CISSP · Tier 3 SOC / CSIRT · ParisParis / France / Global

Senior SOC / CSIRT Engineer.
Incident Response & Threat Hunting.
Detection Engineering.

Cybersecurity engineer with 8 years of experience across critical banking and asset-management, retail, aerospace and defence environments. My core work covers alert qualification, incident investigation, Threat Hunting and the design of actionable detections.

8
years in critical environments
SOC N3 / CSIRT
incident response & threat hunting
SIEM / EDR / XDR
detection engineering
Architecture / Identity / Resilience
defense@architecture:~$ verify trust-boundaries --scope critical-systems
[*] Mapping critical assets and dependencies…
[*] Verifying trust boundaries and identities…
[+] Priority administration path isolated.
[*] Preparing hardening and detection plan…
Privileged accounts mapped to an owner
Administration flows flagged for segmentation
Critical logging added to remediation
SOC stackSplunk ESMicrosoft Defender XDRSentinelOneCybereasonVectra NDRKQLSPLMITRE ATT&CK
Field credibility & enterprise experience
LBP AME.LeclercAirbusCISSPSplunk Certified
Core practice

Detect, investigate, contain.

Three connected capabilities for turning a technical event into a reliable, documented and actionable SOC decision.

Qualify and contain

Incident Response & CSIRT

L2/L3 triage, impact analysis, timeline reconstruction, containment coordination and corrective-action tracking.

  • Malware & phishing
  • Endpoint / identity / network
  • Lessons learned & remediation
Understand behaviour

Threat Hunting & investigation

Multi-source correlation, MITRE ATT&CK-driven hunting and analysis of weak signals beyond isolated indicators.

  • KQL & SPL
  • MITRE ATT&CK
  • Forensics & timelines
Turn telemetry into decisions

Detection Engineering

SIEM use cases, EDR/XDR tuning, correlation rules, dashboards and playbooks designed to accelerate triage.

  • Splunk ES
  • Defender XDR
  • SOAR & CTI
Achraf Hachimi portrait
Senior SOC / CSIRT Engineer

Senior SOC / CSIRT, from raw signal to remediation.

Profile

A clear professional identity: SOC, CSIRT and detection.

Cybersecurity engineer with 8 years of experience across critical banking and asset-management, retail, aerospace and defence environments. My core work covers alert qualification, incident investigation, Threat Hunting and the design of actionable detections.

SOC / CSIRT operations and L2/L3 triage
Endpoint, identity and network Threat Hunting
SIEM / EDR / XDR Detection Engineering
Containment and remediation coordination
Certifications

Security, governance and Splunk certifications.

Verifiable certifications supporting a field track record across SOC, security architecture and governance.

E.LeclercAirbus
CISSP
ISC2 / 2026

CISSP

Security governance, risk management and architecture aligned with business priorities.

ISO 27001 Lead Implementer
PECB / 2023

ISO 27001 Lead Implementer

Implementing an information security management system, policies and action tracking.

Splunk Enterprise Admin
Splunk / 2024

Splunk Enterprise Admin

Splunk Enterprise administration, log collection and day-to-day platform operations.

Splunk Power User
Splunk / 2024

Splunk Power User

Event search and analysis, dashboards and correlations that support investigations.

Selected interventions

A SOC track record built in critical environments.

Recent roles place SOC/CSIRT operations, EDR/XDR, Splunk and incident response at the centre.

La Banque Postale Asset Management · July 2025 — present

Lead Security Engineer — SOC / CSIRT & XDR

Operational responsibility for SOC / CSIRT run activities, EDR/XDR/NDR/SIEM controls and log visibility in a financial environment.

Defender XDR & Cybereason
Cybereason → Defender migration
Splunk ES, KQL, tuning and log pipelines
E.Leclerc · April 2022 — June 2025

Cybersecurity Engineer & Tier 3 SOC / CSIRT Analyst

Advanced investigation, continuous SOC capability improvement and integration across EDR, SIEM, SOAR, WAF and vulnerability controls.

SentinelOne across 7,000+ endpoints
Splunk ES, SPL & Notable Events
Cortex XSOAR, forensics & phishing
Airbus · July 2018 — March 2022

SecOps DLP & Network Security Engineer

DLP investigations, rule tuning and infrastructure experience providing a practical understanding of flows, identities and root causes.

Forcepoint & Netskope
147,000 users / 37 sites
Splunk, Python, network & PKI
SOC projects

Tools built for investigation.

ThePhishAnalyzer demonstrates my approach: structure evidence, automate repetitive checks and keep the decision with the analyst.

SOC Automation / Phishing Analysis / OSINT / TypeScript

ThePhishAnalyzer

A phishing-investigation workbench for SOC analysts: EML/RFC822 parsing, SPF/DKIM/DMARC checks, URL extraction, enrichment and analyst-ready summaries.

Threat modeling / Burp Suite / RAG / LLM / AppSec

Ghost-Hunter

A RAG/LLM prototype for structuring application-security triage and connecting test scenarios to signals useful for detection.

Supporting expertise

Technical depth that improves investigations.

Architecture, identity and data protection remain supporting skills: they improve attack-path understanding and the quality of SOC decisions.

PKI / ADCSIAM / Entra IDPAM / WallixF5 WAFForcepoint DLPNetskopeCisco ISEVulnerability ManagementISO 27001
Lead Magnet #01

The Ghost-Hunter workflow map

A working map to organise bug bounty investigations, connect testing stages and track leads to explore.

Ghost-Hunter / workflow map
Lead Magnet #02

CISSP Study Planner

An interactive prep planner with email persistence, weekly workload and tracking across all 8 domains.

CISSP / study planner
Lead Magnet

The Ghost-Hunter workflow map

A clear view of the Ghost-Hunter pipeline to move from raw HTTP traffic to actionable test hypotheses, then to properly tracked findings.

Two complementary formats: a Ghost-Hunter map for structured investigation and an interactive CISSP planner for managing exam preparation.

Senior SOC / CSIRT Engineer

Hiring a Senior SOC / CSIRT profile?

Let’s discuss your environment, team and priorities across Incident Response, Threat Hunting, Splunk ES, Defender XDR and Detection Engineering.