Looking to Hire a SOC or Web Security Analyst?
Experienced with SIEM threat correlation, endpoint telemetry analysis, incident triage, and web application security auditing. Prepared for live technical evaluations.
Ian Job
Professional Summary
Analytical and security-focused professional transitioning into Security Operations Center (SOC) and Web Security analysis, backed by a strong foundation in full-stack web engineering, DNS infrastructure, and web server administration. Experienced in endpoint telemetry correlation (Sysmon, Windows Event Logs, Linux auth.log), SIEM threat hunting (Splunk), and passive web application vulnerability assessments. Dedicated to rigorous evidence collection, methodical alert triage, and defense-in-depth engineering.
Core Cybersecurity Competencies
Alert triage, incident classification, Splunk SPL correlation queries, Sysmon v15 deployment, Windows Security Event analysis (4624, 4625, 4688), Linux journald/auth.log parsing.
MITRE ATT&CK mapping (Initial Access, Execution, Persistence, Discovery), Atomic Red Team emulation, IOC extraction, defanging conventions, CyberChef de-obfuscation.
OWASP Top 10 vulnerabilities (SQLi, Broken Access Control, XSS), defensive HTTP headers (CSP, HSTS, X-Frame-Options), API security, WordPress hardening, Apache access log triage.
Zeek conn.log analysis, Suricata NIDS alerts, Wireshark packet inspection, RFC 822 email header dissection, SPF/DKIM/DMARC email authentication validation.
Demonstrated Security Projects
- Architected an isolated multi-node virtual lab forwarding Windows endpoint and Linux system telemetry to a centralized Splunk indexer.
- Tuned SwiftOnSecurity Sysmon XML schema to filter benign noise while maintaining 100% detection coverage for script-based download cradles.
- Authored and validated 14 SPL correlation alert rules mapped to MITRE ATT&CK techniques.
- Engineered a non-intrusive, passive security assessment engine evaluating HTTP response headers, TLS posture, and DNS email security (SPF/DMARC).
- Implemented strict SSRF validation rejecting private RFC 1918 and loopback IP resolutions.
- Generates actionable configuration templates for Nginx, Apache, and Next.js environments.
- Built a high-performance in-memory parsing utility extracting IPs, domains, hashes, and CVE identifiers with 0% external network transmission.
- Supports one-click defanging for safe inclusion in ticketing systems and incident response documentation.
Documented SOC Investigations (Sample)
Correlated Word macro execution spawning obfuscated Base64 PowerShell download cradles using Sysmon Event IDs 1 and 3 in Splunk. De-obfuscated script and documented host isolation runbook.
Analyzed 12,000+ failed login events across /var/log/auth.log, verified failure of fail2ban due to lock contention, validated absence of successful sessions, and enforced UFW perimeter rules.
Professional Experience & Technical Background
- Developed, audited, and maintained web applications and WordPress deployments across Linux cloud servers (Ubuntu, Debian, Apache, Nginx).
- Administered Cloudflare edge security (WAF rules, SSL/TLS encryption mode, bot mitigation, DNS management).
- Monitored web access logs to identify automated scanners, malicious SQLi/XSS probes, and unauthorized admin endpoint access.
Education & Cybersecurity Study Path
Technical Tooling & Environments
Analysis & Utilities: CyberChef, Wireshark, Procmon, VirusTotal, Brim/Zui, curl, awk, sed, grep.
Operating Systems: Windows 10/11, Windows Server, Ubuntu, Debian, Kali Linux, REMnux.
Development: Bash, PowerShell, Python (scripting), TypeScript, Next.js, Git.