Expertise

SOC, CSIRT & Threat Hunting skills

A Tier 3 SOC / CSIRT profile able to investigate incidents, improve detection and connect SIEM, EDR, NDR, CTI and remediation teams.

What should a Senior SOC / CSIRT Engineer bring?

A Senior SOC / CSIRT Engineer must qualify complex alerts, reconstruct attack chains, query endpoint and SIEM data, improve detection rules and coordinate containment. My experience covers this chain with Splunk ES, Microsoft Defender XDR, SentinelOne, Cybereason, Vectra NDR, Cortex XSOAR, KQL, SPL and MITRE ATT&CK.

Qualify and contain

Incident Response & CSIRT

L2/L3 triage, impact analysis, timeline reconstruction, containment coordination and corrective-action tracking.

  • Malware & phishing
  • Endpoint / identity / network
  • Lessons learned & remediation
Understand behaviour

Threat Hunting & investigation

Multi-source correlation, MITRE ATT&CK-driven hunting and analysis of weak signals beyond isolated indicators.

  • KQL & SPL
  • MITRE ATT&CK
  • Forensics & timelines
Turn telemetry into decisions

Detection Engineering

SIEM use cases, EDR/XDR tuning, correlation rules, dashboards and playbooks designed to accelerate triage.

  • Splunk ES
  • Defender XDR
  • SOAR & CTI
Capabilities, tools, evidence

Verifiable experience, not a list of technologies.

Each capability is connected to the platforms used and to a professional situation documented in my background.

CapabilityTools and methodsField evidence
Incident Response / CSIRTDefender XDR, Cybereason, SentinelOne, Vectra, Splunk ESSOC/CSIRT run at LBP AM and Tier 3 investigations at E.Leclerc
Threat HuntingKQL, SPL, Deep Visibility, MITRE ATT&CK, CTIEndpoint, network, identity, email and DLP correlation
Detection EngineeringSplunk ES, Notable Events, dashboards, EDR/XDR rulesRule creation, tuning, documentation and false-positive reduction
SOAR & automationCortex XSOAR, Python, VirusTotal, MISPTriage playbooks, IOC enrichment and L2/L3 escalation
RemediationQualys, Rapid7, CVSS, corrective-action trackingCoordination across infrastructure, IAM, network, production and development

How I approach a SOC investigation

I start by qualifying the signal: source, identity, asset, timeline, behaviour and business criticality. I then correlate endpoint, network, email, identity and DLP events to distinguish a false positive, unusual legitimate activity and a compromise.

The expected output is not simply a closed alert. It includes a reasoned decision, relevant evidence, containment measures, an owner for each action and operational knowledge that the wider SOC can reuse.

Threat Hunting and incident response

Threat Hunting starts from a hypothesis or observable behaviour, not only a hash. I use SPL, KQL, Deep Visibility and available telemetry to reconstruct processes, connections, identities and movement associated with a MITRE ATT&CK scenario.

During incident response, this approach helps scope impact, find other affected assets and coordinate infrastructure, IAM, network, production and development teams.

Detection Engineering and continuous improvement

A useful detection connects a threat, available telemetry, understandable logic and a triage procedure. I work across Splunk ES rules, Notable Events, SPL and KQL queries, EDR/XDR tuning, dashboards and SOAR playbooks.

Each change must preserve coverage while reducing noise. Rule documentation, tests, lessons learned and false-positive tracking make improvement measurable and transferable.

Supporting expertise that strengthens the SOC

My experience in PKI, IAM, PAM, WAF, DLP, networking and vulnerability management improves attack-path understanding. It enables direct collaboration with the teams that produce telemetry or implement remediation.

CISSP certification and ISO 27001 experience complement this operational practice with an understanding of risk, accountability and business constraints without replacing hands-on investigation.

Supporting expertise

Technical depth that improves investigations.

Architecture, identity and data protection remain supporting skills: they improve attack-path understanding and the quality of SOC decisions.

PKI / ADCS
IAM / Entra ID
PAM / Wallix
F5 WAF
Forcepoint DLP
Netskope
Cisco ISE
Vulnerability Management
ISO 27001