About
SOC Analyst with 2.9 years of continuous 24×7 enterprise security operations, monitoring and correlating events across SIEM, IDS/IPS logs, network traffic, and endpoint/antivirus consoles to reduce mean-time-to-detect by 25% across 500+ endpoints with zero security breaches. Skilled in incident response and containment within defined SLA targets, forensic-style examination of system logs and network traffic to locate evidence, and root-cause analysis mapped to MITRE ATT&CK. Experienced tuning SIEM/IDS correlation rules against threat feeds and reputation data, authoring the team's SOC playbooks and knowledge base, and staying current on emerging threats and attack vectors. Comfortable across Windows Server, Linux, TCP/IP, and Azure IAM environments, with strong written and verbal reporting to technical and business stakeholders across rotational 24/7 coverage.
Skills & Expertise (23)
Work Experience
SOC Analyst — Tier 1
CubeLogic
Sep 2023 - Present
Monitored and correlated events across SIEM (Splunk, Wazuh), IDS/IPS logs, network traffic, and endpoint/AV consoles for 500+ endpoints to determine true incidents, cutting mean-time-to-detect by 25% with zero security breaches. Responded to security incidents and investigation requests within defined SLA targets, triaging and containing advanced-vector activity, including DDoS, brute-force, and ransomware attempts, under ITIL process with 99.5% SLA compliance over 2.9 years. Conducted forensic-style examination of system logs, applications, and network traffic (Wireshark) to locate evidence, performed RCA for escalated incidents, and updated the team's knowledge base and 10+ SOC playbooks mapped to MITRE ATT&CK. Tuned Splunk + Wazuh correlation rules and IDS/IPS thresholds based on threat feeds, reputation data, and investigation findings, reducing false positives and providing tuning recommendations during team reviews. Delivered definitive verdicts on 100% of escalated phishing cases by inspecting SMTP headers, SPF/DKIM/DMARC records, and MX anomalies across POP3, IMAP, and webmail channels, and endpoint/AV console findings. Monitored threat intel feeds and dark-web sources to stay current on emerging threats and attack vectors, correlating IOCs across multiple sources to drive proactive containment ahead of disclosure. Built dashboards and translated Splunk, Wazuh, and SaaS telemetry into concise briefings and remediation recommendations for SOC managers, technology teams, and C-level stakeholders across rotational 24/7 coverage.
Education
B.Tech, Mechanical Engineering - Lovely Professional University
2019 - 2022 · Afghanistan
Certifications
Defensive & Offensive Security Intro — TryHackMe
· 2025
Cybersecurity Analyst Simulation — Deloitte
· 2025
Microsoft SQL Server Administration — Udemy
· 2025
Cybersecurity Job Simulation — Mastercard
· 2025
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (23)
Click a skill to find developers with the same skill