SOC Analyst • Cybersecurity Analyst • Threat Hunting • Detection Engineering • DFIR • Microsoft Sentinel • MITRE ATT&CK
📄 Download CV 📄 Download Cover LetterI am a Microsoft Certified Security Operations Analyst (SC-200) with hands-on experience building Security Operations Center (SOC) projects focused on Microsoft Sentinel, Detection Engineering, Threat Hunting, Incident Response, Digital Forensics and Incident Response (DFIR), MITRE ATT&CK mapping, Windows Event Analysis and Security Monitoring. My cybersecurity portfolio demonstrates practical blue-team workflows using Microsoft Sentinel, KQL, Sigma Rules, Windows Event Logs, Sysmon, Velociraptor, Linux, Bash, Python, Wireshark, tcpdump and Git/GitHub. I focus on building practical security investigations that demonstrate how SOC analysts detect, investigate, document and respond to security events. Before cybersecurity, I spent more than a decade in the South African public sector — most recently as a Senior Personnel Officer in Human Resource Management at the Department of Labour — working on workplace investigations, confidential records management, evidence-based documentation and legislative compliance. That background now underpins how I approach structured SOC monitoring, incident triage and investigative reporting.
Hands-on Microsoft Sentinel detection engineering lab demonstrating KQL threat detection, threat hunting, MITRE ATT&CK mapping, incident investigation, detection logic and SOC investigation workflows.
View Project →DFIR and endpoint investigation lab demonstrating forensic artifact analysis, endpoint investigation, incident response workflows and MITRE ATT&CK techniques.
View Project →Hands-on threat hunting lab demonstrating log analysis, IOC investigation, evidence collection, incident reporting, privilege escalation detection and MITRE ATT&CK mapping.
View Project →Detection Engineering Lab demonstrating Sigma Rule development, Windows security event analysis, detection logic, threat detection and MITRE ATT&CK mapping.
View Project →Python-based SOC automation lab demonstrating Windows Event Log analysis, detection engineering, alert correlation, incident investigation, security automation and MITRE ATT&CK mapping.
View Project →Additional supporting projects demonstrating continued practical development across network analysis, Windows telemetry, threat mapping and SOC monitoring.
Microsoft Sentinel SOC simulation demonstrating alert triage, incident investigation, security monitoring, MITRE ATT&CK mapping and threat detection workflows.
View Project →Network monitoring, DNS analysis, HTTP investigation and suspicious IP detection.
View Project →Windows Security Event investigation and authentication log analysis.
View Project →Endpoint telemetry analysis using Sysmon and process monitoring.
View Project →Threat mapping, ATT&CK techniques and detection engineering.
View Project →SOC dashboard development, investigations, alert metrics and security monitoring workflows.
View Project →I am currently seeking opportunities as a SOC Analyst, Junior SOC Analyst, Cybersecurity Analyst, Security Operations Analyst or Security Analyst. My goal is to contribute to security operations through practical threat detection, investigation, incident response, digital forensics and detection engineering — while continuing to develop professionally in a real-world SOC environment. My decade of experience in investigation, compliance and evidence-based documentation within the South African public sector complements this technical foundation.