Who we are

A security practice built on a decade of defending things that actually matter.

C3Security exists because the discipline used to protect classified defense networks works just as well for a thirty-person business — it has simply never been affordable to them.

The founder

Andrew Hogan

Andrew Hogan founded C3Security after nine years on the defensive side of some of the most scrutinized networks in the country. He enlisted in 2016, trained as an Information Technology and Cyber Operations Specialist, and spent the next several years moving from helpdesk leadership to full cyber operations.

At U.S. Central Command in Kuwait he stood up an operational security program, enforced NIST SP 800-171 and DFARS safeguards for controlled unclassified information, and resolved more than two hundred security incidents across Splunk, Tenable, Sentinel, and Defender. At Army Cyber Command he engineered detections in Microsoft Sentinel, tuned EDR, and hunted state-sponsored activity across DoD systems.

Today he provides Tier 2 security operations inside a 24x7 enterprise management operations center supporting DHS and TSA hybrid infrastructure, and holds an active TS/SCI with CI polygraph alongside a CISSP. He is completing a B.S. in Cybersecurity and Information Assurance at Western Governors University.

Outside client work he builds — a multi-agent AI operations platform, a threat intelligence platform ingesting twenty-four feeds across ninety thousand vulnerabilities, and the external exposure scorecard C3Security offers free to any organization that asks.

founder portrait
Service record
Apr 2025 — Present
Security Operations Administrator
Peraton — DHS / TSA

Tier 2 security operations in a 24x7 enterprise management operations center; incident, event, and request management across physical, virtual, and cloud infrastructure.

Feb 2025 — Jul 2025
Information Security Analyst
BayForce

Security engineering assessments across Azure, M365 Defender, Proofpoint, and Meraki; SSO and identity lifecycle via SAML, SCIM, and OIDC; NIST-aligned risk assessments.

Dec 2021 — Sep 2024
Cyber Operations Specialist
U.S. Army Cyber Command

Threat hunting with Defender XDR, Sentinel detection engineering and EDR tuning, annual security control self-assessments against NIST SP 800-171 and CUI safeguarding requirements.

May 2024 — Sep 2024
SOC Analyst (Internship)
Augusta University

Alert triage across Defender XDR, Sentinel, and Cisco Secure Endpoint; built workbooks, analytic rules, and automated playbooks; KQL investigation across Azure data sources.

Dec 2019 — Dec 2021
Senior Information Technology Specialist
U.S. Central Command — Camp Arifjan, Kuwait

Established the OPSEC program, enforced NIST SP 800-171 and DFARS 252.204-7012, authored incident-handling SOPs, and led STIG implementation across enterprise systems.

Nov 2016 — Dec 2019
Helpdesk Manager
Army NETCOM — Fort Lewis, WA

Led secure IT support for 1,000+ users, managed and mentored ten technicians, and owned hardware, software, and license lifecycle across the enterprise.

Credentials

Clearances

  • DoD TS/SCI with CI Polygraph (active)
  • DHS Public Trust (active)

Certifications

  • (ISC)² CISSP
  • CompTIA SecurityX
  • (ISC)² SSCP
  • CompTIA PenTest+ · CySA+
  • CompTIA Security+ · Network+ · A+
  • Microsoft AZ-900 · SC-900
  • ITIL v4 Foundation · Linux Essentials

Education & training

  • B.S. Cybersecurity & Information Assurance — WGU, 2027
  • Army AIT: IT Specialist & Cyber Operations Specialist
  • Microsoft: SIEM Operations with Sentinel
  • Focal Point: Network Traffic Analysis
  • Microsoft: Data Analysis with KQL
How we work

Plainly stated

No fear-selling and no acronym fog. You get what was found, what it means, and what it costs to fix.

Documented

Every engagement leaves behind diagrams, runbooks, and evidence — useful long after the work ends.

Proportional

The right control for your risk and budget. Sometimes the honest answer is that you do not need the product.