Senior SOC / CSIRT Engineer.
Incident Response & Threat Hunting.
Detection Engineering.
Cybersecurity engineer with 8 years of experience across critical banking and asset-management, retail, aerospace and defence environments. My core work covers alert qualification, incident investigation, Threat Hunting and the design of actionable detections.
Detect, investigate, contain.
Three connected capabilities for turning a technical event into a reliable, documented and actionable SOC decision.
Incident Response & CSIRT
L2/L3 triage, impact analysis, timeline reconstruction, containment coordination and corrective-action tracking.
- Malware & phishing
- Endpoint / identity / network
- Lessons learned & remediation
Threat Hunting & investigation
Multi-source correlation, MITRE ATT&CK-driven hunting and analysis of weak signals beyond isolated indicators.
- KQL & SPL
- MITRE ATT&CK
- Forensics & timelines
Detection Engineering
SIEM use cases, EDR/XDR tuning, correlation rules, dashboards and playbooks designed to accelerate triage.
- Splunk ES
- Defender XDR
- SOAR & CTI
The capabilities I bring to a SOC.
Hands-on coverage across collection, detection, qualification, investigation, response, automation and operational learning.
Triage, investigation & response
L2/L3 qualification, impact analysis, timeline reconstruction, containment and coordination of remediation teams.
Multi-source Threat Hunting
Endpoint, network and identity hunting with CTI context, MITRE ATT&CK and weak-signal analysis.
Detection, tuning & automation
SIEM use cases, EDR/XDR tuning, correlation, dashboards and playbooks for faster, repeatable qualification.

Senior SOC / CSIRT, from raw signal to remediation.
A clear professional identity: SOC, CSIRT and detection.
Cybersecurity engineer with 8 years of experience across critical banking and asset-management, retail, aerospace and defence environments. My core work covers alert qualification, incident investigation, Threat Hunting and the design of actionable detections.
Security, governance and Splunk certifications.
Verifiable certifications supporting a field track record across SOC, security architecture and governance.

CISSP
Security governance, risk management and architecture aligned with business priorities.

ISO 27001 Lead Implementer
Implementing an information security management system, policies and action tracking.

Splunk Enterprise Admin
Splunk Enterprise administration, log collection and day-to-day platform operations.

Splunk Power User
Event search and analysis, dashboards and correlations that support investigations.
A SOC track record built in critical environments.
Recent roles place SOC/CSIRT operations, EDR/XDR, Splunk and incident response at the centre.
Lead Security Engineer — SOC / CSIRT & XDR
Operational responsibility for SOC / CSIRT run activities, EDR/XDR/NDR/SIEM controls and log visibility in a financial environment.
Cybersecurity Engineer & Tier 3 SOC / CSIRT Analyst
Advanced investigation, continuous SOC capability improvement and integration across EDR, SIEM, SOAR, WAF and vulnerability controls.
SecOps DLP & Network Security Engineer
DLP investigations, rule tuning and infrastructure experience providing a practical understanding of flows, identities and root causes.
Tools built for investigation.
ThePhishAnalyzer demonstrates my approach: structure evidence, automate repetitive checks and keep the decision with the analyst.
ThePhishAnalyzer
A phishing-investigation workbench for SOC analysts: EML/RFC822 parsing, SPF/DKIM/DMARC checks, URL extraction, enrichment and analyst-ready summaries.
Ghost-Hunter
A RAG/LLM prototype for structuring application-security triage and connecting test scenarios to signals useful for detection.
Technical depth that improves investigations.
Architecture, identity and data protection remain supporting skills: they improve attack-path understanding and the quality of SOC decisions.
The Ghost-Hunter workflow map
A working map to organise bug bounty investigations, connect testing stages and track leads to explore.
CISSP Study Planner
An interactive prep planner with email persistence, weekly workload and tracking across all 8 domains.
The Ghost-Hunter workflow map
A clear view of the Ghost-Hunter pipeline to move from raw HTTP traffic to actionable test hypotheses, then to properly tracked findings.
Two complementary formats: a Ghost-Hunter map for structured investigation and an interactive CISSP planner for managing exam preparation.
Threat Hunting, investigation and detection.
Operational analysis on detection, SOC investigations, phishing, SIEM platforms and incident response.
Detection engineering in Splunk: what separates visibility from noise
Move a SIEM from alert clutter to a useful SOC decision engine with testable threat scenarios, reliable telemetry and controlled tuning.
SOC incident response drill: scenario, injects and success criteria
Build an exercise that truly tests decisions, access, telemetry and crisis coordination.
SIEM explained: architecture and criteria for an operational system
A SIEM collects and correlates events. Its value still depends on data quality, use cases and the response process.
Hiring a Senior SOC / CSIRT profile?
Let’s discuss your environment, team and priorities across Incident Response, Threat Hunting, Splunk ES, Defender XDR and Detection Engineering.
