I am a Cybersecurity professional focused on Security Operations (SOC), SIEM monitoring, detection engineering, incident response, and security automation. I build hands-on cybersecurity labs that simulate real-world enterprise environments using SIEM, EDR, SOAR, threat intelligence, AI and adversary simulation tools. My projects demonstrate experience in log analysis, threat detection, security workflow automation, and AI-assisted threat hunt and analysis.
Applying skills in Security Operations, SIEM monitoring, detection engineering, incident response, threat hunting, security automation, AI-assisted security operations, and identity security. Seeking opportunities as a SOC Analyst, Security Engineer, or Incident Response Analyst to contribute to threat detection, log analysis, security investigations, and building security workflows using enterprise security tools.
| Skill | Associated Project |
|---|---|
| Active Directory Administration & Security | AD Homelab Project |
| SIEM Monitoring and SOC Analysis | SOC Automation with AI |
| Security Automation & Orchestration (SOAR) | SOAR EDR Integration |
| SIEM Monitoring & Detection Engineering | SOC ELK Detection Lab |
| AI-Assisted SOC Operations & Threat Hunting | AI SOC Agent 2.0 |
Deployed an Active Directory SOC environment with Splunk and Sysmon for centralized monitoring, then simulated RDP brute-force and MITRE ATT&CK techniques using Hydra and Atomic Red Team to validate detection workflows.
Built an automated incident response workflow using n8n, Splunk, AbuseIPDB, and Gemini for alert ingestion, IOC enrichment, AI-driven risk analysis, and structured analyst notifications.
Developed a SOAR/EDR incident response workflow using LimaCharlie and Tines to automate detection, alerting, analyst approval, and endpoint isolation with post-action validation.
Built a SOC detection and investigation environment using Elastic Stack, Sysmon, and Elastic Defend to monitor brute-force activity and C2 behavior, investigate alerts, map adversary activity to MITRE ATT&CK, and automate osTicket incident tracking.
Built an AI-assisted SOC investigation workflow using Elastic, Python, and Gemini for threat hunting, evidence collection, structured investigations, and SOC reporting, with tool-based workflows, query optimization, security guardrails, and token/cost controls.

