×
About Skills Certifications Projects Competitions Education Experience
Hi. My name is Sarah Lishin

And I'm

.profile { •------» ABOUT «------•.profile {


WHO:

Hello! I'm Sarah. I'm many things: A Mom. An InfoSec Analyst. A Learner of Things.

WHAT:

A Passion for Cyber Security and making the world a better place for everyone.
I'm quite excited to keep learning these new things and continue my journey.

WHEN:

Now! Everyday the Cyber Security landscape gets a little worse, and we need to work a little harder.

WHERE:

NYC - But The #SecurityMindset is Everywhere

WHY:

Seeing the world change so rapidly, and watching new technology and the
fumbles in the cyber security world and thought to myself,
'What could I do to make this better?'.

I want a world that is safer for my daughter, my family, and for everyone.

Let's work together to make that happen.

.ability { •------» SKILLS «------•.ability {


.certs { •------» CERTIFICATIONS «------•.certs {


    CISSP Issued September 2023 GIAC Certified Incident Handler Issued December 2021 CompTIA CySa+ Issued July 2020 CompTIA Security+ Issued August 2020
    Splunk Core Certified Power User Issued June 2022 Splunk Core Certified User Issued September 2020 Microsoft Azure Fundamentals Issued October 2020 AWS Cloud Practitioner Issued December 2020

.fun { •------» PROJECTS «------•.fun {


.irl { •------» COMPETITIONS «------•.irl {


.learn { •------» EDUCATION «------•.learn {

Fullstack Academy Cyber Security Immersive
  • Computing and Networking
  • Virtualization
  • Linux
  • Python
  • Bash Scripting
  • Data Encoding
  • Information Gathering
  • Malware Analysis
  • Digital Forensics
  • Attack Frameworks
  • Web Frameworks
  • Firewall Bypass
  • Buffer Overflow
  • Scanning and Enumeration
  • Network Capture
  • Patching
  • Application Restrictions
  • Event and Incident Reporting
  • Whitelisting and Log Audition
  • Kill Chain Mapping
  • Network Configurations
  • Threat Identification
  • Threat Mitigation
  • Access Control and Policies
  • Compliance Policies
  • Incident Response
  • Vulnerabilities Management
  • Threat Management

.work { •------» EXPERIENCE «------•.work {


Quanata, Security Operations Analyst


  • Monitor and triage alerts using SIEM, endpoint, and cloud security platforms
  • Investigate anomalous activity and escalate incidents according to defined runbooks
  • Track investigations and incident status using Jira or other case management tools
  • Collaborate with IT and engineering teams to validate and remediate alerts
  • Support incident response, including containment and root cause analysis
  • Identify trends in alert fatigue and contribute to tuning and detection improvements/li>
  • Maintain and improve SOC playbooks, runbooks, and detection documentation
  • Participate in security incident postmortems and response exercises
  • Support the evaluation of commercial products via triage, technical reviews, and monitoring
  • Contribute to threat-informed detection development and SLA tracking for triage and response

Fluxx, Information Security Analyst


  • Monitor and respond to security events and incidents, leading various steps and remediations
  • Optimize and automate security tools to improve threat detection and incident response
  • Maintain security documentation, findings, metrics, and recommendations
  • Assess, prioritize, and coordinate vulnerability remediation while improving management
  • Conduct access reviews, investigate violations, and enforce least-privilege access
  • Provide security guidance, training, and recommendations to users and stakeholders
  • Collaborate across teams and research emerging threats to strengthen security operations

Match Group, Enterprise Security Analyst III


  • Implementation, Monitoring, and Analysis of Enterprise Security Systems and Logs
  • Review and Monitor SIEM and EDR, concurrent with Research and Testing of Security Processes
  • Document Processes, Procedures, and Collaboration on Comprehensive Reports and Outcomes
  • Lead Communications with Technical and Management Teams During Security Incidents
  • Develop Technical Solutions and New Security Tools, leading PoC’s
  • Monitor Bug Bounty Program, Threat Hunting Metrics, and User Behaviour Analytics
  • Mentor and Lead Security Analyst team for Specific Brands within Portfoli

Hinge, Enterprise Security Analyst


  • Analyze and Review Output for Infrastructure Security Systems
  • Review and Monitor SIEM and EDR, such as Splunk and Falcon
  • Document Processes, Procedures and Events
  • Collaborate Writing Comprehensive Reports, Outcomes, and Propositions
  • Assist with Configuration and Troubleshooting Security Controls
  • Communicate and Respond with Technical and Management Teams During Security Incidents
  • Support Triage for Bug Bounty Program
  • Research and Testing of Additional Security Processes and Products
  • Review New Threats and Exploits in the Security Community and Update Procedures Accordingly

TAD Associates, Senior Operations Coordinator


  • Managed Internal IT Projects, Work Scopes, and Daily Tasks
  • Collaborated with External IT Vendors for Management of IT Systems
  • Assisted in designing IT Best Practices and Procedures
  • Developed Proposal Pricing Matrices with VBA in Microsoft Excel
  • Maintained AP Database of 15+ data structures and Differing Vendor Requirements
  • Coordinated AR with Project Principals, Company Leadership, and Clients
  • Organized Workplace Events, Employee Retention and Training, and OnBoarding
  • Led Effort on Implementation of a Employee Mentorship Program
  • Oversaw Employee Certification Management and TradeShow Events
  • Managed HR, Payroll, Benefit and 401k Administration
-->