Open to opportunities - relocation or remote

I build the detection, then answer for what it catches.

Cyber Security Engineer and L2 SOC analyst. Two years deploying and tuning Darktrace, LogRhythm and CrowdStrike Falcon across a managed SOC - and one project where I built the entire detection chain myself and put a stopwatch on it.

2+ years
in a managed SOC, as the L2 analyst on escalated alerts
18
certifications - INE, EC-Council, CrowdStrike, Red Hat
< 60 s
measured MTTD on the SOC I built and instrumented end to end
Top 1%
globally on TryHackMe, across CTF and hands-on labs

Expertise

Both halves of the job, not one.

Most people in a security operations centre either run the tooling or work the queue. I do both - I commission and tune the detection platforms across a client estate, and I am the analyst who investigates what those same rules escalate. Building the detection and answering for it closes a loop most teams leave open.

Detection engineering

Commissioning, tuning and optimising client detection platforms: use-case design against real risk, correlation rule authoring, log source onboarding, and the unglamorous half - driving false positives down until the alert queue means something again.

LogRhythm AI Engine · Wazuh rules · Suricata · Falcon policy

Incident response & forensics

Qualification and in-depth investigation of escalated alerts under NIST SP 800-61: attack scenario reconstruction, root cause, containment, and a prioritised remediation written so the client's decision-makers can act on it.

NIST SP 800-61 · DFIR · TheHive · Cortex · MISP

Threat hunting & intelligence

Proactive hunting between incidents, adversary profiling against MITRE ATT&CK, and turning intelligence into something operational - detection rules and D3FEND countermeasures rather than a report nobody actions.

MITRE ATT&CK · D3FEND · OpenCTI · IoC analysis

Platforms

The stack I work in.

The first three run in production across client environments, and I hold the vendor certification on each. The rest I deployed and configured myself building the SOC below.

Darktrace
NDR - certified
LogRhythm
SIEM - LRSA, LRPA
CrowdStrike Falcon
XDR - CCFA
Palo Alto
NGFW
Wazuh
SIEM / HIDS
Suricata
NIDS
TheHive & Cortex
SOAR
MISP
Threat intelligence
Active Directory
Identity
Zabbix, Prometheus & Grafana
Observability
Python & Bash
Automation
Linux & Windows Server
RHEL, Kali, Parrot

Standards: NIST SP 800-61 · NIST CSF · ISO/IEC 27001 · CIS Controls · OWASP · PCI-DSS

Selected work

Three things worth showing.

01

A SOC, designed and built end to end

Engineering final-year project · Global IT Vision · 2026

Ten components, eight of them open source, segmented behind a Palo Alto NGFW and aligned to the NIST SP 800-61 incident response lifecycle. Detection, enrichment, case management and notification wired into one chain - then validated with two end-to-end MITRE ATT&CK scenarios rather than a dashboard screenshot.

The measurement that mattered was time to a contextualised alert with no human in the loop. Run either scenario below and watch it.

Attack simulation
Attack timeline 09:20
Architecture of the ten-component SOC Kali (192.168.10.129) attacks two servers in the DMZ through a Palo Alto next-generation firewall. Suricata taps the DMZ and the host agents feed a Wazuh SIEM, which correlates the events, opens cases in TheHive, enriches them through Cortex against VirusTotal and AbuseIPDB, publishes indicators to MISP, and notifies Discord through n8n. CrowdStrike Falcon runs out-of-band in its own cloud console. Zabbix, Prometheus and Grafana watch platform health. DMZ · 192.168.10.0/24 SOC · IDENTITY · 192.168.80.0/24 SOAR · 192.168.80.147 ATTACKER kali · 192.168.10.129 PALO ALTO NGFW · .10 / .205 WEB · DVWA apache2 · 192.168.10.151 FTP SERVER vsftpd · 192.168.10.150 DOMAIN CONTROLLER lab.local · 192.168.80.170 ENDPOINTS win10 · 8 wazuh agents SURICATA NIDS · dmz0 · .154 CROWDSTRIKE XDR · cloud console WAZUH SIEM · 192.168.80.145 decode · correlate · ATT&CK THEHIVE cases · tasks · observables CORTEX VirusTotal · AbuseIPDB MISP IOC sharing · feeds n8n → DISCORD webhook · < 15 s NOC zabbix · .153 prometheus · .150 grafana · .150
    MTTD< 60 s
    Correlation ruleWazuh 40112 · level 12
    Case raisedTheHive · vsftpd + Suricata + Palo Alto
    OutcomeOne correlated incident, file quarantined

    Both scenarios were replayed against the live build - Kali 192.168.10.129 against the DMZ. IP addresses and rule IDs are the real ones from the project.

    Detect
    Wazuh, Suricata, CrowdStrike Falcon XDR
    Enrich & respond
    TheHive, Cortex, MISP
    Observe
    Zabbix, Prometheus, Grafana
    Segment & notify
    Palo Alto NGFW, n8n
    02

    Profiling APT34 (OilRig)

    Threat intelligence · MITRE ATT&CK G0049

    A full profile of the Iranian espionage group: tradecraft mapped across the kill chain, three malware families taken apart, and the command-and-control infrastructure characterised.

    Intelligence is worth only the detection it produces, so the deliverable was not the report - it was a set of actionable detection rules and the matching MITRE D3FEND countermeasures. Select any technique to see what it looked like in this group's hands.

    Initial access

    Execution

    Persistence

    Credential access

    Discovery

    Lateral movement

    Command & control

    Exfiltration

    POWRUNER

    Backdoor receiving tasking and returning output over DNS queries to attacker-controlled domains.

    BONDUPDATER

    PowerShell backdoor using a DNS tunnelling channel, with fallback across query types to survive filtering.

    RDAT

    Later-generation backdoor that hid its traffic in email and inside image files - steganography as a covert channel.

    T1071.004 · DNS tunnelling C2 The signature of this group. POWRUNER and BONDUPDATER both carry tasking and output inside DNS queries, because DNS leaves nearly every network unfiltered. Detection lives in the shape of the traffic rather than the payload: query volume per domain, subdomain entropy, and record types a normal client never asks for. D3FEND countermeasures mapped: DNS traffic analysis · network traffic filtering · executable allowlisting · credential hardening.
    03

    Further work

    Offensive engagements, automation and applied cryptography

    Phishing simulation, end to end
    OSINT reconnaissance, custom scenarios and templates, campaigns triggered and tracked through an API - delivered fully functional and completely documented, with a reproducible procedure and an awareness debrief. Pwn & Patch Tunisia, 2024.
    Cybersecurity training platform
    An Odoo-based LMS for internal curricula: module catalogue, learner paths, progress tracking, and hands-on labs attached to each module. Driven from requirements through to production release. DEFENSYLAB, 2023.
    Threat-intel driven blocking
    Automated DNS and IP blocking fed from threat intelligence feeds, in Python against PostgreSQL.
    Cryptography from the specifications
    AES, RSA and ECC implemented from the standards rather than called from a library, plus secure web applications in MERN and PHP/MySQL.

    Experience

    Where the work happened.

    November 2023 - present
    Current role

    Cyber Security Engineer

    Global IT Vision - Tunis, Tunisia
    • Commission, tune and optimise the detection tooling across the client estate - use-case design, correlation rule authoring, false-positive reduction.
    • Qualify and investigate escalated alerts as L2: attack scenario reconstruction, root cause, containment, prioritised remediation, and reporting written for decision-makers.
    • Proactive threat hunting, security posture advisory, and upskilling of client teams.
    May - June 2024
    Internship

    Cybersecurity Intern

    Pwn & Patch Tunisia - Tunis, Tunisia
    • Phishing simulation taken from target selection to final report: OSINT reconnaissance, custom scenarios and templates, campaigns triggered and tracked through an API.
    • Shipped fully functional and completely documented - a reproducible procedure plus the awareness debrief that makes the exercise worth running.
    February - July 2023
    Final-year internship, bachelor's

    Final-Year Intern

    DEFENSYLAB - Tunis, Tunisia
    • Built a cybersecurity training platform - an Odoo-based LMS for internal curricula: module catalogue, learner paths, progress tracking.
    • Hands-on labs attached to each module, driven from requirements through to production release.

    Credentials

    18 certifications, 2023 to 2026.

    Weighted towards the blue team, and towards the platforms I actually run. Filter by what you are hiring for.

    eCDFP2026Digital Forensics Professional - INE
    eCTHP2026Threat Hunting Professional - INE
    eCIR2026Incident Responder - INE
    eEDA2026Enterprise Defense Administrator - INE
    CCFA2026Certified Falcon Administrator - CrowdStrike
    eJPTv22025Junior Penetration Tester - INE
    CEH2025Certified Ethical Hacker - EC-Council
    CSA2025Certified SOC Analyst - EC-Council
    LRSA2025LogRhythm Security Analyst
    LRPA2025LogRhythm Platform Administrator
    Darktrace2025Certified Cyber Engineer
    Darktrace2025Threat Visualizer Essentials
    CNSP2025Certified Network Security Practitioner
    RHCSA2024Red Hat Certified System Administrator
    BTJA2024Blue Team Junior Analyst
    CPP2024ManageEngine PAM360
    CPP2024ManageEngine Key Manager Plus
    THM2023Pentesting, Pentest+, Web Fundamentals - TryHackMe

    Education

    Training and degrees.

    Engineering Degree - Network & Information Systems Security
    TEK-UP University, Tunis
    2023 - 2026
    SOC Analyst certification track
    Clevory Training, Tunis - CEH, CSA, CyberOps, ISO 27001
    2024
    Bachelor's Degree - Telecommunications & Network Security
    ISET'COM, Tunis
    2020 - 2023

    Contact

    Hiring for a SOC?

    I am open to SOC engineer, cyber engineer, incident response, threat hunting, detection engineering and SOC analyst roles.

    Location
    Ariana, Tunisia · GMT+1
    Mobility
    Europe, Canada, EMEA or fully remote
    Languages
    Arabic native · French fluent · English fluent