Junior SOC Analyst with a background in IT Support, Systems Administration and Networking.
I currently work in a Security Operations Centre, investigating and triaging security incidents, analysing indicators of compromise and supporting incident management and response activities.
My main interests are Blue Team operations, threat detection, incident response and security automation.
- Security incident investigation and triage
- EDR / XDR analysis
- IOC analysis: IPs, domains, hashes, files and processes
- Threat intelligence and reputation analysis
- Incident management and escalation
- Security monitoring and event analysis
- Authorised containment and remediation support
Security
- Microsoft Defender for Endpoint
- CrowdStrike
- Palo Alto Cortex XDR
- Threat Intelligence platforms
- Jira
Systems & Infrastructure
- Windows Server & Active Directory
- Microsoft 365
- Microsoft Entra ID
- Microsoft Intune
- Windows & Linux
- TCP/IP, DNS, DHCP, VLANs and VPNs
- Ubiquiti UniFi
- Freshservice
- SharePoint
Python-based SOC automation platform for threat detection, IOC analysis, log monitoring, threat intelligence and incident response workflows.
- IOC detection and classification
- Security event parsing
- Log ingestion and monitoring
- Threat intelligence enrichment
- Detection and response automation
- SOC / SOAR-oriented architecture
Containerized operations and security platform for incident management, access auditing and monitoring.
- FastAPI, PostgreSQL, Docker and Nginx
- JWT authentication and role-based access control
- Prometheus and Grafana monitoring
- Security event logging and audit trails
Windows Server and Active Directory home lab simulating a small business infrastructure.
- Active Directory, DNS and DHCP
- Users, groups and Organizational Units
- NTFS permissions and Group Policies
- Security auditing
- PowerShell automation
- Jira Service Management
High-availability infrastructure project.
- MariaDB Galera Cluster
- HAProxy load balancing
- Keepalived failover
- VPN access
- Security monitoring
- Automated backups
- Microsoft Azure Fundamentals (AZ-900)
- Cisco CCNA 1-3
- Blue Team Level 1 (BTL1) — In Progress
- Cambridge English C1 Advanced
- Spanish — Native
- English — C1
- Japanese — JLPT N5 in progress