SOC, CSIRT & Threat Hunting skills
A Tier 3 SOC / CSIRT profile able to investigate incidents, improve detection and connect SIEM, EDR, NDR, CTI and remediation teams.
What should a Senior SOC / CSIRT Engineer bring?
A Senior SOC / CSIRT Engineer must qualify complex alerts, reconstruct attack chains, query endpoint and SIEM data, improve detection rules and coordinate containment. My experience covers this chain with Splunk ES, Microsoft Defender XDR, SentinelOne, Cybereason, Vectra NDR, Cortex XSOAR, KQL, SPL and MITRE ATT&CK.
Incident Response & CSIRT
L2/L3 triage, impact analysis, timeline reconstruction, containment coordination and corrective-action tracking.
- Malware & phishing
- Endpoint / identity / network
- Lessons learned & remediation
Threat Hunting & investigation
Multi-source correlation, MITRE ATT&CK-driven hunting and analysis of weak signals beyond isolated indicators.
- KQL & SPL
- MITRE ATT&CK
- Forensics & timelines
Detection Engineering
SIEM use cases, EDR/XDR tuning, correlation rules, dashboards and playbooks designed to accelerate triage.
- Splunk ES
- Defender XDR
- SOAR & CTI
Verifiable experience, not a list of technologies.
Each capability is connected to the platforms used and to a professional situation documented in my background.
| Capability | Tools and methods | Field evidence |
|---|---|---|
| Incident Response / CSIRT | Defender XDR, Cybereason, SentinelOne, Vectra, Splunk ES | SOC/CSIRT run at LBP AM and Tier 3 investigations at E.Leclerc |
| Threat Hunting | KQL, SPL, Deep Visibility, MITRE ATT&CK, CTI | Endpoint, network, identity, email and DLP correlation |
| Detection Engineering | Splunk ES, Notable Events, dashboards, EDR/XDR rules | Rule creation, tuning, documentation and false-positive reduction |
| SOAR & automation | Cortex XSOAR, Python, VirusTotal, MISP | Triage playbooks, IOC enrichment and L2/L3 escalation |
| Remediation | Qualys, Rapid7, CVSS, corrective-action tracking | Coordination across infrastructure, IAM, network, production and development |
How I approach a SOC investigation
I start by qualifying the signal: source, identity, asset, timeline, behaviour and business criticality. I then correlate endpoint, network, email, identity and DLP events to distinguish a false positive, unusual legitimate activity and a compromise.
The expected output is not simply a closed alert. It includes a reasoned decision, relevant evidence, containment measures, an owner for each action and operational knowledge that the wider SOC can reuse.
Threat Hunting and incident response
Threat Hunting starts from a hypothesis or observable behaviour, not only a hash. I use SPL, KQL, Deep Visibility and available telemetry to reconstruct processes, connections, identities and movement associated with a MITRE ATT&CK scenario.
During incident response, this approach helps scope impact, find other affected assets and coordinate infrastructure, IAM, network, production and development teams.
Detection Engineering and continuous improvement
A useful detection connects a threat, available telemetry, understandable logic and a triage procedure. I work across Splunk ES rules, Notable Events, SPL and KQL queries, EDR/XDR tuning, dashboards and SOAR playbooks.
Each change must preserve coverage while reducing noise. Rule documentation, tests, lessons learned and false-positive tracking make improvement measurable and transferable.
Supporting expertise that strengthens the SOC
My experience in PKI, IAM, PAM, WAF, DLP, networking and vulnerability management improves attack-path understanding. It enables direct collaboration with the teams that produce telemetry or implement remediation.
CISSP certification and ISO 27001 experience complement this operational practice with an understanding of risk, accountability and business constraints without replacing hands-on investigation.
Technical depth that improves investigations.
Architecture, identity and data protection remain supporting skills: they improve attack-path understanding and the quality of SOC decisions.
