TECHNICAL ARSENAL

Skills & Tools

A comprehensive breakdown of my enterprise production stack, auxiliary engineering tools, and training background.

Core Platforms & Professional Experience

Tool: Datadog

Platform Expertise: Real-time signal triage, log ingestion pipelines, billing/cost management, workflow automation.

Tool: CrowdStrike

Platform Expertise: Endpoint detections, AIDR, DLP, SaaS Security, host management, advanced event search, and CrowdStrike Intelligence & Sandbox.

Tool: Material Security

Platform Expertise: Phishing investigations, file sharing and permissions management, account takeover (ATO) resilience.

Tool: Notion

Platform Expertise: Notion power user; custom signal triage queue, detection rule registry, SOC operation runbooks, knowledge-base.

Incident Response & Operations

Incident Liaison / Tech Lead: Acted as SME managing the full lifecycle of security incidents through to post-mortem (via incident.io).

OSINT & Threat Intel

Analysis Tools: VirusTotal, AbuseIPDB, app.any.run, URL2PNG, CyberChef, Scamdoc, and GreyNoise for live threat enrichment and artifact analysis.

Frameworks & Compliance

  • MITRE ATT&CK Framework: Mapped custom detection rules and playbooks to adversary tactics.
  • ISO 27001 Framework: Applied operational security standards (e.g., threat intelligence annex).
  • NIST SP 800 Framework: Scoped all runbooks and IR procedures.

Auxiliary Technical Stack & Engineering

Scripting & Automation

Python, API integrations.

Infrastructure & CI/CD

Unix/Linux log monitoring, GitLab pipelines, change management workflows.

Training, Labs & Additional Tooling

  • SIEM: Splunk
  • Network & Forensics: Wireshark, Nmap, Autopsy, FTK Imager, ExifTool
  • Honeypots: Cowrie
  • Active Learner: TryHackMe, LetsDefend.io, BlueTeamLabs.online

Soft Skills & Professional Attributes

Stakeholder Communication

Adept at translating cyber risks into clear business impacts for non-technical stakeholders and collaborating seamlessly across engineering teams.

Operational Ownership

Taking proactive charge of continuous improvement by defining robust SOC cadences, standardising workflows, and leading reporting initiatives.

Continuous Adaptation

Passionate about staying ahead of the curve, rapidly embracing emerging technologies, and pivoting defences against evolving adversary tactics.

Constructive Collaboration

Highly receptive to peer feedback for personal growth, while delivering actionable and empathetic feedback to elevate the broader team.

Empathy & Active Listening

Fostering a blameless security culture. Approaching user-reported incidents with warmth and patience to ensure staff feel supported.

Mentorship & Team Growth

Dedicated to upskilling the expanding SOC operations team, actively guiding peers, and documenting procedures to share knowledge.

Technical Agility

Fast learner and adaptable Subject Matter Expert across a diverse modern stack.

Strategic Foresight

Looking beyond the daily alert queue to design scalable, future-proof workflows, integrating automation and AI to build next-generation defences.