Available for new opportunities

Garrett Morgan

Cybersecurity Analyst  /  GRC  ·  SOC  ·  Infrastructure

Security professional with 3+ years across security operations, GRC consulting, and infrastructure engineering. I bridge the gap between hands-on threat detection and governance frameworks — from triaging 500+ daily SOC alerts to leading multi-framework compliance audits for enterprise clients.

🛡️
3+ Years Security Experience
📋
6 Frameworks GRC Coverage
🎓
CISA | Net+ Certified
🏗️
Home Lab Builder
GM
Current Status
Senior Audit Consultant
AARC-360 · Remote
CISSP Exam: Jun 2026

About Me

Security engineer who builds before auditing, and audits before recommending.

I started in IT infrastructure — administering VMware ESXi environments at BYU, managing 200+ virtual machines, and learning how enterprise systems actually break under pressure. That hands-on foundation shaped how I approach security: not as a policy exercise, but as an engineering problem with real operational consequences.

At Arctic Wolf, I operated inside a 24/7 SOC — triaging hundreds of alerts daily, running incident response across diverse customer environments, and building the runbooks that made the team faster. That experience taught me what threat detection looks like at scale, and why playbook quality matters as much as tooling.

Today at AARC-360, I lead multi-framework security audits spanning SOC 2, PCI DSS, HITRUST, ISO 27001, and ISO 42001. I work directly with client leadership to translate technical control gaps into clear remediation strategies — and I helped build a one-test, multi-audit methodology that cuts duplicate testing across overlapping compliance programs.

Outside of work, my home lab runs Proxmox VE, a segmented UniFi network, Docker-hosted services, and a self-hosted Wazuh SIEM. I learn by building — and I believe the best security professionals maintain that builder instinct throughout their careers.

Current Focus Areas

Security Operations GRC Consulting SIEM Engineering Cloud Security Compliance Automation Identity & Access Threat Detection Infrastructure Security
3+
Years in Security
6
Compliance Frameworks
500+
Daily Alerts Triaged (Arctic Wolf)
200+
VMs Administered (BYU)

Technical Skills

A full-stack security skillset spanning detection, governance, infrastructure, and automation.

🔍
Security Operations
Security Monitoring Incident Response Alert Triage Threat Detection Threat Intelligence Threat Hunting Security Awareness Training Playbook Development
📊
SIEM & Detection Engineering
Wazuh Kibana Log Analysis IDS / IPS Vulnerability Scanning Custom Alerting Rules Dashboard Design
📋
Governance, Risk & Compliance
SOC 1 / SOC 2 PCI DSS HITRUST ISO 27001 ISO 42001 NIST CSF Risk Assessment IT General Controls Application Controls GDPR / CCPA
☁️
Cloud & Infrastructure
AWS Microsoft Azure Virtual Networks (VNets) NSGs Storage Accounts VMware ESXi Proxmox VE vCenter
🌐
Networking
TCP/IP DNS / DHCP VLANs VPN Firewall Configuration Network Segmentation UniFi / UDM Pro CompTIA Network+
🔐
Identity & Access Management
Active Directory Group Policy (GPO) RBAC MFA Least Privilege IAM User Provisioning Privacy Controls
📦
Containers & Automation
Docker n8n Python PowerShell Bash REST APIs Workflow Automation
💻
Operating Systems
Ubuntu Linux Debian Windows Server Windows 10/11 Linux Administration Server Hardening
📈
Monitoring & Observability
Grafana Prometheus Log Monitoring Metrics Dashboards Alerting Rules Service Uptime Container Health

Professional Experience

Security roles spanning enterprise SOC, GRC consulting, and IT infrastructure.

Senior Audit Consultant
Jul 2023 — Present
AARC-360 · Anna, TX (Remote)
  • Lead IT security audits and risk assessments across 6 compliance frameworks — SOC 1, SOC 2, PCI DSS, HITRUST, ISO 27001, and ISO 42001 — evaluating IT general controls, application controls, and security processes for enterprise clients.
  • Identify control gaps and cybersecurity risks, then architect risk mitigation strategies that strengthen client compliance posture, governance structure, and overall security culture.
  • Present findings, risks, and remediation roadmaps directly to client leadership, translating complex technical vulnerabilities into clear, actionable guidance for non-technical stakeholders.
  • Manage 3+ concurrent client engagements in a senior capacity — overseeing teams, reviewing audit workpapers, and mentoring staff consultants to ensure accurate and timely deliverables.
  • Contributed to a unified one-test, multi-audit methodology that eliminated duplicate control testing across overlapping compliance engagements, materially improving engagement efficiency.
SOC 2 PCI DSS HITRUST ISO 27001 ISO 42001 SOC 1 Risk Assessment IT General Controls Stakeholder Management
Triage Security Analyst
Jan 2023 — Jul 2023
Arctic Wolf · Pleasant Grove, UT
  • Performed real-time security monitoring inside a 24/7 SOC environment — triaging 500+ daily security alerts using playbook-driven analysis to detect, investigate, and escalate active threats across diverse customer environments.
  • Executed incident response activities including threat identification, containment procedures, and escalation to senior analysts and customer teams.
  • Developed and refined security runbooks that standardized incident response workflows, accelerated team response times, and strengthened knowledge management across the analyst team.
  • Diagnosed and resolved 100+ technical issues involving security sensors and vulnerability scanners, maintaining continuous monitoring coverage and operational reliability for customers.
SIEM SOC Operations Incident Response Threat Detection Runbook Development Vulnerability Management Alert Triage
Student Systems Engineer
Feb 2022 — Jan 2023
Brigham Young University · Provo, UT
  • Administered VMware ESXi and vCenter environments supporting 200+ virtual machines across the university's infrastructure, ensuring uptime and performance for critical academic and administrative services.
  • Resolved hardware failures, network connectivity issues, and configuration problems across Dell MX chassis and blade server infrastructure, reducing downtime and improving overall system stability.
  • Built foundational expertise in enterprise virtualization, server hardware, and production IT operations — the infrastructure understanding that underpins all later security work.
VMware ESXi vCenter Dell MX Chassis Virtualization Network Troubleshooting Server Administration

Certifications

An active certification path targeting the highest levels of security expertise.

🌐
CompTIA Network+
CompTIA · Earned 2024
● Active
🔍
CISA — Certified Information Systems Auditor
ISACA · Passed 2025
◎ Exam Passed — Issuance Pending
🛡️
CISSP — Certified Information Systems Security Professional
ISC2 · Exam Scheduled June 2026
⏳ Candidate — In Preparation
Certification Timeline
2024
CompTIA Network+ · Active
2025
ISACA CISA · Passed — Pending Issuance
2026
ISC2 CISSP · Exam Jun 2026 — In Preparation

Featured Projects

Real systems built to learn, test, and demonstrate production-level security and infrastructure engineering.

🔭
Security Operations Home Lab

Wazuh SIEM Security Monitoring Lab

Designed and deployed a full Security Information and Event Management system from scratch in a home lab environment. The system centralizes log collection across the network, detects suspicious behavior in real time, and surfaces security events through a custom Kibana visualization layer.

Problem No centralized visibility into endpoint and server security events across the lab network.
Solution Deployed Wazuh manager on Ubuntu Server with agents on each host; configured detection rules and built Kibana dashboards for real-time analysis.
Outcome Enterprise-grade SIEM architecture running on commodity hardware — validates SOC monitoring concepts in a controlled environment.
Wazuh Kibana Ubuntu Linux Log Agents Detection Rules Security Analytics
⚙️
Automation Engineering Home Lab

Containerized Automation Platform (n8n + Docker)

Designed and deployed a self-hosted workflow automation platform using Docker to containerize n8n on a Linux server. The system automates system administration tasks, API-driven notifications, and scheduled operations — eliminating repetitive manual work across the home lab.

Problem Manual system administration tasks and no centralized automation layer across lab services.
Solution Containerized n8n using Docker on Ubuntu Server; built workflows for API integrations, scheduled tasks, and automated notifications.
Outcome Reusable, self-hosted automation platform demonstrating containerization, service deployment, and API-driven workflow engineering.
Docker n8n Ubuntu Server REST APIs Workflow Automation Container Networking
☁️
Cloud Infrastructure Azure

Azure Cloud Infrastructure Lab

Built a cloud networking and identity management lab in Microsoft Azure to replicate enterprise cloud architecture patterns. The environment includes segmented virtual networks, security-hardened VMs, Network Security Groups, and an identity management simulation using Azure IAM.

Problem Limited exposure to cloud-native networking and IAM patterns relevant to enterprise cloud security work.
Solution Deployed VNets with subnet segmentation, applied NSG rules to control traffic flow, provisioned VMs, and configured storage accounts with access controls.
Outcome Hands-on cloud architecture skills directly applicable to cloud security audits and infrastructure assessments.
Microsoft Azure Virtual Networks NSGs Azure VMs Storage Accounts IAM

Home Lab

A fully operational engineering lab used to build, break, and validate real security and infrastructure concepts.

🖥️
Proxmox VE
Virtualization Platform
🌐
5 VLANs
Network Segments
📦
Docker
Container Platform
🔭
Wazuh
SIEM Platform
☁️
Azure
Cloud Environment
📈
Grafana
Monitoring Stack
🖥️
Virtualization — Proxmox VE
  • Windows Server VM — Active Directory, DNS, DHCP, GPO; simulates enterprise identity infrastructure
  • Ubuntu / Debian Server VM — Docker host for containerized services and automation workloads
  • 16GB RAM / 2TB Storage — dedicated bare-metal host
  • Full VM lifecycle management, snapshots, and resource allocation
🌐
Network Architecture — UniFi
Management
Infrastructure access
Server
Lab services
User
End-user devices
IoT
Isolated smart devices
Guest
Untrusted network access
  • UDM Pro router with full firewall rules and traffic policies
  • USW-24 POE managed switch; (2) UniFi ceiling APs
  • VPN, DNS, DHCP, inter-VLAN routing controls
📦
Container Services — Docker
  • n8n — workflow automation, API integrations, scheduled tasks
  • Grafana + Prometheus — system metrics, service uptime, container health dashboards
  • Docker networking for isolated service communication
  • Container lifecycle automation via Bash scripts
🔐
Security Implementation
  • Wazuh SIEM — centralized log collection, real-time alerting, Kibana dashboards
  • MFA on all administrative access points
  • RBAC across AD, Docker, and network management
  • Least privilege principles enforced at all service layers
  • Firewall rules and inter-VLAN ACLs to limit lateral movement
☁️
Cloud Environment — Azure
  • Virtual Networks (VNets) with subnet segmentation
  • Network Security Groups (NSGs) for traffic filtering
  • Azure VMs with security-hardened configurations
  • Storage Accounts with access control policies
  • Identity and Access Management simulation
  • Cloud networking patterns mirroring enterprise architecture
Automation — PowerShell & Bash
  • PowerShell — user provisioning, AD management, system maintenance reports
  • Bash — system updates, service management, Docker container automation
  • Reduced manual administration and improved consistency across all managed systems
  • Scheduled tasks and cron-based automation pipelines

Key Achievements

Engineering contributions and professional milestones across SOC, GRC, and infrastructure roles.

🔄

Multi-Framework Audit Efficiency

Contributed to a unified one-test, multi-audit methodology at AARC-360 that eliminated duplicate control testing across overlapping compliance frameworks, reducing audit effort and improving delivery timelines.

SOC Runbook Engineering

Developed and refined incident response runbooks at Arctic Wolf that standardized triage workflows, improved escalation accuracy, and strengthened institutional knowledge management across the analyst team.

📊

High-Volume Alert Operations

Operated at full production capacity in a 24/7 SOC — triaging 500+ daily security alerts using structured playbook analysis, maintaining consistent threat detection quality across diverse customer environments.

🔧

Sensor Reliability Maintenance

Resolved 100+ technical issues with security sensors and vulnerability scanners at Arctic Wolf, ensuring continuous monitoring coverage and eliminating blind spots in customer security environments.

🎓

CISA Certification — Passed 2025

Passed the ISACA CISA examination in 2025, validating expertise in IS auditing, governance, risk management, and information systems control — a globally recognized credential in security assurance.

🏗️

Enterprise-Grade Home Lab

Built and maintains a production-grade home lab environment running Proxmox VE, a segmented UniFi network across 5 VLANs, Docker containerized services, Wazuh SIEM, and an Azure cloud extension — all self-designed and self-operated.

🌐

6-Framework GRC Coverage

Executing security audits across SOC 1, SOC 2, PCI DSS, HITRUST, ISO 27001, and ISO 42001 simultaneously — one of the broadest active compliance framework portfolios a consultant of this tenure can demonstrate.

🖥️

200+ VM Infrastructure Administration

Administered production VMware ESXi and vCenter environments at BYU supporting over 200 virtual machines — building the infrastructure depth that informs practical security assessments today.

Education

Bachelor of Science in Cybersecurity
Graduated
Brigham Young University · Provo, UT

Formal academic foundation in cybersecurity principles, information assurance, cryptography, network security, and digital forensics. Concurrent hands-on engineering experience as a Student Systems Engineer in BYU's IT infrastructure team.

Cybersecurity Network Security Cryptography Information Assurance Digital Forensics

Resume

📄
Garrett Morgan — Resume
Cybersecurity Analyst · GRC · SOC · Infrastructure

Contact

Open to security roles, consulting engagements, and technical conversations.

I'm currently open to full-time security roles and consulting opportunities in security operations, GRC, cloud security, and infrastructure engineering. If you're building or growing a security team, let's talk.

Open to Opportunities

Based in Anna, TX — available remotely and open to hybrid or on-site roles in the DFW area. Currently focused on opportunities in security operations, GRC consulting, cloud security, and infrastructure engineering.

Remote DFW Hybrid Security Operations GRC Cloud Security Infrastructure