Phillip Tarrant

Cybersecurity Director | Automation Leader

Accomplished and analytical professional with 20+ years of experience in cybersecurity, server infrastructures, and data-center operations. Proven expertise in AI use in Cyber Operations, digital forensics, penetration testing, information system management, malware reversing, threat detection, and threat hunting. Proactive leader with a proven record of managing multiple large teams and leading the charge to complete project goals. Managed MSSP operations for 50+ large business clients encompassing over 150,000 assets and 1 million+ users.

Work

Senior Information Security Consultant

Confidential
– Present
Remote

Contract consulting role providing cybersecurity leadership and technical expertise.

  • Develop, design, and review risk assessments and vulnerability scans of client networks and systems

  • Developing and implementing robust security controls and countermeasures to mitigate identified risks

  • Designing and deploying secure architectures for cloud, on-premises, and hybrid environments

  • Providing guidance on compliance with industry regulations (HIPAA, PCI-DSS, GDPR, NIST 800-53)

  • Collaborating with clients to develop and implement incident response and disaster recovery plans

  • Conducting regular security audits and assessments to ensure ongoing compliance and security posture

  • Short-term director role at American Technology Services (ATS) restructuring SOC flow and training

  • Managed Vulnerability Management Program for largest fintech client using Qualys

  • Currently managing SOC operations for US Defense Space market supplier across multiple Microsoft tenants

Compuquip Cybersecurity

Director of Automation
Doral, Florida

Lead the Automation Team to deliver the automation needs of the business.

  • Spearheaded new automation processes and procedures including standup of new architecture and infrastructure

  • Drove and mentored the team in new Automation workflows using Python, AWS Lambda and SOAR technology

  • Developed custom AI processes to handle several key business needs using custom prompts and data

  • Built automation handling 3,500 tickets weekly with 47% closed without human involvement

  • Designed, programmed, and deployed AI tools, prompts, code, and logic for security automation

SOC Director
Doral, Florida

Directed Security Operations Center and Red Team operations for MSSP clients.

  • Grew SOC client base from 16 to 52 customers over tenure with expansion of services

  • Improved SOC profitability from 18% to 52% margin (80% in one quarter) contributing to 15% annual net income growth

  • Directly managed team of 17 reports

  • Oversaw Red team / Offensive Security Teams and Managed Remediation Service projects

  • Managed DFIR engagements, MDR services, Proactive Vulnerability Scanning, Patching, and Pentesting

  • Maintained situational awareness reports for advanced threats (APT and FO incidents)

  • Part of leadership team with COO/CEO/CFO involved in quarterly strategic planning

SOC Technical Manager
Tampa, Florida

Managed SOC Operations and led incident research and engineering teams.

  • Authored SOPs and training documentation for SOC team

  • Lead Incident Research and mentored SOC Engineers

  • Developed threat trend analysis reports and metrics

  • Managed SOC Operations and developed SOC playbooks/workflows

  • Generated end-of-month reports for managers and customers

  • Maintained situational awareness reports for advanced threats

Sr. Cyber Security Architect

Travel Syndication Technology (TST)
Alpharetta, Georgia

Responsible for security architecture, training programs, and compliance across the organization.

  • Formulated and oversaw phishing and developer security training programs

  • Developed and maintained cloud security protections and security posture

  • Created custom tools to automate attacks against infrastructure and design detections

  • Saved $10,000+ through effective vendor/supplier negotiations

  • Steered organization through PCI and NIST 800 series audits

  • Devised, created, and upgraded cybersecurity related policies and procedures

  • Designed and implemented automated security verification and attack programs

Intercontinental Exchange

Senior Cyber Security Engineer
Marietta, Georgia

Part of the Architecture and Automation Team focused on security data flow and automation.

  • Designed and maintained security data flow from network endpoints through aggregation, parsing, and storage

  • Created methods, processes, and algorithms to extract knowledge from structured/unstructured data

  • Designed custom tools to automate SOC triage and response activities

  • Incorporated security into infrastructure CI/CD pipelines including cloud technologies

  • Formulated vulnerability and threat hunting dashboard for tracking and mitigation

Cyber Security Engineer
Marietta, Georgia

Part of the Incident Response / Digital Forensics Team as lead investigator.

  • Served as lead investigator on critical incidents with thorough investigations

  • Created extensive documentation on processes and procedures for the entire IR team

  • Served as leader in Malware Analysis in isolated sandboxed environments

  • Developed skills of junior agents including custom malware writing through training

  • Managed multi-server compromise investigations coordinating across three teams and time zones

The National Wild Turkey Federation

Technical Services Manager
Edgefield, South Carolina

Managed IT team supporting 300+ staff members with focus on infrastructure and security.

  • Managed team of technicians and developers facilitating 300+ staff members

  • Oversaw 8 direct reports with performance management responsibilities

  • Conducted vendor/supplier negotiations to minimize costs

  • Managed security of entire web presence including network and programming code

  • Efficiently managed doubling of server space and usage

  • Migrated 3rd party tools to in-house solutions saving $50,000+ yearly

Network / Server Administrator
Edgefield, South Carolina

Managed Windows and Linux server environments with focus on infrastructure and automation.

  • Designed, managed, and monitored infrastructure systems (LANs, WANs, Security)

  • Developed and maintained process automation through scripting and programming

  • Administered servers, computers, printers, routers, switches, firewalls, and phones

  • Spearheaded performance tuning, hardware upgrades, and resource optimization

System Administrator

Morgan Thermal Ceramics
Augusta, Georgia

Contract role managing network support and infrastructure upgrades.

  • Managed network support and upgrades including fiber optic link installation

  • Served key role implementing 35 managed switches with several VLANs

  • Resolved major data outage in main switch room without assistance

  • Completed three-month contract in one month

  • Developed automated cloning system to minimize cost and speed deployment

IT Coordinator / Network Administrator / System Administrator

Briarwood Academy
Warrenton, Georgia

Oversaw IT department budgets and deployment strategies for the school.

  • Oversaw budgets and deployment strategies for entire IT department

  • Administered servers, desktop computers, printers, routers, switches, firewalls

  • Shifted all servers from physical to virtual to save space and minimize costs

  • Rolled out wireless for entire campus comprising several acres

  • Negotiated and delivered fiber link for the school free of charge

  • Managed Linux NAS storage solutions for 200+ workstations

Computer Service Technician

Pronet
Georgia

IT expert for hire in block time situations and emergency disaster recovery.

Tier 3 Support

Sitel Group

Assisted Tier 2 technicians with customer service issues and tested new developing technologies.

Education

Virginia College

Associate in Network Administration

Awards

Lethal Forensicator Coin Winner

Awarded by SANS/GIAC

SANS Challenge Coin for excellence in digital forensics

Certificates

GWAPT - Web Application Penetration Tester

Issued by GIAC

GCFA - Forensic Analyst

Issued by GIAC

GCIH - Incident Handler

Issued by GIAC

A+ Certification

Issued by CompTIA

Skills

Security Operations & SIEM

  • Splunk
  • ELK Stack
  • Microsoft Sentinel
  • Microsoft Defender
  • Sentinel One
  • Rapid7 IDR
  • Stellar Cyber

SOAR Platforms

  • Swimlane
  • D3 SOAR
  • Torq
  • Playbook Development
  • Workflow Automation

EDR & Threat Detection

  • Darktrace
  • Tanium
  • Vectra
  • FireEye
  • Sentinel One
  • Detection Engineering

DFIR & Forensics

  • Volatility
  • Malware Analysis
  • Reverse Engineering
  • Incident Response
  • Evidence Collection
  • Multi-host Investigation

Penetration Testing & Red Team

  • Metasploit
  • Web Application Security
  • Attack Simulation
  • Red Team Oversight
  • Purple Team Testing
  • Vulnerability Assessment

Cloud Platforms & Security

  • AWS
  • Azure
  • Oracle Cloud
  • Lambda
  • EC2
  • Cloud Security Architecture
  • Hybrid Environments

AI/ML & Automation

  • AWS Bedrock
  • Large Language Models
  • RAG
  • Machine Learning
  • Python Automation
  • Custom Tool Development

Programming & Scripting

  • Python
  • PowerShell
  • Bash
  • SQL
  • YAML

Infrastructure & Systems

  • Windows Server
  • Linux/UNIX
  • Active Directory
  • VMware
  • Docker
  • Kubernetes
  • Network Architecture

Compliance & Frameworks

  • NIST 800-53
  • PCI-DSS
  • HIPAA
  • GDPR
  • CIS Benchmarks
  • Security Audits

Leadership & Management

  • Team Leadership (17+ reports)
  • MSSP Operations
  • Budget Management
  • Vendor Negotiations
  • Training Programs
  • Hiring & Mentorship

Languages

English

Native speaker