Peru Ancient Journeys — Travel Website
Designed and deployed a full travel experience website for a Peruvian tour operator. Built with a focus on visual storytelling, mobile-first layout, and conversion-optimised booking prompts.
finance professional & cyber security enthusiast
Hi, I'm Gary Gallegos Garay — a finance professional turned cybersecurity learner based in Brisbane, Australia. With 10+ years in financial advising and risk analysis, I'm now building hands-on skills in threat detection, SOC operations, and cloud security — combining analytical discipline with real-world labs.
I spent over 10 years in financial services — as a Financial Advisor and Loan & Mortgage Analyst — where every recommendation was built on data, risk modelling, and earning client trust. That career taught me to think analytically under pressure and communicate complex decisions to non-technical audiences.
Today I'm applying those same skills to a deliberate transition into cybersecurity and cloud engineering. I'm actively working through Google Cybersecurity Certificates, completing hands-on labs on TryHackMe (SOC Level 1, phishing analysis, SIEM, EDR), and building a home lab to practise what I learn in real environments.
I'm targeting SOC Analyst and cloud security roles where analytical thinking and a continuous learning mindset matter as much as technical credentials. Based in Brisbane — open to remote and on-site opportunities across Australia.
Canterbury Technical Institute | Brisbane, Australia·2026 — Present
Currently studying Network Engineering at advanced diploma level — covering routing and switching, network security principles, and enterprise infrastructure design. Hands-on coursework reinforcing practical skills applied in home lab environments.
Canterbury Technical Institute | Brisbane, Australia·2025 — 2026
Completed an Advanced Diploma in Information Technology, building structured knowledge across systems administration, networking, and IT project management — directly supporting the transition into cybersecurity and cloud engineering roles.
Self-Employed | Remote·2024 — Present
Designing and deploying production websites for real clients. Handling everything from UX design and component architecture to deployment and performance optimisation.
Self-Directed | TryHackMe, Google, Home Lab·2023 — Present
Completing structured cybersecurity learning paths covering SOC operations, phishing analysis, SIEM fundamentals, and EDR concepts. Running a home lab with Windows Server, Active Directory, and a free SIEM stack to apply skills in a real environment. Participated in AI and cybersecurity workshops to stay current with evolving threats.
Finance Sector·10+ years
Provided financial advisory services and managed mortgage portfolios for retail and commercial clients. Built deep expertise in risk assessment, regulatory compliance, and translating data into clear client recommendations — transferable skills now applied to security risk management and stakeholder communication.
Alert triage, IOC identification, threat intel basics, log investigation
ELK Stack basics, Splunk Free, event correlation, query writing
Header analysis, URL deobfuscation, sandboxing, threat reporting
Windows, Linux CLI, Networking (TCP/IP, DNS, HTTP), Active Directory
Log parsing scripts, regex pattern matching, automated alert digests
TryHackMe, Wireshark, Nmap, AWS Console, Google Security Suite
Responsive design, deployment — handling everything from UX to deployment
Designed and deployed a full travel experience website for a Peruvian tour operator. Built with a focus on visual storytelling, mobile-first layout, and conversion-optimised booking prompts.
Created a brand identity and website for a wellness business. Delivered a clean, elegant aesthetic with clear service presentation, contact flows, and a professional online presence.
Worked through TryHackMe's SOC Level 1 path: triaging security alerts, investigating suspicious activity, and practising escalation decisions across simulated SIEM environments.
Analysed malicious email samples to extract IOCs — inspecting headers, deobfuscating URLs, and documenting threat indicators. Used sandboxing tools to safely examine attachments.
Built an ELK Stack monitoring environment in a home lab. Ingested Windows and Linux logs, wrote detection queries, and practised correlating events to identify suspicious behaviour patterns.
Deployed a Windows Server domain with two client VMs. Joined machines to AD, configured GPO policies, and instrumented the network with a SIEM stack to practise detection rule creation.
A toolkit of Python scripts that parse authentication logs, flag brute-force patterns with regex, and send a daily email digest. Built to reduce repetitive analyst workload in a home lab context.
Deployed a three-tier application on AWS using VPC, ALB, EC2, and RDS. Implemented IAM least-privilege roles, security groups, and CloudWatch logging across the full stack.