CV

Senior SOC / CSIRT Engineer CV

Achraf Hachimi’s background in Incident Response, Threat Hunting and Detection Engineering: 8 years of experience, Splunk ES, Defender XDR, SentinelOne and CISSP.

Professional profile

Senior SOC / CSIRT Engineer with 8 years of experience in critical environments. Specialized in alert qualification, incident investigation, Threat Hunting, Detection Engineering and the improvement of SIEM, EDR, XDR and NDR controls.

Based in Paris, I currently work at La Banque Postale Asset Management across SOC/CSIRT run activities, Defender XDR, Cybereason, Vectra and Splunk ES.

Priority skills

Tier 3 SOC / CSIRTIncident ResponseThreat HuntingDetection EngineeringSplunk ES / SPLMicrosoft Defender XDR / KQLSentinelOne / CybereasonMITRE ATT&CK / CTICortex XSOAR / PythonForensics & phishing

SOC and security operations experience

La Banque Postale Asset Management · July 2025 — present

Lead Security Engineer — SOC / CSIRT & XDR

Operational responsibility for SOC / CSIRT run activities, EDR/XDR/NDR/SIEM controls and log visibility in a financial environment.

  • Defender XDR & Cybereason
  • Cybereason → Defender migration
  • Splunk ES, KQL, tuning and log pipelines
E.Leclerc · April 2022 — June 2025

Cybersecurity Engineer & Tier 3 SOC / CSIRT Analyst

Advanced investigation, continuous SOC capability improvement and integration across EDR, SIEM, SOAR, WAF and vulnerability controls.

  • SentinelOne across 7,000+ endpoints
  • Splunk ES, SPL & Notable Events
  • Cortex XSOAR, forensics & phishing
Airbus · July 2018 — March 2022

SecOps DLP & Network Security Engineer

DLP investigations, rule tuning and infrastructure experience providing a practical understanding of flows, identities and root causes.

  • Forcepoint & Netskope
  • 147,000 users / 37 sites
  • Splunk, Python, network & PKI

SOC & automation projects

ThePhishAnalyzer

A phishing-investigation workbench for SOC analysts: EML/RFC822 parsing, SPF/DKIM/DMARC checks, URL extraction, enrichment and analyst-ready summaries.

Try ThePhishAnalyzer

Ghost-Hunter

A RAG/LLM prototype for structuring application-security triage and connecting test scenarios to signals useful for detection.

Explore the workflow

Certifications: CISSP, ISO 27001 Lead Implementer, Blue Team Level 1, Splunk Enterprise Certified Admin and Splunk Core Certified Power User.

Explore my SOC capabilities
CISSP | Detection Engineering | Splunk ES | Defender XDR

Achraf Hachimi

Paris, France

Senior SOC / CSIRT Engineer with 8 years of experience in critical environments. Specialized in alert qualification, incident investigation, Threat Hunting, Detection Engineering and the improvement of SIEM, EDR, XDR and NDR controls.

The full PDF remains available below with all experience, tooling and certifications.

Your browser cannot render the embedded PDF.

Open PDF