Keelen Carrera
Security+ · AWS Cloud Practitioner · CargoWise Certified

KEELEN CARRERA

Security Engineer SOC Analyst DevSecOps & AWS Cloud Specialist Logistics Systems Specialist

Engineer shaped by 2+ years across global freight operations, enterprise system integration, and secure software development. From carrier APIs and customs data flows to DevSecOps pipelines. I understand how real-world systems are built, connected, and broken.

2+Years Experience
8Integrations Delivered
5ATT&CK Techniques Mapped
scroll

Shifting left.
Defending everything.

Security isn't a layer you bolt on at the end, it's the foundation. With a software engineering background across backend development and enterprise cloud integration, I transitioned deliberately into security, earning my CompTIA Security+ and AWS Certified Cloud Practitioner while building real-world skills in SIEM, SOC operations, and DevSecOps pipeline hardening.

My background as a software engineer gives me an edge in security: I understand how systems are built, which means I understand exactly how they break. I embed security into CI/CD pipelines, harden cloud infrastructure, and build detection capabilities that catch threats before they become incidents.

Currently pursuing for SOC Analyst and DevSecOps while simultaneously building a hands-on security lab and public portfolio demonstrating practical skills beyond certifications.

🛡️
CompTIA Security+SY0-701 · Issued Feb 2026 · Expires Feb 2029
☁️
AWS Cloud PractitionerIssued Mar 2026 · Expires Mar 2029
🔎
CompTIA CySA+Next Target
🚢
CargoWise Certified ProfessionalIssued Jun 2024 · Expires Jun 2026
keelen@devsecops ~
❯ whoami
keelen_carrera
❯ cat profile.txt
Role : DevSecOps Engineer / SOC Analyst
Stack : Node.js · Python · TypeScript · AWS
Security : Security+ · SIEM · CI/CD · IaC
Location : Houston, TX
Status : Open to Opportunities
❯ ls skills/
threat-detection/ incident-response/ pipeline-security/ cloud-hardening/ vulnerability-mgmt/ siem-engineering/
❯ █

Technical Arsenal

Rated honestly, not inflated: Hands-On means shipped in a real lab or production system, Building means active current work, Cert-Level means certified foundational knowledge without production hands-on time yet.

🔒

Security

Detection Engineering (Sigma · MITRE ATT&CK · Atomic Red Team)Hands-On
Vulnerability Management (SAST · SCA · Secrets Scanning)Hands-On
SIEM — WazuhHands-On
Log Analysis & TriageHands-On
SIEM — Splunk / Microsoft SentinelBuilding
Network Traffic Analysis (Wireshark)Building
☁️

Cloud & DevOps

CI/CD Pipeline Security (GitHub Actions)Hands-On
AWS Core Services (IAM · EC2 · S3)Cert-Level
Docker / ContainersBuilding
IAM & Access ProvisioningHands-On
💻

Development

Node.js / TypeScriptHands-On
RESTful API DesignHands-On
SQL (Stored Procedures & Query Design)Hands-On
Prisma / PostgreSQLHands-On
PythonBuilding
Java / C# / C++Coursework
🔧

Tools & Platforms

MuleSoftJitterbit SalesforceJira GitLinux ETL PipelinesExpress MITRE ATT&CKEDI (X12)

Career Timeline

Feb 2025 – Present

Independent Cybersecurity Professional Development

Self-Directed Training & Hands-On Laboratory Work
Security-Focused

Conducting full-time independent training in cybersecurity disciplines, with a focus on detection engineering, blue-team operations, and cloud security.

  • Curated and documented 5 MITRE ATT&CK-mapped Sigma detection rules — each with adversary context and hardening guidance — as the technical foundation for a home SOC lab; Wazuh deployment and Atomic Red Team validation are the active next phase.
  • Developed experience in API design, data processing, and scalable system architecture, with an emphasis on translating system requirements into working applications and improving overall system reliability.
  • Focused on professional growth through certifications and hands-on development in cloud, backend, and security-focused systems. Earned AWS Certified Cloud Practitioner and CompTIA Security+ while building real-world projects, including a logistics integration platform and a full-stack inquiry processing application.
AWSIAMREST APIsSecure SDLC
Apr 2026 – Present

Product Flow Specialist

Best Buy · Part-Time
Operations

Concurrent part-time role in inventory and fulfillment operations, run alongside the security training and project work above — not a career pivot, a deliberate choice to keep income steady while building toward a full-time security engineering role.

  • Executes inventory pulls, stocking, and order fulfillment against tight service windows — consistently completing picks within a 45-minute fulfillment target at 100% accuracy.
  • Reinforces the operational discipline (process adherence, inventory integrity, time-boxed execution) that carries directly into incident response and detection workflows.
Inventory OpsProcess Discipline
Jun 2023 – Jan 2025

Software Integration Engineer

Aries Worldwide Logistics
Integration

Owned end-to-end design, development, deployment, and ongoing maintenance of enterprise system integrations connecting Revenova TMS, CargoWise ERP, HubSpot CRM, Salesforce, EDI trading partners, and internal company tools.

  • Configured logging and monitoring for integration pipelines, instrumenting flows to surface failure conditions, capture audit trails of data transformation steps, and support root-cause analysis when production incidents occurred. Routinely reviewed logs to identify integration anomalies and remediation requirements.
  • Designed and implemented automated ETL pipelines using SQL stored procedures to optimize data ingestion and transformation, improving data processing efficiency and ensuring data integrity.
  • Collaborated with business stakeholders and technical teams to troubleshoot production integrations, resolve data discrepancies, and improve operational reliability across logistics platforms..
MuleSoftPythonETLSQLAPI Integration
Dec 2022 – Jun 2023

Software Development Instructional Support Staff

Code Fellows
Education

Supported software development professional program, providing technical instruction, code review, mentorship, and deployment guidance to students transitioning into software engineering careers.

  • Supported 30+ students building full-stack applications using JavaScript, Python, SQL, and AWS services; conducted code reviews, guided deployment to AWS EC2/S3, and reinforced Git-based workflows.
  • Provided 1-on-1 tutoring for students who needed more assistance with web services, applying technical concepts and logic, and problem-solving skills for code challenges.
JavaScriptAWS EC2GitCode Review

Verified Credentials

Professional certifications across cloud architecture, cybersecurity, and logistics operations — each backed by a credential ID and active validation.

🛡️ Active

CompTIA Security+ SY0-701

CompTIA
IssuedFeb 2026
ExpiresFeb 2029
Cybersecurity
☁️ Active

AWS Certified Cloud Practitioner

Amazon Web Services
IssuedMar 2026
ExpiresMar 2029
ID9e57badb90de4f1a9f4531cbc4d24efd
Cloud
🚢 Active

CargoWise Certified Professional

WiseTech Global
IssuedJun 2024
ExpiresJun 2026
ID102272
Logistics

Lab Portfolio

Every project below gets the same breakdown — problem, what I actually owned, and outcome — because that's what stands up in an interview, not a screenshot and a tech-stack list.

SCA — dependency audit0 vulnerabilities
SAST — Semgrep0 findings · 43 files · 83 rules
Secrets — Gitleaks0 leaks · 384 commits
Threat model — STRIDEAuth missing, app-wide
Case Study 01 · Independent Security Work

AppSec Labs — Hardening a Real Codebase

Solo · Aug 2026 · Ongoing

Problem

Most portfolio "security labs" are synthetic CTF boxes. I wanted to know what an actual AppSec review finds on a real, already-shipped codebase — so I forked my own Dine Flow backend and ran it through one.

What I Did

Forked the repo to my own account, then worked the review in order: SCA dependency triage, a STRIDE threat model, SAST via Semgrep, secrets scanning via Gitleaks, then a GitHub Actions pipeline that gates every future push on all three checks.

Headline Finding

The threat model surfaced something the scanners couldn't: zero auth middleware across every router — including two metrics endpoints serving live revenue and waste data with no authentication at all. That's the finding that matters most, since it compounds every other issue rather than sitting beside them. (Remediation is scoped as the next phase, not yet shipped.)

Verifying My Own Tooling

I didn't just trust a green pipeline. I opened a branch that deliberately added a known-vulnerable dependency, an eval() call, and a fake hardcoded AWS key — confirmed all three checks failed red, and caught a stale scanner-version bug in my own pipeline in the process.

GitHub ActionsSemgrepGitleaksnpm auditSTRIDE Threat Modeling
Dine Flow Platform
Case Study 02 · Team Project

Dine Flow: Stock & Inventory Router

Backend engineer, 6-person cohort team · Feb–Apr 2025

Problem

Restaurant managers juggle inventory, ordering, and stock tracking across disconnected tools. Dine Flow's goal was one platform covering all three.

What I Owned

The Express/TypeScript/Prisma stock router, end-to-end: full CRUD on inventory records, expiration-date calculation from shelf life, and conditional logic branching between local stock creation and an automated supplier reorder request. Inventory decrements automatically the moment an order is placed. Schema design and the frontend were team-built; the stock router was mine.

A Real Bug

The GET-by-ID endpoint was returning every stock item instead of the one requested — traced to referencing the wrong ID field from the database, fixed by mapping the correct one.

Outcome

Deployed to Netlify and demoed live to the cohort in April 2025. This same codebase is what Case Study 01's security review is built on.

Node.jsTypeScriptExpressPrisma
Logistics Integration Portfolio
Case Study 03 · Solo Project

Org Matching Utility — Logistics Integration Portfolio

Solo · One of 10 documented integration patterns — the one that's actually running

Problem

CRM and ERP org records drift out of sync over time — mismatched, inactive, or orphaned records that break clean bidirectional sync between systems.

What I Built

A reconciliation engine in MuleSoft/DataWeave classifying every record as matched, inactive, orphaned, or missing a code, behind a real HTTP listener secured with bearer-token authentication I configured explicitly as a policy — not an Anypoint default.

A Real Bug

A mapping error silently connected sales-rep category CUS to members from category ACT — no error thrown, just members quietly assigned to the wrong rep. Reworked the mapping conditions to properly separate all three categories, then re-tested against sample data to confirm.

Honest Scope

This is the one workflow in the 10-pattern repo that was actually run and tested — via Postman against the live endpoint, checking that response data matched the source, not just a 200 status. The other 9 patterns are documented architecture and DataWeave designs using fictional data.

MuleSoftDataWeaveREST APIsBearer Auth
SOC Home Lab
Case Study 04 · Independent Project

SOC Home Lab — Detection Engineering Foundation

Solo · Apr 2026 · Foundation Phase

Problem

Detection logic doesn't click from reading alone. Before I touch a live SIEM, I wanted to build the habit of reading, evaluating, and mapping real detection rules against the adversary behavior they're meant to catch.

What I Did

Researched and curated 5 Sigma detection rules mapped to MITRE ATT&CK techniques — including a brute-force SSH rule targeting T1110.001 — reviewed each rule's logic line by line rather than treating them as a copy-paste library, and documented adversary context and hardening guidance for each one.

Honest Scope

These rules are curated and studied, not authored from scratch — I selected, reviewed, and learned from existing detection logic rather than originating it. Wazuh deployment and Atomic Red Team validation against a live attack/target VM pair are the active next phase, not yet started.

SigmaMITRE ATT&CKWazuh (planned)
Case Study 05 · WGU Coursework

Discover Texas

Solo · WGU Front-End Web Development · 🏆 WGU Excellence Award

Problem

WGU's Front-End Web Development course required a multi-page, fully responsive site built in vanilla HTML, CSS, and JavaScript — no framework scaffolding to fall back on.

What I Built

A solo travel-guide site covering Texas's three major cities — Austin, Houston, and Dallas — with dedicated city guides, attractions, dining recommendations, and a working contact page, designed and styled from scratch.

Outcome

Earned WGU's Excellence Award for the submission.

HTMLCSSJavaScriptResponsive Design

Learning Roadmap

A transparent view of the structured path I'm following to build professional-grade security skills — cert by cert, lab by lab.

🛡️
Security+
Completed 2026
→
☁️
AWS Cloud Practitioner
Completed mar 2026
→
🔍
CompTIA CySA+
Next
→
🏗️
AWS Solutions Architect
Upcoming
01

SIEM Mastery

Wazuh, Splunk (BOTS CTF), Microsoft Sentinel, Elastic SIEM. Writing custom detection rules, SPL queries, KQL analytics.

Weeks 1–4Active
02

Practical Threat Detection Engineering Labs

Active Directory environment, attack simulation with VMS (WSL2), detection and incident reporting, Docker

Weeks 2–6Active
03

CTF & Platform Training

TryHackMe SOC paths, HackTheBox Sherlocks, LetsDefend.io alert triage, PortSwigger Web Academy.

OngoingActive
04

DevSecOps Pipeline

GitHub Actions with CodeQL, Semgrep, Trivy, TruffleHog, Checkov. IaC security with Terraform. Container scanning.

Months 2–4Planned
05

10-Lab Portfolio

SIEM deploy, phishing detection, Kerberoasting, PCAP analysis, vuln management, AWS threat detection, IR playbooks, DFIR challenges.

OngoingBuilding

Let's Build
Something Secure.

Open to Security Software Engineering, SOC Analyst, DevSecOps, and Logistics-tech integration roles. I bring engineering depth, a security mindset, and a rare combination of freight operations experience and modern software skills.