SOC Analyst with hands-on experience in Active Directory security, SIEM monitoring, EDR and AI-driven SOAR automation. I leverage Splunk, Elastic, LimaCharlie, and Tines to build labs and execute automated incident response workflows.
Seeking SOC Analyst, Security Operations, or IAM Analyst roles to apply skills in security monitoring, detection, investigation, identity security, and automated response to strengthen organizational defenses.
Open to remote international roles.
| Skill | Associated Project |
|---|---|
| Identity & Access Management (IAM) & Active Directory Security | Active Directory Homelab |
| SIEM Monitoring and SOC Analysis | Wazuh SOC Lab |
| Security Automation & Orchestration (SOAR) | SOAR EDR Integration |
| SIEM Monitoring & Detection Engineering | SOC ELK Detection Lab |
| AI-Assisted SOC Operations & Threat Hunting | AI SOC Agent 2.0 |
Deployed a repeatable Active Directory security lab covering IAM, JML lifecycle automation, PowerShell provisioning, access reviews, BloodHound attack-path analysis, credential exposure, Kerberoasting, and controlled red-team testing.
Engineered an on-premises Wazuh SOC environment for centralized Windows/Linux monitoring, detection engineering, FIM, security investigations, and automated Active Response.
Integrated LimaCharlie with Tines to build a SOAR/EDR workflow automating detection, alerting, analyst approval, and endpoint isolation with post-action validation.
Constructed a detection environment using Elastic Stack, Sysmon, and Elastic Defend to investigate brute-force and C2 activity, map adversary behaviors to MITRE ATT&CK, and streamline osTicket incident tracking.
Designed an AI-assisted SOC investigation workflow with Elastic, Python, and Gemini, empowering threat hunting, evidence collection, and structured reporting through query optimization, guardrails, and cost controls.

