Senior SOC Analyst
My work focuses on escalated security incidents, SIEM/SOAR investigations, EDR/XDR analysis, malware and phishing cases, threat hunting, log correlation, customer calls and operational reporting.
I prefer evidence-based conclusions: establish scope, validate what is known, identify gaps, and recommend actions proportionate to the observed risk.
Signal → Context → Response
- Validate detection quality and initial impact.
- Correlate identity, endpoint, network and threat intelligence telemetry.
- Separate suspicious behavior from legitimate business activity.
- Document findings with defensible technical evidence.
- Recommend containment, remediation and detection improvements.
SOC Delivery
- Senior incident investigation and L1/L2 escalation handling
- Client calls, incident updates and management reporting
- SLA-driven response and ticket lifecycle management
- Knowledge transfer and SOP/process improvement
Technical Investigation
- Malware, phishing/BEC and suspicious remote access
- IOC sweeps and threat intelligence correlation
- Firewall, IDS/IPS, DNS, IIS and endpoint telemetry analysis
- MITRE ATT&CK mapping and root-cause analysis