Andrew Jerry

Andrew Jerry

SOC Automation Lead

Linked In

Andrew Jerry is a SOC Automation Lead at Dropzone AI, where he drives innovation for AI-powered security solutions tailored to SOC analysts. With a focus on aligning technology with real-world user workflows, Andrew ensures that Dropzone AI's platform empowers analysts to respond decisively and efficiently to security threats. Before joining Dropzone AI, he honed his expertise as a Senior Detection & Response Analyst at Expel, leading high-stakes investigations and mentoring security teams. Passionate about redefining modern security operations, Andrew Jerry combines technical acumen with a user-first approach to deliver impactful solutions.

Inside the SOC

Legacy Auth, Real Business: The MFA Alert That Didn’t Signal Compromise

Dropzone AI's SOC analyst investigated a suspicious MFA bypass alert, revealing legitimate legacy auth behavior. Real investigation case study with analysis.

By Andrew Jerry, June 23, 2025

Unmasking the Relay: Navigating Alerts Triggered by Anonymized IP Services

A suspicious login from an anonymized IP triggered an alert. See how Dropzone AI traced it to Apple Private Relay and saved analyst time.

By Andrew Jerry, May 1, 2025

How Dropzone AI Cracked a Tricky VPN Logon Alert—and Why Context Matters

A suspicious VPN login alert flagged a CMO. Dropzone AI investigated the context—VPN, inflight Wi-Fi, and history—and resolved it as benign.

By Andrew Jerry, April 30, 2025

Silent Threat or Software Update? Decoding a Suspicious Dell Installer Alert

A CrowdStrike alert flagged a Dell installer as suspicious. See how Dropzone AI’s autonomous investigation revealed the truth in minutes.

By Andrew Jerry, April 16, 2025

.webp)

How Dropzone AI Built a Rock-Solid Quality Control Program

Learn how Dropzone AI applies quality control methodology, rolling performance metrics, and human validation to ensure every AI-generated alert is accurate and trustworthy.

By Andrew Jerry, March 27, 2025

IP Address Analysis Guide: Expert Tips for SOC Analysts

Transform IPs into intelligence using enrichment tools, threat feeds, geolocation. Essential techniques for SOC investigations. Guide inside.

By Andrew Jerry, January 2, 2025

How AI Eliminates Knowledge Silos in Security Operations

Learn how AI eliminates knowledge silos in security operations, enabling SOC analysts to quickly access critical context and streamline investigations with efficiency.

By Andrew Jerry, November 14, 2024

Top 4 Phishing Signs Every SOC Analyst Must Know

Learn to spot the top 4 phishing signs every SOC analyst should know. From suspicious links to social engineering, master key indicators for effective threat detection.

By Andrew Jerry, November 4, 2024

OSCAR Methodology: A Framework for Efficient SOC Investigations

Learn the OSCAR framework: A 5-phase investigation method reducing time from 40 to 3 minutes. See how AI implements this proven methodology.

By Andrew Jerry, October 16, 2024

Mean Time to Conclusion (MTTC): The Ultimate SOC Efficiency Metric

Mean Time to Conclusion (MTTC) measures the full alert lifecycle, from detection through disposition. See what MTTD and MTTR don't capture, with examples.

By Andrew Jerry, September 13, 2024