Overview
Technical skills
Timeline
Roles

Overview

Cybersecurity engineer focused on SOC operations, SIEM/EDR monitoring, incident response, and threat hunting. Builds and tunes detection rules and SIEM use cases, performs vulnerability assessments, and maps detections to MITRE ATT&CK. Also has experience executing red team and full-scope penetration tests and participating in security detection validation.
Phone

Technical skills

Languages
5
Python
Java
SQL
Bash
PHP
Cybersecurity
14
SIEM
MITRE ATT&CK
Metasploit
Burp Suite
DLP
SentinelOne
Wazuh
AbuseIPDB
Trend Micro
FortiGate
Nessus
Nmap
OWASP ZAP
Wireshark
DevOps
3
Linux
Splunk
Windows
Other
5
OpenVAS
pfSense
OWASP
Cyber Kill Chain
Red Teaming

Timeline

Cybersecurity Engineer (SOC, SIEM, Incident Response) • Middle
Group Vital • Full-Time
May 2026 to Present 4 Months In office
Monitors and administers a multi-vendor SOC stack, including SIEM, EDR, firewalls, and email security. Investigates security alerts through event analysis, IOC checks, and threat validation. Builds and tunes SIEM detection rules and correlation searches, maps detections to MITRE ATT&CK, and works on reducing false positives. Supports incident response with investigation/enrichment playbooks and coordinates remediation for vulnerabilities.
MITRE ATT&CK
Cybersecurity Engineer (SIEM, EDR) • Middle
Data Consult • Full-Time
Feb 2025 to Apr 2026 1 Year 2 Months In office
Monitors and optimizes multi-vendor SIEM, EDR, and email security deployments while enforcing security policies to improve detection and response. Performs vulnerability assessments, prioritizes high-risk findings, and supports remediation efforts. Configures endpoint compliance via MDM and creates security reports and dashboards for threat and incident trends. Develops detection rules and SIEM use cases aligned to MITRE ATT&CK to reduce detection gaps.
MITRE ATT&CK
Red Team / Penetration Tester • Middle
Potech • Full-Time
Oct 2024 to Feb 2025 4 Months In office
Executes red team and full-scope penetration testing across networks, endpoints, and web applications to identify vulnerabilities and attack paths. Runs realistic attack simulations, including custom exploitation and social engineering, to assess technical and human risk. Collaborates with SOC/blue teams to validate detections and strengthen monitoring rules and incident response. Produces executive and technical reports with prioritized findings and remediation recommendations.