From Cashier to SOC Analyst: Kevin Botana’s Journey into Cybersecurity

Miami Tech Works

|

Kevin Botana’s journey into cybersecurity didn’t start in a classroom. It started at home, watching his family get targeted by phishing calls, suspicious texts, and deceptive emails, and being the one everyone turned to for answers. That quiet responsibility became the foundation of a career.

“The journey to becoming a SOC analyst is built through dedication, continuous learning, and the drive to grow into a successful cybersecurity professional.”

The Defender Who Was Already There

Before enrolling at Miami Dade College, Kevin was working at his grandfather’s accounting business, steady, familiar, and close to home. On the side, he was quietly teaching himself cybersecurity. Not because someone told him to, but because his family needed someone who understood what was happening online.

“I decided to pursue cybersecurity after seeing my family targeted by various phishing attacks growing up, through phone calls, text messages, and emails.” He became their first line of defense. Over time, that role deepened: he studied attacker tactics, educated his family on how to recognize threats, and helped them become more vigilant. By the time he entered a formal program, he was already thinking like a defender.


What the Classroom Built

At Miami Dade College, Kevin discovered something that would prove just as valuable as any technical skill: how to work effectively as part of a team.

“That experience has been especially valuable in cybersecurity, where collaboration and communication are essential in team-oriented environments.” SOC work is rarely a solo act. Incidents get triaged across shifts, escalations involve multiple analysts, and findings have to be communicated clearly to people at every level of an organization. The group projects and collaborative culture at MDC prepared him for exactly that.

His capstone project was a standout moment, one that pulled together key frameworks and network architecture in a way that connected classroom theory to real-world practice. It wasn’t just an academic exercise; it was a blueprint for how to think about enterprise security.

A Certification That Made It Real

Kevin pinpoints the exact moment the hard work started to feel like something more: earning his CompTIA Security+ certification during his final semester of college.

That credential wasn’t just a milestone, it signaled readiness to employers and, more importantly, to himself. It marked the transition from someone learning cybersecurity to someone prepared to practice it.

Getting the Door to Open

Breaking in wasn’t easy. Kevin submitted numerous applications, reached out for referrals, and refined his resume again and again and again before landing his first opportunity. The process was humbling, but it was also instructive.

“Through persistence, dedication, and continuous refinement of my resume, I was eventually able to break into the field.” What carried him through wasn’t luck — it was the willingness to keep improving and keep showing up, even when progress wasn’t visible yet.

Today, Kevin works as a Threat Detection and Incident Response Analyst at MUFG, operating in a 24/7 Global Security Operations Center for one of the world’s largest financial institutions. His responsibilities span triaging security events, monitoring network traffic, analyzing SIEM logs, participating in threat hunting exercises, and supporting SOC efficiency through standardized procedures and reporting. His prior background , including IT support and account management at Tax One, gave him a grounding in real business environments that now informs how he approaches security in high-stakes settings.

Building Toward Leadership

Kevin isn’t standing still. In his current role, he’s focused on sharpening his ability to distinguish real threats from false positives in complex enterprise environments, a skill that only comes with exposure and repetition at scale.

But he’s also looking ahead. He’s pursuing leadership and management-focused training with a clear goal: to eventually lead the kind of teams he now works alongside. “I have a strong passion for cybersecurity, as well as a genuine desire to help and support people.” That desire, to protect, to educate, to lead, is the same instinct that first drove him to help his family identify a suspicious email. Now it’s being channeled into a career built to last.

What He’d Tell Someone Starting Out

Kevin’s advice is direct and practical: “Start by building strong fundamentals in networking, operating systems, and common attack types, then get hands-on practice with logs and SIEM tools through labs or platforms like TryHackMe.”

But technical skills are only part of the picture. “Focus on developing both technical analysis skills and clear communication — since SOC work is as much about explaining findings as it is about detecting threats.” That balance, between technical depth and human clarity, is what separates a capable analyst from an indispensable one.


Kevin Botana’s story is a reminder that the path into cybersecurity doesn’t require a perfect starting point. It requires a reason. For Kevin, that reason was protecting the people he loved. Everything else, the certifications, the projects, the persistence, followed from there.

Share with