Information Systems graduate with hands-on SOC experience at TAHAKOM, resolving up to 15 security cases weekly through SIEM triage and MITRE ATT&CK threat hunting. CompTIA Security+ certified. I turn noisy alerts into decisions.
Four months embedded in TAHAKOM's Information Security Department — real alerts, real escalations, real adversary tradecraft.
Conducted threat intelligence analysis and dark web monitoring to identify emerging threats, leaked credentials, and fresh IOCs targeting the organization — feeding findings directly into SOC incident response workflows so exposure was actioned before it became an incident.
One real supply-chain compromise briefed to leadership, and one simulated enterprise breach reconstructed from raw log data.
A maintainer-targeted phishing campaign defeated two-factor authentication, giving the attacker publishing rights to widely-used NPM packages. Malicious code was injected downstream into 18 packages — turning a single credential compromise into a dependency-graph-wide exposure. I reconstructed the attack chain and presented it, with mitigations, to TAHAKOM's Information Security director and the wider department.
Boss of the SOC is a blue-team investigation lab — I worked the V1 dataset on CyberDefenders. You are dropped into an enterprise environment indexed in Splunk after a compromise has already happened: no alert to anchor on, no starting point, no summary. Just raw logs from web servers, IDS, endpoints and firewalls, and a set of questions you can only answer by reconstructing the events yourself. I worked it the way I would work a live case: establish the sequence before forming a theory, pivot on each confirmed indicator rather than broadening the search, and trust correlation across sources over any single log.
The same five steps whether it's a phishing report or a suspicious process tree. Most of the value is in doing them in order.
The alert lands, or a user reports something. First question isn't "is this bad" — it's "what fired, on which asset, for which user, and have we seen this pattern before." Context before analysis.
Decide fast: true positive or benign, one host or many, contained or spreading. I timebox this deliberately — a quick, defensible "no" protects the queue as much as catching a real one does.
Pull what actually proves it: raw logs, email headers, file hashes, process ancestry, destination reputation. Then pivot on every confirmed indicator rather than widening the search and hoping.
Recommend or take the step that stops the bleeding — block, isolate, reset, revoke — sized to how confident I actually am. Over-containment costs the business; under-containment costs more.
Write it so the next analyst doesn't repeat the work: what happened, what was done, which indicator to watch, and what detection would have caught this earlier. The last part is what stops the same case coming back.
Techniques I have personally triaged, hunted, or analysed — not a wish list. Click any highlighted cell for what the work actually involved.
▸ Select a highlighted technique above to see the hands-on detail.
Built in a live SOC environment, not a lab simulation.
Alert triage and full incident response on 6–15 cases weekly in LogRhythm — log correlation, IOC enrichment, severity calls, and escalation with defensible write-ups.
Hypothesis-driven hunts mapping adversary TTPs to the ATT&CK matrix, surfacing behavior that never fired an alert and turning findings into escalations.
Continuous monitoring of underground sources for leaked credentials, exposed assets, and chatter — turning external signals into actionable internal IOCs.
Next-generation firewall policy design, NAT rule sets, and VLAN segmentation — building the network boundaries that shrink an attacker's blast radius.
Header forensics with SPF/DKIM/DMARC validation, URL and attachment analysis, sender infrastructure pivoting, and campaign-level IOC extraction.
Network, email, disk, and metadata forensics plus steganography analysis — reconstructing what happened, in what order, and what the attacker touched.
I came into security from the systems side — an Information Systems degree at Imam Mohammad Ibn Saud Islamic University — and found that the part I actually cared about was the investigative one. Not the theory of how an attack could work, but the reconstruction of what did happen, in what order, from whatever the logs kept.
My internship at TAHAKOM was where that stopped being academic. Six to fifteen cases a week, real escalations, and the constant discipline of separating what the evidence shows from what it merely suggests. Presenting the NPM supply-chain post-mortem to the Information Security director taught me something the technical work didn't: an analysis nobody can follow may as well not exist.
Right now I'm deepening the detection-engineering side of the job — moving from closing alerts to writing the logic that catches things next time — and looking for a SOC team in Riyadh where I can keep learning at that pace.
Open to SOC Analyst and Cybersecurity Analyst roles in Riyadh and across Saudi Arabia. Fastest way to reach me is email.