Information Security & Privacy-Cybersecurity Law with a passion for web application security, IoT devices, proactive threat detection, data protection, and compliance. I enjoy bridging the gap between technical cybersecurity challenges and legal/regulatory frameworks.
Security Operations & Analysis (Blue Team Focus)
- Cybersecurity Analysis & Analytics: Threat detection, security event correlation, log analysis, behavioral analytics.
- Cyber-Incident Response: Investigating and responding to security incidents, malware identification, basic cyber forensics.
- Threat Detection & Management: Proactive threat hunting, developing detection strategies, managing threat landscapes.
- SIEM & Log Management: Proficient with Splunk and Elastic Kibana for monitoring, analysis, and reporting.
- Endpoint Detection & Response (EDR): Utilizing tools like Falcon Crowdstrike for endpoint threat detection and mitigation.
Vulnerability Management & Assessment
- Vulnerability Analysis & Management: Identifying, assessing, and prioritizing vulnerabilities.
- Security Scanning & Tools: Nessus, Nmap for vulnerability scanning and network discovery.
- Web Application Security: Understanding web-based threats, using tools like Burp Suite for vulnerability discovery.
Network & Infrastructure Security
- Network Security: Firewall configuration, Intrusion Detection/Prevention Systems (IDS/IPS), Web Application Firewalls (WAF), Data Loss Prevention (DLP).
- Network Traffic Analysis: Wireshark, tcpdump.
- Security Configuration & Architecture: Implementing secure configurations, understanding cybersecurity architecture principles.
- Mobile Device Security: Awareness of security considerations for mobile devices.
Information Security Management & Governance
- Information Security Management: Implementing and managing security programs and policies.
- Risk Management: Identifying, assessing, and mitigating security risks.
- Access Control & Management: Implementing and managing access control mechanisms.
- Data Security & Cryptography: Principles of data protection and cryptographic techniques.
- Security Policies & Awareness: Developing security policies and promoting security awareness.
- Disaster Recovery Planning: Understanding principles of DRP.
- Reporting And Communication: Effectively communicating security findings and reports.
Technical Proficiencies & Automation
- Primary Tools: Splunk, Elastic Kibana, Falcon Crowdstrike, Nessus, Nmap, Wireshark, Burp Suite, VirusTotal, AlienVault OTX.
- Scripting: Python for SOC automation and security task scripting.
- Web Technologies (Understanding): HTML, CSS, JavaScript (for understanding web threats).
- CompTIA Security Analytics Professional (CSAP) - Issued: May 2024
- CompTIA Cybersecurity Analyst (CySA+) - Issued: May 2024
- CompTIA Security+ - Issued: Dec 2022
- Verify my certifications: My Credly Profile
- Master's in Privacy and Cybersecurity Law - York University (Ongoing: Jan 2025 - Jan 2027)
- Diploma in Information Security Management - Fanshawe College (Graduated: Apr 2025)
- Bachelor's in Law - Marmara University
- Deepening my expertise in advanced threat hunting techniques.
- Developing Python tools for security operations and automation.
- Exploring the evolving landscape of IoT security and data privacy regulations.
- LinkedIn: linkedin.com/in/bozdag-enes
- Email: ebozdag@bozinfosec.ca
- GitHub: You're here!