Actively Looking for Work
SOC Analyst with hands on experience in SIEM monitoring, log correlation, and incident investigation, built through a self designed Splunk based SOC lab processing over 11,000 events and structured through real world alert triage simulations. Skilled in detecting and analyzing phishing, brute force, and endpoint based attacks, with practical application of the MITRE ATT&CK framework and NIST aligned incident response workflows spanning detection, triage, investigation, escalation, and reporting. Built and maintained detection rules mapped to specific MITRE techniques including T1059.001, T1566, T1110, T1087.001, and T1136.001, and used those rules to investigate repeated brute force activity, separating true positives from false positives and documenting findings in structured incident reports. Developed PhishTriage, a Python based phishing email triage tool that extracts indicators of compromise such as sender IP, URLs, and attachment hashes from email files and enriches them through the VirusTotal and AbuseIPDB APIs, producing weighted, explainable risk verdicts similar to a lightweight SOAR playbook. Completed hands on SOC analyst training investigating and triaging more than 50 security alerts across phishing, brute force, malware, and suspicious network activity scenarios, with a focus on email header analysis, URL inspection, and endpoint log review. Holds CompTIA Security+, Splunk Core Certified User, ISC2 Certified in Cybersecurity, and Fortinet FCF and FCA certifications, alongside working knowledge of NIST CSF, ISO 27001, NCA ECC, SAMA CSF, and the Cyber Kill Chain. Prior experience includes working with Active Directory administration and access control configuration during a development trainee role, with comfortable scripting ability in Python, Java, C++, JavaScript, and PowerShell. Fluent in Arabic and professionally proficient in English, currently seeking to bring this blue team expertise to a high tempo MSSP environment in Saudi Arabia.