Carlos Colón
AeroLeads people directory · profile

Carlos Colón Email & Phone Number

Cloud Incident Response operations and manager at Lockheed Martin
Location: Kissimmee, Florida, United States 9 work roles 4 schools
LinkedIn matched
✓ Verified July 2026 3 data sources Profile completeness 86%

Contact Signals

LinkedIn Profile matched
3 free lookups remaining · No credit card
Current company
Role
Cloud Incident Response operations and manager
Location
Kissimmee, Florida, United States

Who is Carlos Colón? Overview

A concise factual answer block for searchers comparing this professional profile.

Quick answer

Carlos Colón is listed as Cloud Incident Response operations and manager at Lockheed Martin, based in Kissimmee, Florida, United States. AeroLeads shows a matched LinkedIn profile for Carlos Colón.

Carlos Colón previously worked as Cloud Incident Response Manager/Lead at Lockheed Martin and SIEM Engineer and Threat Hunter at Unisys. Carlos Colón holds M.S., Cyber Security from Webster University.

Company email context

Email format at Lockheed Martin

This section adds company-level context without repeating Carlos Colón's masked contact details.

Lockheed Martin

Review company-level records connected to Carlos Colón before choosing the right outreach path.

Profile bio

About Carlos Colón

With over a decade of experience as a Cyber Security Engineer, I have sharpened my expertise in offensive techniques, cyber threat hunting, and the Risk Management Framework (RMF). Safeguarding Government and public information using prescribed standards, techniques, and tactics. Currently, I manage a dynamic Security Operations Center (SOC) team of 8-12 skilled incident response professionals. My role involve orchestrating security strategies, defense mechanisms, and mitigating cyber threats to safeguard critical assets. Good understanding of the security involved in Cloud and hybrid systems vs. traditional on premise system. Also, can prescribe security measures for Government systems just as well as the civilian sector. Great advocate of training, leading, and collaboration up the chain and back down. It is truly important my team understands the main goal and vision well enough to manage and lead a team to success.

Current workplace

Carlos Colón's current company

Company context helps verify the profile and gives searchers a useful next step.

Lockheed Martin
Lockheed Martin
Cloud Incident Response operations and manager
AeroLeads page
9 roles

Carlos Colón work experience

A career timeline built from the work history available for this profile.

Cloud Incident Response Operations And Manager

Kissimmee, Fl, Us

Cloud Incident Response Manager/Lead

Bethesda, Md, Us

Threat Hunter: Detecting tools like Netcat, Evasion techniques, Standard Exploitation tools like Meterpreter, initial access and pivoting maneuvers, Malware analysis (static vs. dynamic), Log investigations, Scanning techniques and mapping, Web Attacks and procedures, Reconnaissance (DNS, ports, IPs, IAM, ), Password attacks/techniques, Exploitation (initial access), Command and control detection, Payloads, Windows and Linux Situational Awareness, WMIC, Cloud: Detection of Host discovery and active reconnaissance, limitations on Cloud infrastructures, Mass IP scanning vs. targeted scanning, Vulnerability scanning internally, Authentication types and key material, AWS/Azure IAM, Azure infrastructure, AWS infrastructure, Entra ID/Cognito, Microsoft Graph, File/Storage system, CLI tools and usage, Red team operations and preparation, Containers (native, dockers, Kubernetes) vulnerabilities, Container Backdoors, Terraform Vulnerabilities, Control Plane vs. Data plane vs. Mission Plane, Deployment Pipeline vulnerabilities, MiTTRE ATTACK (Cloud Matrix), Serverless functions, database exposure, Cloud Priv/lateral escalation, VM/Computer vulnerabilities, permissions and roles based attacks. Operating Systems: Cisco, Linux, Windows, Palo Alto, Logic controllers. Tools: SolarWinds, ePO, trellis, SIEM (Sentinel and Splunk), Entra ID, Eyewitness, NMAP/Massan, sliver, Empire, Kali Linux, Socat, Azure/AWS ClI Tools. Python/PowerShell, CI/ID code analysis.

Siem Engineer And Threat Hunter

Blue Bell, Pennsylvania, Us

Security Operations Center: Incident response alerts vs. threshold, Permissions Structure, KQL and SPL proficiency, Construct Data Models and tagging system, reduce alerts fatigue and noise, Parsing structured vs unstructured data based on required architecture means, MITTRE ATTACK reference, Cyber Kill Chain Process, Regex Capture, Asset, Application, and user health monitoring, create easy to use visualizations for leadership, analyst, and incident responder. Understand Vulnerabilities and their management, Research and development on required specifics, correlate and build Security tools to work in conjunction with SIEM, SOAR and Sentinel Runbook, design and lead security structure for programs/information system, understanding projects against resource management/budgets, help analyst understand data, bridge the gap between analyst, tools, automation, and policy. Automation. Aggregate and collect information based on a single incident. i.e., collect all alerts that may be related to an incident. Provide proper visualization for Audits and assessments. Provide networking team with real time analysis and alerts of informational logs processed by networking devices. Form unstructured data into easy-to-use information for lower tier individuals to understand. Search for random information audits or specifications on the entire system regarding outside or insider risk. i.e., formulate an IP expression and provide conditions to proper IP traffic versus approved Ip ranges.

Jun 2022 - Feb 2023

Information Assurance Analyst (Cyber Security)

Falls Church, Va, Us

Threat Hunting: Identify Security incidents, Search for gaps and constraints in Security System Architecture, Provide analysis to leverage Security vs. production, Monitor Network traffic through Syslog ingestion, Monitor endpoints, applications, and System activity, understanding Architecture policy and regulations, Understand program Operations and Development, Understand Trends in private and public sector, Understand Application/hardware behavior, understand user/developer behavior, testing alerts and their effectiveness, Development: Build Splunk Dashboards and Panels, Capture triggers against policy and regulations, build queries capturing Techniques, Tactics, and procedures. Ensure SIEM platform is aligned with specific needs (insider threat, Cloud Matrix, Standard Framework), understand expected anomalies vs. unusual anomalies, SolarWinds Monitoring, Train and maintain Security Awareness training for general/Priv users, prepare mitigation and Security plan for specific tactics and techniques, build resilience between internal and external (perimeter vs. internal) system, yearly review of assets, hardware, software, and required capabilities. Understanding thresholds for malicious activities, dashboard automation.Security Tools: Sentinel, Splunk, McAfee, Tenable Security Center, Panorama, SolarWinds, ePO, python/PowerShell scripting.

Aug 2020 - Feb 2023

Principal Information Assurance Analyst (Cyber Security)

Falls Church, Va, Us

May 2022 - Jun 2022

Information System Security Risk Analyst

Bethesda, Md, Us

Build and maintain Risk Management Packages for Government and Local sectors: Provided System Security Plans, Architecture diagrams and Standard Operating Procedures, obtain and conserved Authorization to operate, Adhere to NIST 800-53 documentations and control consistently met annual goals and Plans of action, Operated JSIG rev 4 version, provided baseline and built security policy regulations per requirements, implemented and assessed security controls. Continuous Monitoring: Vulnerability search and management through Tenable Security center (ACAS, SCAP, STIGs), ComSec maintenance and operations, Configuration Change board approvals and assessments, monitoring latest threats and intel, Assured File transfers and procedures, System Disposal, Incident Response, Security analysis: Provided in depth mitigation plans, conducted security review against intel requirements, network traffic analysis through Wireshark, Splunk, and Elastic Search, User, hardware, software baseline and maintenance, Supply chain management.

Mar 2019 - Aug 2020

Cyber Warfare Operations (1B4X1)

Robins Afb, Ga, Us

Attended Air Force Cyber Warfare Operations course consisting of the following requirements. Linux comprehension: File system structure and management, Operating System distro, Unix/Linux, Basic Commands and CLI navigation. Permissions in linux, user and group management, and Linux networking, light shell scripting. Networking fundamental: Network architectures, Network Components, IPv4 vs IPv6, IP address and subnetting, Wireless Principles and protocols, Switching concepts, VLAN configurations, Cisco device managment (Telnet, SSH, HTTP, HTTPS, Console, Security settings), routing table and forwarding decisions, OSPF and other autonomous systems, Syslog, Key Security concepts, access control, password policies, VPNs structures, AAA system, WAN and LAN Security matters.Windows fundamental: Operating System Structure, Windows File System, Permissions management, Windows services, Processess, Task Manager, Security, Microsoft management Console, Subsystem for linux.Ethical Hacking: Understanding laws and ethics, enumerating and Open source intel, internal information gathering, information characteristics in computers, DNS footprinting, Scanning networks (masscan vs. nmap), Initial access, lateral and escalation attepmts, persistence, and exfiltration, malware analysis, evasion techniques (subsystem process vs. internal detection devices). General Topics: Analysis and reporting, communication network Security, Cyber law and Ethics, Intelligence, Reconnaissance, Programming Scripting (Python and Powershell), Public Key management,

Jun 2017 - Jun 2020

Low Observable Technician

Randolph Afb, Tx, Us

-Ensured careful planning to execute goals on long term projects (4-5months) while supervising a team and millions in assets.-Created, instructed, developed technical diagrams/blueprints to ensure quality completion.-Inspected and analyzed over 2.2 billion dollars in assets through accounting (Finance Analysis), time compliance, and physical asset for errors and operations enhancement.-Followed and upheld Environmental and safety regulations through Air Force, OSHA, and MSDS regulations.

Jan 2015 - May 2017

Air Traffic Controller

Randolph Afb, Tx, Us

-Strong verbal and written communication skills. -Concentration skills and situational awareness under any environment -Delivered and revised technical information for federal publications and training documents-Perform accurate and quick arithmetic, compute speed, time, and problems efficiently. Provide organized and timely information at all time while providing critical problem skill

Jun 2011 - May 2014
Team & coworkers

Colleagues at Lockheed Martin

Other employees you can reach at lockheedmartin.com. View company contacts →

4 education records

Carlos Colón education

M.S., Cyber Security

Webster University

Bachelor Of Arts - Ba, Homeland Security

American Military University

Associate Of Science - As, Airframe Mechanics And Aircraft Maintenance Stealth Technology/Technician

Community College Of The Air Force

Associate Of Science - As, Airway Science

Community College Of The Air Force
FAQ

Frequently asked questions about Carlos Colón

Quick answers generated from the profile data available on this page.

What company does Carlos Colón work for?

Carlos Colón works for Lockheed Martin.

What is Carlos Colón's role at Lockheed Martin?

Carlos Colón is listed as Cloud Incident Response operations and manager at Lockheed Martin.

Where is Carlos Colón based?

Carlos Colón is based in Kissimmee, Florida, United States while working with Lockheed Martin.

What companies has Carlos Colón worked for?

Carlos Colón has worked for Lockheed Martin, Unisys, Northrop Grumman, Us Air Force Reserve, and United States Air Force.

Who are Carlos Colón's colleagues at Lockheed Martin?

Carlos Colón's colleagues at Lockheed Martin include Justin Kerber, Byrl Getman, Karen Christensen-Grubb, Scott Meares, Cpa, and Cole Smith.

How can I contact Carlos Colón?

You can use AeroLeads to view verified contact signals for Carlos Colón at Lockheed Martin, including work email, phone, and LinkedIn data when available.

What schools did Carlos Colón attend?

Carlos Colón holds M.S., Cyber Security from Webster University.

Find 750M verified contacts

Search by job title, company, industry, location, and seniority. Export verified B2B contact data when you need it.