I am a security operations analyst with three years defending enterprise and financial-sector environments, including a resident posting at a central bank. I currently work night shifts at EnSOC-MYS, monitoring and investigating alerts across Microsoft Sentinel, Splunk, IBM QRadar and LogRhythm, and validating threats with EDR and threat-intelligence platforms.
I focus on the details that stop breaches: clean triage, fast escalation, and understanding why an alert fired — not just closing the ticket.
Outside the queue I run a hands-on lab: building detection rules with Sigma and Wazuh, working through offensive paths on sanctioned training platforms, and building AI-agent tooling for security workflows. My goal is purple work — attack and defend, with AI-assisted detection as the differentiator.
| Period | Role |
|---|---|
| Sep 2023 – present | SOC Analyst, Ensign InfoSecurity (EnSOC-MYS) |
| Feb – Aug 2023 | Security Analyst (resident), financial-sector client via SysArmy |
| Aug 2022 – Jan 2023 | Security internship |
In progress: detection engineering portfolio; eJPT is the next hands-on certification on the list.
I keep anonymised write-ups of real investigations I have owned — triage decisions, the evidence that contradicted my first hypothesis, and the detection gap that followed. They are available on request in an interview setting. Nothing derived from employer or client telemetry is ever published here, which is also why there are no real incident data or IOCs anywhere on this site.