Skills
Grouped by expertise area — the tools and platforms I work with, how I use each, and where I've applied it.
Monitored and investigated security alerts, wrote KQL detection queries, and escalated confirmed incidents.
Developed detection queries, hunted across logs, and automated repetitive SOC tasks.
Conducted endpoint investigations, contained threats, and supported timely remediation.
Investigated phishing emails and validated indicators during email-threat triage.
Performed vulnerability assessments and validated remediation activities.
Analysed suspicious network traffic as part of investigations.
Validated IOCs and enriched investigations with reputation and detection context.
Enriched phishing and malware investigations by observing sample behaviour.
Checked IP reputation while validating IOCs during investigations.
Mapped detections to ATT&CK techniques to structure investigation and coverage.
Automated repetitive SOC tasks and built security tools end to end.
Automated repetitive SOC tasks and used it for Windows endpoint control.
Automated repetitive SOC tasks to improve operational efficiency.
Managed incidents and tracked investigation work.
Managed incidents and coordinated resolution with IT teams.