Summary
Overview
Work History
Education
Skills
Certification
Additional Training
Timeline
Generic

Tai-Shan Tracey

Kingston

Summary

Security professional with 8+ years of experience in IT and cybersecurity, with deep expertise in incident response, threat detection, and security assessments across hybrid and SaaS environments. Proven track record in leading enterprise-wide monitoring initiatives, designing and executing response plans, and driving remediation efforts in collaboration with legal, executive, and technical stakeholders. Skilled in applying threat intelligence, log analysis, and risk-based controls to strengthen organizational security posture.

Overview

10
10
years of professional experience
1
1
Certification

Work History

Application Security Specialist

KPMG JESS
09.2024 - Current
  • Lead over 20 security reviews for on-prem, SaaS, and PaaS applications using a NIST-CSF-adapted baseline.
  • Evaluated controls around access, logging, secure coding, patching, and vulnerability management.
  • Prioritized remediation based on PII/PHI sensitivity, exposure, and risk severity.
  • Coordinate with developers, architects and risk teams to ensure timely remediation of identified security gaps and alignment with business objectives.
  • Tracked risks using Archer and Microsoft Planner.
  • Influenced architectural changes after discovering missing TDE in high-criticality application.

IT Security Specialist

RJRGLEANER Communications Group
09.2021 - 08.2024
  • Conducted daily IOC sweeps (IPs/domains/hashes) tied to phishing and password spray attempts.
  • Used VirusTotal and Cisco Talos for IOC validation; escalated findings to CTO.
  • Analyzed payloads in malicious emails to extract hashes.
  • Reported IOC trends to support threat hunt prioritization.
  • Monitored external intel sources (BleepingComputer, CISA, CyberWire, JA CIRT, Alienvault OTX).
  • Ran regular endpoint/network vulnerability scans; ensured appliance patching.
  • Produced metrics: incident counts, blocked threats, top targeted users.
  • Deployed geo-IP blocking to reduce spray attack rates.
  • Delivered monthly C-suite reports on security posture and IR readiness.
  • Managed 2-person team for executive device hardening (EDR, MFA, naming).
  • Led 6-person project for org-wide MFA deployment in response to credential threats.
  • Led IR investigations with Legal; authored formal reports and built IR policy.
  • Deployed and tuned Darktrace across network, SaaS, email; created autonomous detection workflows.
  • Developed and maintained the 24/7 Incident Response Plan for a hybrid environment, including operational processes aligned to risk and compliance.
  • Created and updated playbooks for consistent response across key incident types.
  • Led monitoring and detection efforts across the full attack surface using a range of security tools.
  • Built automated workflows to trigger incident alerts and escalate based on risk levels.
  • Trained technical teams on roles and procedures to ensure readiness and swift response.

Telecom Engineer

Spectrum Management Authority
09.2017 - 08.2021
  • - Monitored firewall logs; supported secure network operations.

Radio Access Network Engineer

Digicel Jamaica
08.2015 - 08.2017
  • - Delivered stable telecom infrastructure and reliable RAN services.

Education

BSc. Electronics Engineering (Hons.) -

University of The West Indies
07.2015

Skills

  • Threat Intelligence
  • Incident Response
  • SIEM/SOAR (Darktrace)
  • KQL (query writing)
  • IOC Sweeps
  • External Threat Monitoring
  • Risk Reviews (NIST CSF)
  • Executive Dashboards
  • Archer GRC
  • VirusTotal, Cisco Talos, SOCRadar

Certification

  • Microsoft AI 900: Azure Fundamentals (2025)
  • Microsoft SC-200: Security Operations Analyst (2023)
  • CompTIA CySA+ (2022)
  • ISC2 SSCP (2021)
  • Scrum Master (2021)
  • Azure Fundamentals (AZ-900, 2020)
  • CCNA (2019)

Additional Training

  • Practical Ethical Hacking (TCM)
  • SOC Level 1 (TryHackMe)
  • CCSP Prep (LinkedIn Learning)
  • Google Cloud Security (Pluralsight)
  • SSCP Exam Writer (ISC2)
  • Supervisory Management (UCC)

Timeline

Application Security Specialist

KPMG JESS
09.2024 - Current

IT Security Specialist

RJRGLEANER Communications Group
09.2021 - 08.2024

Telecom Engineer

Spectrum Management Authority
09.2017 - 08.2021

Radio Access Network Engineer

Digicel Jamaica
08.2015 - 08.2017

BSc. Electronics Engineering (Hons.) -

University of The West Indies
Tai-Shan Tracey