Home About Projects YouTube Coursework Skills Contact
Cybersecurity Portfolio

Quinton
Anding

BBA Risk Management · CompTIA Security+ · CySA+ · GRC & SOC Analyst

Security+ CySA+ GRC SOC Analysis DFW Based

Business Meets
Security

December 2025 University of Texas at Arlington graduate with a BBA in Risk Management and a cybersecurity focus. I hold CompTIA Security+ and CySA+ certifications and am pursuing entry-level GRC Analyst, Security Analyst, and Risk Analyst roles in the DFW area. My background bridging business administration with hands-on security operations lets me translate technical risk into business language.

University of Texas at Arlington

Bachelor of Business Administration — Risk Management · Focus: Cybersecurity
Graduated December 2025


Certifications

CompTIA Security+  ·  CompTIA CySA+ (CSAP Stackable)

CyberVibeCheck Lab Series

10 hands-on cybersecurity projects built and documented for the CyberVibeCheck YouTube channel

Lab 01 · Monitoring & Alerting

How to Monitor Network Availability with Uptime Kuma

Deploy a real-time uptime dashboard to monitor internal and external asset health. Configure automated Discord alerts so you know the second anything goes down — before your users do.

Analyst Tie-In

Proactive monitoring is the foundation of every SOC. This is how Tier 1 analysts know an incident happened before the helpdesk phones start ringing.

Key Steps
1

Launch Uptime Kuma via Docker: docker run -d --restart=always -p 3001:3001 -v uptime-kuma:/app/data louislam/uptime-kuma:1

2

Access the UI at http://localhost:3001 and create your first monitors

3

Configure Ping + HTTP(s) monitors for gateway and portfolio site

4

Integrate Discord Webhooks for automated incident alerting

DockerUptime KumaDiscord WebhooksNetwork Monitoring
Live Demo
99.9%
Uptime Tracked
/ Real-time Dashboard / Discord Alerts / Incident Detection
Lab 02 · Deception Technology

How to Catch Hackers with Canary Tokens

Create digital tripwires that alert you the moment an attacker touches a file — including their IP, OS, and timestamp — without them ever knowing.

Analyst Tie-In

Deception technology is used by enterprise SOC teams at scale. Understanding it makes you stand out from candidates who only know detection — not deception.

Key Steps
1

Navigate to CanaryTokens.org and select "MS Word Document" as the token type

2

Provide a Discord webhook URL and a convincing label (e.g., "Q4_Salary_Review_Confidential.docx")

3

Download the token file and "leak" it onto a desktop or USB drive

4

Open the file and watch the real-time alert fire with IP and OS data captured

CanaryTokens.orgDiscord WebhooksDeception TechThreat Detection
Live Alert
<2s
Alert Fire Time
/ IP Capture / OS Detection / Zero-Cost Tripwire
Lab 03 · Threat Intelligence

How to Perform OSINT on a Suspicious Domain

Investigate a malicious website without ever visiting it. Map an attacker's full infrastructure — IP history, redirect chains, sibling domains — in under 5 minutes.

Analyst Tie-In

At Tier 1 in a SOC, you triage 50–100 phishing URLs per shift. This passive OSINT workflow is the playbook. Knowing it cold is table stakes for the role.

Key Steps
1

Pull a confirmed phishing URL from PhishTank — never visit suspicious links directly

2

Paste into URLScan.io and analyze sandboxed screenshot, IP, redirect chain, and technologies

3

Search the domain on VirusTotal — check Detection, Relations, and Community tabs

4

Use WHOIS to find registration dates, registrar, and contact info patterns

URLScan.ioVirusTotalWHOISPassive Recon
OSINT
70+
AV Engines Checked
/ No Direct Contact / Infrastructure Mapping / PhishTank Feed
Lab 04 · Cloud Security

How to Audit Cloud Security with ScoutSuite

Scan an AWS environment for open S3 buckets, weak IAM policies, and misconfigured security groups using a read-only automated audit — no destructive actions.

Analyst Tie-In

Cloud misconfiguration is the #1 cause of data breaches. AWS and Azure security skills add 20–40% to a Security Analyst's salary. This is where the money is.

Key Steps
1

Create IAM user "scoutsuite-auditor" with SecurityAudit + ReadOnlyAccess policies

2

Install ScoutSuite: pip install scoutsuite

3

Configure credentials via aws configure then run scout aws

4

Review HTML report for Danger-level findings: open S3, root account keys, no MFA

ScoutSuiteAWS Free TierIAMCloud Security
Cloud Audit
AWS
Free Tier · Read Only
/ S3 Misconfiguration / IAM Policy Gaps / Automated Report
Lab 05 · GRC

How to Build a Risk Assessment Heat Map

Translate scary tech vulnerabilities into business language that executives understand. Build a color-coded 5×5 risk matrix in Google Sheets that quantifies and prioritizes organizational risk.

Analyst Tie-In

This is the deliverable you hand to a CISO or Board of Directors. Grounded in NIST SP 800-30 and ISO 27005.

Key Steps
1

Create columns: Asset, Threat, Impact (1–5), Likelihood (1–5), Risk Score

2

Input 5+ realistic scenarios: Ransomware, Insider Threat, Phishing, Data Center Fire, Vendor Breach

3

Add formula =C2*D2 for Risk Score and IF formula for risk level labels

4

Conditional formatting: Red (16–25), Yellow (10–15), Green (1–9) plus 5×5 visual matrix

Google SheetsNIST SP 800-30Risk ScoringGRC
GRC Deliverable
5×5
Risk Matrix
/ Likelihood × Impact / Color-Coded Risk / Executive Ready
Lab 06 · Phishing Analysis

How to Analyze Email Headers for Phishing

Find where a fake email actually came from. Deconstruct raw email headers to trace the originating IP, validate SPF/DKIM/DMARC records, and expose spoofed sender infrastructure.

Analyst Tie-In

This is the #1 daily task for Junior Security Analysts. You triage 50–100 phishing reports per shift at Tier 1. Knowing this cold is table stakes.

Key Steps
1

Open suspected phishing email in Gmail → 3-dot menu → Show original

2

Paste raw headers into Google Admin Toolbox MessageHeader analyzer

3

Analyze Authentication-Results for SPF, DKIM, and DMARC pass/fail status

4

Locate X-Originating-IP and run through MXToolbox blacklist check

Google Admin ToolboxMXToolboxSPF / DKIM / DMARCPhishing Triage
Email Forensics
3
Auth Records Decoded
/ SPF Check / DKIM Validation / DMARC Policy
Lab 07 · Malware Analysis

How to Identify Malicious Files Without Running Them

Never open a suspicious file to find out if it's safe. Use cryptographic hashing to generate a unique file fingerprint and match it against a global threat database — in under 60 seconds.

Analyst Tie-In

File hashing is standard in every IR playbook — it instantly tells you if you're dealing with known commodity malware or something novel to escalate.

Key Steps
1

Generate MD5: md5 ~/Downloads/filename

2

Generate SHA-256: shasum -a 256 ~/Downloads/filename

3

Paste SHA-256 hash into VirusTotal Search tab and review detection results

4

Look up a known malware hash from abuse.ch MalwareBazaar for a live positive detection

macOS TerminalSHA-256VirusTotalMalwareBazaar
Static Analysis
72
AV Engines · Zero Execution
/ MD5 + SHA-256 / No File Execution / Threat DB Lookup
Lab 08 · Application Security

How to Scan Web Vulnerabilities with OWASP ZAP

Find SQL injection and XSS vulnerabilities in a legal test environment. Run a full automated scan, analyze findings by severity, and generate a professional remediation report.

Analyst Tie-In

AppSec is one of the fastest-growing career paths in security. Bug bounty programs on HackerOne pay real money for exactly these findings.

Key Steps
1

Download and install OWASP ZAP from zaproxy.org

2

Use Automated Scan against a legal target: testphp.vulnweb.com

3

Review Alerts tab — filter by High severity first (SQL Injection, XSS)

4

Export HTML report with findings, request/response evidence, and remediation steps

OWASP ZAPSQL InjectionXSSAppSec
Vuln Scan
OWASP
Top 10 · Legal Target
/ SQL Injection / XSS Detection / Remediation Report
Lab 09 · Privacy & Compliance

How to Create a Data Privacy Impact Assessment (DPIA)

Build the compliance document required before any product touching personal data goes live. Map data flows, assign legal basis under GDPR/CCPA, score privacy risks, and define controls.

Analyst Tie-In

Meta was fined $1.3B for GDPR violations. Amazon, $746M. The analyst who understands both security controls AND regulatory requirements gets promoted.

Key Steps
1

Draft sections: System Description, Data Inventory, Legal Basis, Risk Assessment, Controls, Residual Risks, Sign-off

2

Apply template to a "Pizza Delivery App" — map every data type to its GDPR legal basis

3

Score each data type by Likelihood and Impact — color code Critical, High, Medium, Low

4

Identify residual risks and assign corrective actions with owners and due dates

GDPR Art. 35CCPAPrivacy by DesignGRC
Compliance Doc
7
Sections · GDPR Compliant
/ Data Inventory / Legal Basis Mapping / Risk Assessment
Lab 10 · Communication Skills

How to Write an Executive Incident Report

Take a real incident — portfolio site down for 4m 13s — and turn it into the one-page report you'd hand to a CISO. Root cause, business impact, corrective actions. No jargon.

Analyst Tie-In

Technical skills get you the interview. Communication skills get you the offer. This proves you can explain a breach to someone who's never heard of a TLS handshake.

Key Steps
1

Document the real incident: portfolio site TLS failure detected by Uptime Kuma — April 29, 2026

2

Write a 3–4 sentence Executive Summary: what, when, impact, status

3

Build a timeline table with exact timestamps and run the 5 Whys for root cause

4

Create corrective action table: task, owner, due date, status — no "be more careful"

Uptime Kuma5 Whys RCAExecutive ReportingIncident Response
Real Incident
1 pg
CEO-Ready Report
/ 4m 13s Outage Documented / 5 Whys RCA / Corrective Actions

CyberVibeCheck YouTube

Breaking down complex cybersecurity concepts into hands-on, actionable projects — from the homelab to the terminal

All 10 Lab Videos — Click to Play
Lab 01 · Click to Play
Lab 01 · Monitoring

How to Monitor Network Availability with Uptime Kuma

Deploy a real-time uptime dashboard. Configure Discord alerts so you know before your users do.

Lab 02 · Click to Play
Lab 02 · Deception Tech

How to Catch Hackers with Canary Tokens

Create digital tripwires — watch the Discord alert fire live with attacker IP and OS.

Lab 03 · Click to Play
Lab 03 · Threat Intel

How to Perform OSINT on a Suspicious Domain

Map an attacker's full infrastructure in under 5 minutes — without touching the target.

Lab 04 · Click to Play
Lab 04 · Cloud Security

How to Audit Cloud Security with ScoutSuite

Scan AWS for open S3 buckets, weak IAM policies, and misconfigured security groups.

Lab 05 · Click to Play
Lab 05 · GRC

How to Build a Risk Assessment Heat Map

Translate tech vulnerabilities into business language — the 5×5 risk matrix execs actually read.

Lab 06 · Click to Play
Lab 06 · Phishing

How to Analyze Email Headers for Phishing

Trace originating IPs and validate SPF/DKIM/DMARC — the Tier 1 analyst daily workflow.

Lab 07 · Click to Play
Lab 07 · Malware

How to Identify Malicious Files Without Running Them

Cryptographic hashing + VirusTotal: 72 AV engines checked, zero file execution.

Lab 08 · Click to Play
Lab 08 · AppSec

How to Scan Web Vulnerabilities with OWASP ZAP

Find SQL injection and XSS on a legal target — then write the remediation report.

Lab 09 · Click to Play
Lab 09 · Privacy

How to Create a Data Privacy Impact Assessment (DPIA)

Build the GDPR-required compliance doc from scratch — 7 sections, legal basis mapped.

Lab 10 · Click to Play
Lab 10 · Communication

How to Write an Executive Incident Report

Turn a real 4m 13s outage into the one-pager a CISO hands to the Board.

Education & Coursework

University coursework, certifications, and the self-directed study that built the skillset

Bachelor of Business Administration
Risk Management

Cybersecurity focus · College of Business · Graduated December 2025
Arlington, TX  ·  DFW Area

Credentials

Certifications

Industry-recognized credentials validating hands-on security knowledge

🔐
CompTIA Security+ SY0-701 · Foundation security certification
✓ Active
🔍
CompTIA CySA+ CS0-003 · CSAP Stackable · Threat detection & response
✓ Active
☁️
AWS Cloud Practitioner CLF-C02 · In progress
In Progress
Academic Foundation

Core BBA Coursework

Risk Management & Cybersecurity track, College of Business · UTA

  • Enterprise Risk Management & Insurance
  • Information Security Risk Management
  • Business Continuity & Disaster Recovery
  • Corporate Finance & Financial Analysis
  • Business Law & Regulatory Compliance
  • Operations Management & Supply Chain Risk
  • Organizational Behavior & Leadership
  • Business Communications & Professional Writing
Technical Track

Cybersecurity Coursework

Hands-on courses bridging technical operations with business context

  • Network Security Fundamentals (TCP/IP, firewalls, VPNs)
  • Cybersecurity Governance, Risk & Compliance (GRC)
  • Security Operations Center (SOC) Concepts
  • Digital Forensics & Incident Response
  • Cloud Security Architecture (AWS focus)
  • Application Security & OWASP Top 10
  • Privacy Law & Data Protection (GDPR, CCPA)
  • Ethical Hacking & Vulnerability Assessment
Homelab & Self-Study

Hands-On Learning Path

Beyond the classroom — building and breaking things in a real homelab environment

2023
Homelab Build — Proxmox VE
Set up a bare-metal hypervisor running VMs for security testing: pfSense, Kali Linux, Windows Server, Ubuntu
2024
CompTIA Security+ Certification
300+ hours of study including Professor Messer, Jason Dion practice exams, and hands-on labs
2025
CompTIA CySA+ & UTA Graduation
Advanced to CSAP stackable certification. Deployed Wazuh SIEM, OPNsense firewall, and WireGuard VPN
2026
CyberVibeCheck — 10-Lab Series
Launched YouTube channel documenting real-world security projects: monitoring, deception tech, cloud auditing, GRC, incident reporting

Technical Skills

Developed through hands-on lab work, certification study, and real-world homelab infrastructure

🌐

Network & Infrastructure

OPNsense Firewall · Proxmox VE
WireGuard VPN · Pi-hole DNS
Wazuh SIEM · Uptime Kuma
TCP/IP · Network Monitoring
🔒

Security Operations

Threat Intelligence · OSINT
Phishing Analysis · File Hashing
Vulnerability Scanning · SIEM
Incident Response · Log Analysis
📋

GRC & Compliance

GDPR / CCPA · NIST Frameworks
Risk Heat Maps · DPIA Writing
Executive Reporting · Policy Docs
ISO 27001 Concepts · Audit Prep
☁️

Cloud & Tools

AWS (IAM, S3, EC2) · ScoutSuite
Docker · Python · GitHub Pages
OWASP ZAP · VirusTotal
CanaryTokens · URLScan.io

Let's Connect

Open to GRC Analyst, Security Analyst, and Risk Analyst roles in the DFW area.