About
Security Managed Services Engineer with 2 years of hands-on experience configuring and maintaining SIEM systems, developing and customising security detection rules, monitoring and investigating alerts, and managing security incidents through all response phases to closure. Proficient in Splunk Enterprise, IBM QRadar, and Wazuh EDR — with practical experience in log collection, normalisation, and storage from multiple sources including Windows Security Logs, Linux Syslog, and Firewall logs. Experienced in developing incident response procedures, writing incident reports, reducing false positives, and maintaining thorough SIEM documentation. Familiar with SOAR concepts, UEBA, EDR/XDR, vulnerability scanning, malware analysis, and forensic log analysis techniques. Committed to zero missed SLA conditions and continuous optimisation of SOC toolsets for operational integrity.
Skills & Expertise (44)
Work Experience
Security Operations Engineer & SIEM Architect
NIIT Foundation
May 2025 - Jun 2026
Configured and maintained Splunk Enterprise SIEM and IBM QRadar systems — ensuring proper setup for security event data collection, log normalisation, and storage from multiple sources including Windows Security Logs, Linux Syslog, and Firewall logs across domain-joined enterprise lab environments. Developed, customised, and managed security detection rules within Splunk and IBM QRadar to detect and respond to security threats — engineering use cases for brute-force vectors, privilege escalation, unauthorised account modifications, and lateral movement aligned to MITRE ATT&CK; TTPs. Monitored SIEM alerts continuously, investigated events by severity and nature, and took appropriate response actions — maintaining zero missed SLA conditions across all monitored environments and updating tickets with detailed incident documentation. Managed security incidents through all incident response phases to closure — analysing events from Splunk, QRadar, and Wazuh EDR; writing incident reports; documenting actions taken; and implementing measures to reduce false positives and improve signal fidelity. Developed and documented incident response procedures, playbooks, and SOC runbooks — leading and assisting in incident response efforts across simulated enterprise environments and coordinating with cross-functional teams during active investigations. Ingested and normalised 10GB+ of daily live security event data using Splunk Universal Forwarders; maintained thorough documentation of SIEM configuration, log source inventory, and incident response plans for audit and compliance purposes. Integrated Wazuh EDR/XDR for automated endpoint detection and utilised Wireshark for packet capture (PCAP) analysis and network-level forensic investigation — examining running processes, network connections, and reconstructing event histories. Developed PowerShell and Python automation scripts to streamline common security response tasks, reduce manual effort in log pipeline configuration, and enhance SOC operational efficiency — applying REST API and JSON/XML concepts for tool integration. Collaborated with SIEM solution concepts and vendor documentation to apply updates, patches, and configuration improvements — proactively identifying and reporting system security loopholes, vulnerabilities, and infringements to senior management. Continuously optimised SIEM systems for efficient performance — fine-tuning alert thresholds, reducing noise, and ensuring the platform remained responsive under high log volume ingestion from multi-endpoint environments. Maintained operational integrity of SOC toolsets and ensured SIEM configurations aligned with security policies and compliance requirements — supporting audit readiness across NIST CSF, ISO 27001, and CIS Controls frameworks.
Freelance Web Application Security Assessment
Thou Shine in Life
Jan 2024 - Jan 2025
Performed reconnaissance and vulnerability scanning using Nmap — identifying open ports, running services, and exposed attack surfaces on a nopCommerce-based e-commerce web application; documented all findings with required forensic detail. Investigated and identified root causes of critical security misconfigurations including absent security headers (CSP, HSTS, X-Frame-Options), missing CSRF tokens, insecure password reset flows, and lack of rate limiting — reconstructing event histories and attack vectors using forensic analysis techniques. Audited Ventaforce-developed financial endpoints for IDOR vulnerabilities; developed and delivered a structured 10-point remediation report covering CAPTCHA, input sanitisation, patch management, and access control hardening — maintaining complete incident documentation.
Education
Bachelor of Technology (B.Tech) — Computer Science & Engineering - Academy of Technology
- 2024 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (44)
Click a skill to find developers with the same skill