Spirit Managed Services is now branded Infotrust.
Cyber Emergency Number:
IT Support Number:
Security Spotlight

Security Spotlight - Don Castillo, L3 SOC Analyst

China Zamora
August 24, 2026
Home

Let's Get STARTED

In this edition of Security Spotlight, we speak with Don, SOC L3 Analyst, about their journey into cyber security following a life-changing experience with cybercrime. We also discuss the human side of cyber security, emerging threats, and practical advice for anyone considering a career in the industry.

Can you please briefly introduce yourself?

I am currently a SOC L3 Analyst, and I’ve been navigating the cyber security space for almost Five years now here in Infotrust. Five years in a SOC is quite a journey, it’s an environment that teaches you just as much about human resilience under pressure as it does about technical threats.

My core focus areas are a mix of high-level technical response and human leadership. On the technical side, I handle complex alert triage and incident response. At the L3 level, my job is essentially to step in when the stakes are highest, often when a client is facing a critical threat and bring a sense of calm, clarity, and decisive action to the chaos.

And the part of my role that I find the most fulfilling is mentoring our junior analysts and making them feel that they are part of the important piece of the team.  

What first sparked your interest in cyber security, and what path led you into your role?

My journey into cyber security didn't start with a lifelong fascination for technology, it started with a moment of profound vulnerability. Years ago, I fell victim to a vishing scam.

If you’ve never experienced it, it’s a terrible feeling. You don't just lose something tangible; you feel violated, a bit ashamed, and entirely powerless. But instead of sitting with that helplessness, I felt this intense need to take my power back. I started obsessively researching how the scam worked, digging into the psychology and the tactics they used to manipulate me, just to ensure it would never happen to me again.

But as I learned more, my motivation shifted. I realized how many other people out there were vulnerable to these exact same tactics. It stopped being just about protecting myself, and it became a genuine drive to educate and shield others. I didn’t want anyone else to ever feel that specific kind of shame or helplessness. That desire to turn a negative personal experience into a protective shield for others is the exact steppingstone that led me into cybersecurity, and it remains the core reason I am so passionate about what I do today.

What experiences most shaped your approach to security today?

When you spend years in a Security Operations Center, it’s easy to become a bit cynical about human error. But honestly, the experiences that most shaped my approach actually made me deeply empathetic to the human side of security.

It starts with how I got into this field. Years ago, I was the victim of a vishing scam. I know exactly what it feels like to be manipulated, to feel vulnerable, and to feel that heavy sense of shame for falling for it. Because I carry that memory, when I see an employee click a phishing link or make a mistake today, I don't see a 'security risk' or a careless user - I see someone who was targeted. It taught me that our job isn't to judge people for being human; it's to build invisible safety nets that protect them when they inevitably stumble.

That empathy heavily shapes how I treat every analyst, too. As an L3 analyst mentoring juniors, I see the heavy emotional toll of this job every day. The crushing weight of alert fatigue, and the constant, quiet fear of missing a critical alert can break incredibly talented people.

So today, my entire approach to security is human-centric. Security isn't just about protecting data; it's about protecting people.

How has the threat landscape evolved since you started, and how have you adapted?

When I first got into this field, we were mostly fighting loud, scary malware. But today? Threat actors have become incredibly psychological. They realised that the best way to hide isn’t to write a complex new virus, it’s to exploit trust. They just blend right in by using the everyday, boring IT tools that our own teams use to keep the lights on.

And that puts us as defenders in a really tough spot! We can't just block those tools, because our IT folks need them to do their jobs, and the last thing I ever want to do is make my coworkers' lives harder or slow the business down.

So, we had to get creative and completely adapt our mindset. Instead of aggressively hunting for 'bad files,' our strategy shifted to understanding human context and hunting for 'weird behaviour.' We essentially had to learn what normal, healthy life looks like on our network. Now, if a standard background program is doing its normal job, great! But if that same boring program suddenly tries to move a mountain of data at 3:00 AM on a Sunday when everyone should be sleeping? suss isn’t it? It’s all about protecting the business without getting in anyone's way."

What is the most rewarding part of your role? What are you passionate about?

Probably the most rewarding part of my role isn't the technology, it’s the people. I spend a lot of time mentoring our junior analysts. Watching someone go from feeling overwhelmed and afraid of making a mistake, to stepping up with real confidence, is incredibly fulfilling.

As for my passion, it all goes back to my own experience of being scammed years ago. I know exactly what that vulnerability feels like. Because of that, my biggest passion is simply giving people peace of mind. Whether I’m protecting a user from a devastating attack or shielding my own team from burnout, knowing my work helps people feel safe is what keeps me going.

What advice would you have for students looking to get into cyber or individuals who want to shift their career towards cyber?

First off, take a deep breath! I know that looking at all the certifications, acronyms, and insane job requirements can feel completely overwhelming. It is so easy to look at the cyber security world and think, 'I don't fit in here' or 'I'm not technical enough.' But honestly, that is the biggest myth in the industry!

If you are shifting careers, please hear this: your past experience is your biggest superpower, not a weakness. Security isn't just about reading code or configuring firewalls; it’s about understanding human behaviour. If you worked in retail or customer service, you already have the empathy and communication skills needed to explain security to stressed-out employees. If you have a background in teaching, psychology, or even the arts, you bring a completely different way of problem-solving. We need your diverse perspective! Hackers don’t think the same way, so our defenders shouldn't either.

For students, my biggest piece of advice is to give yourself some grace. You are going to face imposter syndrome, and that is completely okay! I still feel it sometimes. No one knows everything in this field because technology changes every single day. What matters way more than memorizing a textbook is your curiosity and your grit.

Don't just collect certificates, build connections. Reach out to people, find a community, and never be afraid to raise your hand and say, 'I don't understand this, but I really want to learn.' This industry is actually full of people who want to mentor and lift you up. Stay hungry, stay empathetic, and remember that you absolutely belong here!"