// Philadelphia, PA

Travis Fricker

Aspiring SOC Analyst — Detection Engineering & Alert Triage

Security-focused IT professional with 4+ years investigating business email compromise, triaging email threats, and administering identity and endpoint security across Microsoft 365 and Azure environments. Currently closing the gap to full-time SOC work through a self-built home lab covering SIEM alert triage, MITRE ATT&CK mapping, and detection engineering — documented in the sections below.

SOC-Relevant Experience

// grouped by function, pulled across roles

Email Threat Triage & BEC Response

  • Triaged Proofpoint quarantine alerts — validated flagged messages with end users, made release/block determinations
  • Investigated and remediated Business Email Compromise: removed malicious inbox rules, reset compromised credentials per Microsoft best-practice procedures
  • Co-developed annual phishing simulation playbook (Cofense) — designed campaign scenarios and cadence to measure user detection capability

Identity & Log Analysis

  • Pulled and analyzed Active Directory / Entra ID logs during access investigations to identify unauthorized access and anomalous authentication activity
  • Administered Entra ID identity lifecycle — provisioning, deprovisioning, MFA enforcement
  • Built a Power Automate flow to automate MFA reset alerting to the security team, replacing a manual process

Endpoint Security & Containment

  • Administered BeyondTrust privileged access management — deployed agents, analyzed blocked-path logs to resolve access conflicts
  • Provisioned with CrowdStrike Falcon access to perform endpoint containment on managed laptops
  • Managed SentinelOne agent deployment/decommissioning; performed malware identification and removal (Malwarebytes) on compromised endpoints

First-Line Incident Response

  • Served as first-line incident responder across all security and IT events with no dedicated security team
  • Acted as primary IT/security resource during two separate MSP-to-in-house transitions
  • Contributed to SCCM → Intune migration, including enrollment/policy troubleshooting

Core Competencies

Email Threat Triage BEC Investigation Entra ID / Azure AD AD & Entra Log Analysis MFA Enforcement SentinelOne CrowdStrike Falcon BeyondTrust PAM Microsoft Intune Power Automate Phishing Simulation (Cofense) Incident Response MSP-to-In-House Transition

Professional Experience

// full chronological history
IT Systems Support Engineer
FreedomPay, Philadelphia, PA
Aug 2024 – Present
  • Triaged Proofpoint email quarantine alerts, validating flagged messages with end users and making release or block determinations to protect against phishing and malicious content.
  • Pulled and analyzed Active Directory and Azure Entra ID logs during access investigations to identify unauthorized access attempts and anomalous authentication activity.
  • Built a Power Automate flow to automate MFA reset notifications to the security team, replacing a manual email process and ensuring consistent alerting on every reset.
  • Administered BeyondTrust endpoint privilege management — deploying agents, troubleshooting permission issues, and analyzing blocked path logs to resolve access control conflicts.
  • Provisioned with CrowdStrike Falcon access to perform endpoint containment actions on managed laptops.
  • Contributed to SCCM to Microsoft Intune migration — performing device conversions, troubleshooting enrollment and policy issues, and documenting procedures for the transition.
  • Executed hands-on Windows device upgrades across 500+ global endpoints, handling coordination and knowledge base documentation throughout the initiative.
IT Service Desk Level 2 (Contract)
Century Therapeutics, Philadelphia, PA
Sept 2023 – Aug 2024
  • Managed SentinelOne endpoint agent deployments and decommissioning through the console across the organization.
  • Administered Azure AD / Entra ID identity lifecycle including user provisioning, deprovisioning, and MFA enforcement — serving as the primary IT resource during MSP-to-in-house IT transition.
IT Coordinator / Support Engineer
Qualitest, Remote
Feb 2023 – Aug 2023
  • Improved device recovery rates by 35% and achieved 100% on-time delivery by redesigning laptop and mobile device deployment processes across North America.
  • Implemented Power Automate workflows to reduce manual effort in device allocation and recovery, improving operational consistency and reducing error rates.
  • Reduced IT procurement costs by 10% through vendor selection improvements, increasing service quality for end users.
Senior IT Support Analyst
Mutual of Omaha Mortgage, San Diego, CA
Dec 2020 – Feb 2023
  • Investigated and remediated Business Email Compromise incidents — identifying and removing malicious inbox rules, resetting compromised credentials, and following Microsoft best practice remediation procedures.
  • Performed malware identification and removal on compromised endpoints using Malwarebytes, serving as the sole IT and security resource during transition from MSP to in-house IT operations.
  • Co-developed annual phishing simulation playbook using Cofense, designing campaign scenarios and testing cadence to measure and improve user threat detection capabilities.
  • Served as first-line incident responder across all security and IT events with no dedicated security team, independently triaging and resolving threats.

Education & Certifications

B.S. Computer & Network Security
Wilmington University · GPA 3.8
CompTIA Security+
Oct 2020
AWS Certified Cloud Practitioner
Jan 2026
Microsoft Azure Administrator (AZ-104)
In Progress · 2026