Robert M. Lee Portfolio
CEO of Dragos and lead investigator on major ICS incidents including the 2015 Ukraine power grid attack and the TRISIS malware targeting a Saudi petrochemical plant; his team also discovered the PIPEDREAM industrial attack framework.
What makes it work
A breakdown of the choices that make this portfolio stand out.
Direct attribution to named, verifiable incidents
Citing specific investigations — the Ukraine grid attack, TRISIS, PIPEDREAM — ties the stated expertise to publicly documented events that can be independently researched, rather than to vague "critical infrastructure experience."
A company built around the specific threat class investigated
Founding Dragos specifically for ICS/OT threat detection turned personal investigative expertise into a dedicated firm, showing the specialty is durable enough to build a business around, not just a personal interest.
Accessible content alongside deeply technical work
Publishing children's books on ICS security concepts next to advanced threat intelligence material shows a willingness to communicate the field at every level, widening the practical impact of the expertise.
What Cybersecurity Analysts can take from this
Specific, actionable tips to apply to your own portfolio — no generic advice.
Attribute your expertise to specific, named, publicly documented incidents wherever you can — it is independently checkable in a way "extensive experience" is not.
If your specialty is durable and in-demand, consider what a business or dedicated practice built specifically around it would look like — it is the strongest possible signal of depth.
Don't restrict your output to only the most technical audience — content that makes your specialty accessible to newcomers extends your influence and is remembered.
More Cybersecurity Analyst portfolios
Ready to build your portfolio?
Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.