I am a Senior Cyber Security Analyst with a strong focus on DFIR, Incident Response, and SOC/CSIRT operations in complex corporate environments. My experience spans on-premises and cloud environments, including AWS, Azure, and GCP.
I manage the full incident handling lifecycle, from triage and evidence preservation to in-depth forensic analysis, containment, eradication, and lessons learned. I have hands-on experience with disk, memory, Windows and Linux artifacts, and I work to ensure incidents are handled with rigor and consistency.
I have built playbooks and SOPs, improved SIEM use cases, and conducted proactive threat hunting using MITRE ATT&CK. I also communicate technical findings clearly to both technical and executive audiences, especially in high-pressure situations.
In my recent roles, I have structured SOC governance, developed dynamic playbooks, standardized response procedures, and supported strategic incident response orchestration. I have also investigated alerts, preserved evidence, and coordinated closely with network, infrastructure, and cloud teams.
My background includes cybersecurity work in highly complex CSIRT environments, cloud incident analysis, vulnerability management, phishing investigation, anti-fraud support, and executive KPI reporting. I have also contributed to hardening and patching processes across enterprise environments.
Before moving fully into cybersecurity, I worked in telecommunications operations, where I handled critical network failures and major outages. That experience gave me a strong systemic view of infrastructure and 24×7 operations, which continues to support my work in security today.
Structured SOC technical governance, including workflow architecture, critical triage, and incident response orchestration. Created and implemented dynamic playbooks, developed SOPs aligned with NIST and MITRE ATT&CK, and conducted in-depth alert investigation, evidence collection and preservation, and coordination with network, infrastructure, and cloud teams.
Identified, analyzed, and remediated cybersecurity incidents in complex CSIRT environments. Investigated public cloud security events in Azure and AWS, managed infrastructure and web application vulnerabilities, reviewed firewall rule risks, analyzed phishing and spam emails, supported anti-fraud activities, designed SIEM use cases, developed incident response playbooks, produced executive KPI reports, and managed hardening and patching processes.
Identified, analyzed, and remediated cybersecurity incidents in a multinational telecommunications CSIRT environment. Improved monitoring rule sets, enriched SIEM data collection, and collected and presented CSIRT KPIs to teams responsible for critical applications.
Identified and resolved critical network failures affecting customers nationwide. Managed major network outages, provided remote support to field teams, coordinated with transport/transmission teams, and developed a strong operational foundation that supported the transition into cybersecurity.
Jobicy
617 professionals pay to access exclusive and experimental features on Jobicy
Free
USD $0/month
For people just getting started
Plus
USD $8/month
Everything in Free, and: