Jake Wilson
BACKGROUND & JOURNEY

Get to Know Me

My professional career began at DXC, where I spent close to a decade as a Service Delivery Coordinator. My time here built a strong foundation in customer service and the technical operations required for secure partner onboardings and EDI data transfer.

Today at ecosio, I leverage this background alongside specialised training from my Master's degree in cybersecurity, various industry certifications, and hands-on operational experience as an L2 SOC Analyst and Blue Teamer.

Looking toward the future, I am actively expanding my expertise. I am currently studying the CompTIA Sec AI+ course, recognising the fast-paced growth of our digitised world and artificial intelligence, I am deeply focused on understanding its security benefits and emerging risks to help shape the future of modern SOC operations.

Professional Background

L2 SOC Analyst @ ecosio GmbH

Driving detection engineering, automation, and incident response for a modern SOC.

Detection Engineering & Automation
  • Detection Engineering: Lead rule creation/maintenance across Datadog SIEM, Material Security, and CrowdStrike (mapped to MITRE ATT&CK), driving cross-team signal investigations via Slack.
  • Datadog Workflow SOAR: Created custom workflows that remove L1 triage by correlating logs/signals, aggregating metadata, and delivering clean notifications to the SOC.
  • Dashboard Creation: Built and managed a wide variety of dashboards to assist the SOC during signal triage and active investigations.
  • Log Management: Orchestrate log integrations into Datadog Cloud SIEM, configuring indexes, log pipelines, and managing cost/billing.
  • GitLab CI/CD: Automated SOC operations using Python and the CrowdStrike API to parse application reports and solve Shadow IT installs.
Platform Defense & Response
  • Signal Triage & Response: Act as L2 SOC Analyst, actively triaging and escalating signals across our entire security tech-stack.
  • Incident Response: Act as Incident Liaison/Tech Lead and SME (via incident.io), managing the full lifecycle from triage through post-mortem.
  • Phishing Investigator: Leverage Material Security to investigate native/user reports, remediate campaigns, and orchestrate company-wide phishing education.
  • CrowdStrike AIDR: Key stakeholder for AIDR workforce/agents deployment; overseeing custom policies for Data Loss Protection (DLP) and Shadow AI usage.
  • CrowdStrike SaaS: Key stakeholder in onboarding of SaaS applications, reviewing posture, and remediating findings.
SOC Operations
  • Signal Architecture: Engineered custom SOC pipelines to route cross-platform signals into a centralised Notion Triage Queue with a custom ticketing system.
  • SOC Runbooks: Authored high-quality playbooks in Notion (scoped to MITRE ATT&CK) to provide reproducible steps and escalation criteria.
  • SOC Processes: Established monthly reviews for SIEM detections, endpoint attack surfaces, and identity audits, plus documentation for rule submissions.
  • Automated Threat Intel: Built a proactive, API-driven threat intel system in Notion to centralise daily feeds (Bleeping Computer, Krebs, Hacker News).

Education & Certifications

Academic & Industry

  • CompTIA Sec AI+
    CURRENTLY STUDYING
  • MSc Computer Science with Cybersecurity (Distinction)
    University of Sunderland • 2025
  • Certified Blue Team Level 1 (BTL1)
    Security Blue Team • 2025
  • AWS Certified Cloud Practitioner (CCP)
    Amazon Web Services • 2024
  • Advanced Level Apprenticeship (IT, Software, Web & Telecoms)
    DXC Technology • 2017

Specialised Platform Training

  • CrowdStrike University
    • CrowdStrike Falcon Administrator
    • Falcon Endpoint Data Protection Fundamentals
    • CrowdStrike AIDR Fundamentals
  • Datadog Learning Center
    • Datadog Cloud Security Engineer Learning Path
    • Datadog Core Skills Learning Path

* Certificates available upon request.