I’m Catherine Jason, an IT and cybersecurity professional who works in security-minded environments and enjoys solving problems that help keep systems stable and protected. I support technology operations for a 42-school district, where I handle identity changes, review endpoint activity, and help maintain secure setups across thousands of devices. My work gives me steady exposure to real alerts, user behavior, and the day-to-day patterns that matter in security.
I’ve built a strong technical foundation through hands-on networking, Windows and Linux administration, and the security work I do in my home lab. I spend a lot of time analyzing logs, testing network behavior, and practicing forensic techniques so I can understand how issues start and how they move through a system. I like breaking things down, checking what’s normal, and spotting the details that don’t fit.
I’m committed to growing in cybersecurity and staying ahead of where the field is going. I hold Security+ and SOCOA I, and I’m currently working toward CompTIA Security AI+ to strengthen my understanding of AI-driven threats and defensive automation. I’m also completing my AAS in Cybersecurity, which helps me expand my skills and stay sharp through structured labs and coursework.
My goal is to move deeper into security operations and incident response, where I can apply what I’ve learned, keep improving, and contribute to a team that values strong analytical thinking and steady growth.
Carroll County Public Schools, Westminster, MD · Aug 2026 to Present
Manage user account lifecycle tasks including access updates and group assignments using least privilege practices.
Review endpoint and system activity with Microsoft Defender alerts to support early detection of potential security concerns.
Provide remote support for staff devices using Quick Assist and Microsoft management tools.
Support district technology operations across 43 school sites, including MFA resets, account lockouts, and password recovery through Active Directory and user management systems.
Maintain endpoint security posture through update and compliance workflows in Dell Command Update, Company Portal, and Software Center.
Operate in an environment aligned with NIST SP 800-53 and Maryland DoIT security standards.
Carroll County Public Schools, Westminster, MD · Summer 2026
Imaged and configured over 6,000 student devices and 45 staff systems across 42 school sites for the district one-to-one rollout.
Applied Windows security updates using Dell Command Update, SCCM for staff endpoints, and Intune Company Portal for student devices.
Executed and verified backup and restore checks to support disaster recovery readiness.
Managed secure end-of-life device transitions including wipe workflows, staging, and site-level inventory tracking.
Reimaged more than 1,000 systems with updated Intune policies and district security settings, then completed compliance validation on each device.
Sykesville, Maryland · 2024 to Present
Provide part-time remote IT and cybersecurity support for a small business across Windows and macOS systems.
Use Quick Assist, Remote Desktop, macOS Screen Sharing, AnyDesk, and TeamViewer to resolve access issues, performance problems, and suspected security events.
Guide clients through remediation for account issues, configuration changes, and system recovery tasks.
Assist with secure setup and baseline hardening during live troubleshooting sessions.
Linux (Ubuntu) GUI & command-line administration
Windows Server
Active Directory & Group Policy
Permissions & access control
Enterprise endpoint management (Company Portal, Software Center)
Windows patch management (Dell Command | Update)
Cisco Catalyst switching (2950, 2960 Plus, 3560G)
Cisco 4331 ISR router configuration
VLANs & routing fundamentals
Traffic analysis & baselining (Wireshark)
Log analysis & event correlation
SIEM familiarity (Splunk)
Alert triage & escalation concepts
Incident response lifecycle (entry-level)
Intrusion detection concepts
SNORT
Signature vs anomaly awareness
Monitoring workflows
Kali Linux (controlled lab environments)
Parrot Security OS (controlled lab environments)
Security tooling platform familiarity
Evidence handling & documentation
Disk imaging & artifact awareness
Chain-of-custody principles
FTK Imager, OSForensics, E3 Forensic Platform, ProDiscover
• Log analysis for authentication events, endpoint alerts, and system activity
• Incident triage to separate false positives from real security events
• IOC identification and pattern recognition across hosts and network sources
• Endpoint defense monitoring using Microsoft Defender and host-level behavior analysis
• Threat behavior understanding and mapping how attacks unfold across systems
• SIEM workflows including event correlation and cross-system investigation
CompTIA Security+
SOC Operations Analyst I (SOCOA I)
CompTIA Security AI+ (In Progress)
AAS in Cybersecurity, Carroll Community College (In Progress)
Cybersecurity & Security Pro+ Certificate, Carroll Community College
Academic and lab projects built around applied IT and security skills in real-world scenarios.
Designed and built a segmented lab network using Cisco Catalyst switches and an ISR router.
Configured VLANs, routing, NAT, and DHCP, and used Wireshark to analyze and baseline traffic behavior.
Validated network operation through packet inspection and controlled traffic testing scenarios.
Administered Linux and Windows Server environments in structured lab settings.
Managed Ubuntu Server using both GUI and command-line tools, covering user administration, permissions, and service management.
Configured Active Directory, Group Policy, and role-based access controls following least-privilege principles.
Conducted structured digital forensics investigations using industry-standard tools.
Performed forensic imaging and analyzed system artifacts, registry data, and file metadata to surface evidence.
Documented all findings in accordance with evidence integrity requirements and chain-of-custody procedures.
Analyzed system and authentication logs to surface suspicious activity and behavioral patterns.
Used SIEM tooling to correlate security events and work through structured alert triage workflows.
Applied incident response concepts to assess alert severity and determine appropriate escalation paths.
Feel free to reach out through either of the platforms below:
I'm always open to connecting with cybersecurity and IT professionals to exchange ideas, learn from different perspectives, and explore where I might be a good fit.