๐Ÿšซ Region Restricted

This page is only accessible from within Alberta or British Columbia.

Mark Augustus V. Funcion

Senior Cybersecurity Professional
๐Ÿ“ Edmonton, AB ยท Kamloops, BC
Professional Summary

Senior cybersecurity professional with 8+ years in security operations, incident response, and threat detection across regulated financial market infrastructure (DTCC), government, and managed security services. Works hands-on with SIEM/XDR detection and response, threat hunting, red and purple teaming, and vulnerability management, with a track record of maturing security programs, tuning detection, and validating controls against MITRE ATT&CK. Comfortable leading incident response end to end and turning complex risk into clear, executive-ready guidance, working across infrastructure, development, and leadership teams in compliance- and audit-driven environments.

Core Competencies
Security Operations (SOC) & Monitoring
Threat Detection & Hunting
Incident Response & Forensics
SIEM & XDR โ€” Sentinel / Splunk / QRadar
Red & Purple Teaming
Detection Engineering โ€” MITRE ATT&CK
Vulnerability Management & VAPT
Cloud Security โ€” Azure / AWS
Identity & Access Management
Security Tooling Optimization
Compliance & Audit โ€” NIST / PCI / RegSCI
Reporting & Stakeholder Briefings
Professional Experience
Senior Information Security Analyst
Mar 2026 โ€” Present
Thompson Rivers University โ€” Kamloops, BC
  • Run institutional security operations across a hybrid Azure and on-premises environment, covering SIEM monitoring, incident response, vulnerability management, and identity and access control
  • Monitor, investigate, and respond to security events spanning endpoint, identity, cloud, and network, and analyze logs and telemetry to determine scope, impact, and root cause
  • Maintain security policy, procedures, and audit-readiness documentation, and build security requirements into system design across the institution
  • Brief faculty, staff, and leadership on risk in plain terms and deliver security awareness programs
Senior Cybersecurity Consultant
Apr 2024 โ€” Apr 2025
SRG Consulting โ€” Government of Saskatchewan
  • Led cybersecurity strategy and implementation across multiple government entities, ensuring compliance with internal policies and international standards including NIST, OWASP, and PCI DSS
  • Designed, launched, and operationalized the province's Cyber Red Team Program, establishing a proactive adversarial-simulation and defense capability
  • Integrated security validation into the GoS-CSRM five-year plan โ€” application/network validation (DevOps), threat-based validation, and security-tool/vulnerability-assessment validation
  • Conducted enterprise-wide risk and vulnerability assessments with prioritized remediation, and reported posture, incident trends, and metrics to senior leadership
Senior Security Associate, Escalations Team Lead
Jul 2018 โ€” Jan 2024
Depository Trust & Clearing Corporation (DTCC) โ€” Manila
  • Led escalations and incident response per SLA at a SEC-regulated financial market infrastructure โ€” validation, investigation, containment, remediation, and post-incident analysis
  • Served as RegSCI Assets Program Lead, owning SEC compliance artifacts for the design, testing, and maintenance of IT controls covering capacity, integrity, resiliency, availability, and security
  • Built and ran a Purple Teaming Lab (VMware vSphere, QRadar, CrowdStrike, Pentera, Caldera) and an off-hours attack-emulation program measuring the MSSP (ReliaQuest) on MTTI, MTTD, and playbook fidelity
  • Performed regular VAPT using NIST CSF and MITRE ATT&CK, delivering findings, severity matrices, and remediation steps
Lead Linux Infrastructure Engineer
Jan 2017 โ€” Jul 2018
Depository Trust & Clearing Corporation (DTCC) โ€” Manila
  • Led a team of Linux engineers with task assignment, SLA coordination, and mentorship โ€” first formal people-management role
  • Managed 300+ RHEL, Solaris, and CentOS servers, hardened to CIS Benchmarks with Ansible, and kept security agents healthy (Splunk, Tripwire, FireEye, QRadar, Syslog-NG)
Cybersecurity & GIS/IT Consultant
Jan 2023 โ€” Present
MASK2 Functional Cybersecurity Consultancy โ€” CA/PH
  • Provide GIS and IT consulting to the Teslin Tlingit Council, a self-governing First Nation in Yukon, working directly with community stakeholders and respecting the Nation's data stewardship and priorities
  • Deployed a Wazuh XDR platform for a government science agency (DOST-STII), standing up their first security operations and monitoring baseline
  • Run vulnerability assessments and penetration tests on web applications and APIs, delivering exposure reports and prioritized fixes
Earlier IT & Support Engineering Roles
2003 โ€” 2016
SolarWinds MSP ยท Semco Maritime ยท White & Case LLC ยท United Overseas Bank
  • Application & network support engineering at SolarWinds MSP (2013โ€“2016), progressing from Intermediate to Senior Engineer
  • IT service desk, desktop support, and technical support roles across maritime, legal, banking, and BPO environments
Education & Certifications
Education
Bachelor of Science, Information Technology
Polytechnic University of the Philippines
Sept 2021
Cyber Security for Energy
Ontario Tech University
Mar 2024
Professional Designations
CIPS Information Systems Professional (I.S.P.)
CIPS โ€” Canada's Association of I.T. Professionals
Active
CIPS IT Certified Professional (ITCP)
CIPS โ€” Canada's Association of I.T. Professionals
Active
Professional Involvement
Mentor โ€” CIPS Alberta Mentorship Program
Speaker & participant โ€” BSides Edmonton 2024
Certifications & Training
ISC2 Certified in Cybersecurity (CC)
ISC2
Active
Microsoft Azure โ€” Security & Fundamentals
Microsoft (AZ-500 / AZ-900)
Active
Certificate of Cloud Security Knowledge (CCSK)
Cloud Security Alliance
Active
Qualys Certified Specialist โ€” VM & Cloud
Qualys
Active
MITRE ATT&CK Defender ยท Purple Teamer
MITRE / MAD ยท AttackIQ
Active
CEH ยท eJPT ยท CARTP
EC-Council ยท INE ยท Altered Security
Active
CCNA ยท Fortinet NSE 2 ยท Certified OT Security Professional
Cisco ยท Fortinet ยท OT security
Active
OSCP
OffSec
In progress
Microsoft SC-200 ยท CISSP / CISM
Microsoft ยท ISC2 / ISACA
Planned