I am a Senior Cyber Security Analyst with a strong focus on DFIR, Incident Response, and SOC/CSIRT operations in complex corporate environments. My experience spans on-premises and cloud environments, including AWS, Azure, and GCP.
I manage the full incident handling lifecycle, from triage and evidence preservation to in-depth forensic analysis, containment, eradication, and lessons learned. I have hands-on experience with disk, memory, Windows and Linux artifacts, and I work to ensure incidents are handled with rigor and consistency.
I have built playbooks and SOPs, improved SIEM use cases, and conducted proactive threat hunting using MITRE ATT&CK. I also communicate technical findings clearly to both technical and executive audiences, especially in high-pressure situations.
In my recent roles, I have structured SOC governance, developed dynamic playbooks, standardized response procedures, and supported strategic incident response orchestration. I have also investigated alerts, preserved evidence, and coordinated closely with network, infrastructure, and cloud teams.
My background includes cybersecurity work in highly complex CSIRT environments, cloud incident analysis, vulnerability management, phishing investigation, anti-fraud support, and executive KPI reporting. I have also contributed to hardening and patching processes across enterprise environments.
Before moving fully into cybersecurity, I worked in telecommunications operations, where I handled critical network failures and major outages. That experience gave me a strong systemic view of infrastructure and 24x7 operations, which continues to support my work in security today.