Cyber incident response / Tampa, Florida

GabrielSimches

Threat Hunting / Incident Response / Digital Forensics

A team-focused cyber incident responder who builds repeatable defense programs, leads complex investigations, and turns adversary behavior into practical action.

01 Hunt 02 Respond 03 Analyze
Illustrated portrait of Gabriel Simches in front of a Shinto gate
Focus: advanced adversaries DEFENSE / INTEL / FORENSICS
01

Operational focus

Find the signal.
Make it actionable.

Offensive perspective, defensive discipline, and clear delivery for the people who need to make the next decision.

HUNT.01

Threat hunting

Intel-led hypotheses, hunt plans, repeatable delivery, KPIs, and quality controls across cloud and on-prem environments.

  • Hypothesis development
  • Adversary behavior mapping
  • Program design & enablement
RESP.02

Incident response

Technical leadership through compromise assessments, high-pressure investigations, forensic analysis, and remediation.

  • Investigation leadership
  • Host & network analysis
  • Preparedness improvement
LEAD.03

Technical leadership

Services, systems, and teams made stronger through useful tooling, thoughtful process, mentoring, and direct communication.

  • Consultant training
  • Process engineering
  • Executive-ready findings
02

Field history

Built from the console up.

Experience across frontline support, systems administration, military cyber operations, incident response, and threat-hunt leadership.

2022 — Present

Mandiant now part of Google Cloud

Senior IR Consultant — Threat Hunt Service Lead

Developing and leading threat-hunt services, directing incident response work, training consultants, and improving how intelligence becomes action.

Threat HuntIRService Design
2018 — 2025

United States Air Force / Air National Guard / Reserve

Cyber threat hunter & cyber warfare operator

Defensive cyber operations, live threat hunting, SIEM engineering, network forensics, mission planning, and briefings for senior leadership.

Cyber OperationsForensicsElastic
2014 — 2018

Apple / Rackspace / Sitecore

Technical foundations

Root-cause troubleshooting, service desk leadership, systems administration, automation, security projects, and customer-facing technical work.

SystemsAutomationSupport
03

Selected credentials

Verified depth.
Practical range.

Credentials support the work. The objective remains the same: understand what happened, contain it, and leave the environment stronger.

GIAC

GEIR

GIAC Enterprise Incident Responder

GIAC

GCFA

GIAC Certified Forensics Analyst

M.S.

Managing Innovation & IT

Champlain College

04

Interactive contact

Ask the terminal.

Type help, choose a command, or use contact for the cleanest route to connect.

visitor@gabriel:~ local session
Gabriel Simches profile terminal v1.0
No telemetry. No cookies. Type help to begin.

Packet loss prevention

Sometimes the system needs a break.

Two dependency-free browser games. No account, no leaderboard, no data collection.

Enter the game room