mexico Tech Council (NMTC) Summit
  • NMTC Women in Tech Peer Group
  • WiCyS (Women in Cybersecurity) events
  • Splunk webinars & workshops
  • Fortinet events
  • SentinelOne events
  • SANS Neurodiversity in Cybersecurity Summit (CPEs earned)
  • Antisyphon Threat Hunting Summit 2026

How I learn

I love what I do. My idea of fun is deepening both my understanding of and experience in the multifaceted world of cybersecurity. That requires a great deal of self-discipline and time management, both of which I am proud to say I have almost mastered. There will always be another system, technique, or question to explore. I would not have it any other way.