$ whoami

Anthony Jucha

Cybersecurity professional specializing in threat hunting, incident response, vulnerability management, and NFC security research. THOTCON speaker. Huntress CTF top 100.

Security+ ISC2 CC THOTCON Speaker Huntress CTF Top 100 Open to Work
GitHub → LinkedIn →
scroll ↓
01

About

Cybersecurity professional with hands-on experience in threat hunting, incident response, vulnerability management, penetration testing, phishing simulation, and MDR monitoring.

Currently functioning as an IT Support Specialist, Level 1 and ad hoc Cybersecurity Analyst within a K-8 school district, having built trust with senior security leadership through demonstrated competence and initiative.

Published NFC security researcher, THOTCON 0xD speaker, self-hosted homelab operator with enterprise-grade network segmentation and SIEM monitoring, and Huntress CTF top 100 finisher.

Previously spent 6 years in finance and operations roles at ALDI USA (Fortune 50), American National, and the US Dept. of the Navy — bringing a rare blend of security acumen and business process optimization.

skills.sh
$ cat core_competencies.txt
Threat Hunting & Detection
Incident Response
Vulnerability Management
Penetration Testing
SIEM & Security Monitoring (Wazuh)
MDR Operations (Sophos)
Phishing Simulation (KnowBe4)
MITRE ATT&CK Framework
Network Segmentation & VLANs
NFC/RFID Security Research
$ echo "Ready to defend."
$ _
02

Experience

IT Support Specialist, Level 1 | Ad Hoc Cybersecurity Analyst

Community Consolidated School District 15 · Nov 2024 – Present
  • Spearheaded business case, acquisition, and deployment of Horizon3 NodeZero autonomous penetration testing platform
  • Designed KnowBe4 phishing campaigns with custom Extreme/Hard templates; integrated with NodeZero to map credential exposure blast radius
  • Monitor and triage Sophos Central MDR events, delivering response recommendations to Sr. Network & Security leadership
  • Perform threat hunting, IR, and vulnerability management beyond formal scope across multi-site K-8 environment
  • Manage Active Directory, Google Admin Console, SSO/MFA, and endpoint security via SCCM across district devices

Treasury Specialist

ALDI USA (Fortune 50) · May 2023 – Aug 2024
  • Engineered automated journal entry workflow using Excel VBA/Macros, cutting processing time 92%
  • Built cross-workbook reconciliation logic to detect anomalies in billing data and recover duplicate payments

IT Expense Analyst

American National · Feb 2022 – May 2023
  • Audited and reconciled vendor billing data to identify $10K in overpayments
  • Designed centralized tracking system to strengthen internal controls and audit readiness

Financial Management Analyst

Navy Region Mid-Atlantic (US Dept. of the Navy) · Jun 2019 – Mar 2021
  • Consolidated budget data across 56 programs and 8 source reports, saving 10 hours of computation time at 100% accuracy
03

Research & Speaking

THOTCON Talk

Driving Range Vulnerability — MIFARE Classic Exploited

THOTCON 0xD · May 2025 · Chicago, IL

Original research on MIFARE Classic 1K NFC vulnerabilities. Covered cryptographic key recovery, local data manipulation, and UID spoofing across two rounds of on-site testing. Formalized findings in a peer-accessible whitepaper.

Homelab & CTF

Homelab & CTF Operations

Self-Directed · Ongoing

Self-hosted Proxmox VE homelab running Wazuh SIEM/XDR with Docker-orchestrated services. Achieved top 100 finish in the annual Huntress CTF across forensics, malware analysis, and web exploitation.

04

Articles

05

CTF Writeups

Operation Breadcrumbs

TCM Security CTF

Multi-stage web exploitation challenge chaining HTTP header analysis, IDOR enumeration, Gzip decoding, EXIF metadata extraction, steganography, and XOR cryptanalysis to recover the final flag.

Huntress CTF

Top 100 Finish

Annual Huntress Capture the Flag competition. Competed across forensics, malware analysis, reverse engineering, and web exploitation categories to achieve a top 100 placement.

06

Lab & Infrastructure

Self-hosted, segmented, and monitored. Everything runs on bare metal in a dedicated rack with full network isolation and logging.

Firewall & Routing

Protectli VP2420 running OPNsense with custom firewall rules, IDS/IPS, and multi-WAN failover. Handles all inter-VLAN routing and egress filtering.

Switching

Ubiquiti USW-24-G2 (Layer 2) + Cisco 24-port switch. VLAN trunking, port isolation, and PoE for cameras and access points.

Wireless

Ubiquiti UniFi AP with SSID-to-VLAN mapping. Separate broadcast domains for enterprise users, IoT devices, and guest access.

Network Segmentation

Four dedicated VLANs: Enterprise (staff/lab), Cameras (isolated NVR stream), IoT (smart devices with egress restrictions), and Guest (captive portal, no LAN access).

Virtualization

HP DL360p Gen8 running Proxmox VE. LXC containers for Docker workloads, dedicated VMs for NVR (Frigate + Coral TPU), and isolated service tiers.

Security Stack

Wazuh SIEM/XDR for endpoint detection and log correlation. Cloudflared tunnels for secure external access. Portainer + Watchtower for container orchestration and automated updates.

07

Certifications