SOC Tier 1 analyst with approximately one year of professional experience and Incident Responder, actively seeking opportunities in international cybersecurity environments.
My work spans alert triage, incident investigation, log analysis, and detection rule tuning across multiple SIEM and SOAR platforms. I complement my professional experience with a strong certification stack and a portfolio of self-built detection engineering projects covering malware triage, phishing analysis, brute force detection, and network traffic forensics.
I hold internationally recognised certifications — CompTIA Security+, CySA+, and English C1 (Trinity ISE III) — and I am currently pursuing Microsoft SC-200 and BTL1 to further specialise in cloud-native SOC operations and blue team techniques.
I am open to a wide range of roles across the cybersecurity spectrum: SOC analyst, incident responder, cybersecurity analyst, threat intelligence analyst, detection engineer, and beyond. My goal is to work with serious, driven teams in international environments — wherever the most impactful security work is happening.
- 📘 Microsoft SC-200 — Security Operations Analyst Associate
- 🎯 BTL1 — Blue Team Level 1 (Security Blue Team)
- 🔍 Expanding detection coverage across KQL (Sentinel) and SPL (Splunk)
- 🌐 Actively pursuing international cybersecurity roles across multiple domains
| Area | Tools & Technologies |
|---|---|
| SIEM & Detection | Microsoft Sentinel · KQL · Splunk · SPL · Wazuh · Microsoft Azure |
| SOAR | Alert automation · Playbook execution · Incident orchestration |
| Scripting & Automation | Python · Bash |
| Network Analysis | Wireshark · Scapy · PCAP analysis |
| Threat Intel & Frameworks | VirusTotal API · MITRE ATT&CK · Pyramid of Pain · STIX/TAXII · YARA · Sigma |
| OS & Endpoint | Linux (Ubuntu) · Windows 11 · Microsoft Entra ID |
| Dev & Workflow | Git · GitHub · Visual Studio Code |
SOC Analyst — Tier 1 | Italy | ~1 year
- Alert triage and investigation across SIEM and SOAR platforms
- Log analysis and correlation for endpoint and network events
- Detection rule tuning to reduce false positives
- Incident documentation and escalation to Tier 2
- Threat intelligence enrichment using IOC lookup tools
- Playbook execution and automated response workflows
I am open to opportunities across the full cybersecurity operations spectrum:
SOC Analyst · Incident Responder · Cybersecurity Analyst · Detection Engineer · Threat Intelligence Analyst · Blue Team Analyst · Security Engineer · CSIRT Analyst
Personal detection engineering projects built to go beyond day-to-day SOC operations. All repositories include MITRE ATT&CK mapping, evidence screenshots, and analyst write-ups.
🛡️ soc-home-lab
End-to-end SOC lab on Wazuh + OpenSearch. Custom detection rules, agent deployment, log ingestion validation, and full triage workflow from alert to incident report.
MITRE → T1110.001 Password Guessing · T1078 Valid Accounts
Python tool for SHA256-based malware triage via VirusTotal API v3. Tested against a real OffLoader trojan sample. Includes a KQL hunt rule for Microsoft Sentinel.
MITRE → T1027 Obfuscated Files · T1204.002 User Execution: Malicious File
Python parser for raw .eml files. Extracts headers, URLs, IPs, and attachment hashes. Flags typosquatting, suspicious TLDs, and urgency language. Enriches IOCs via VirusTotal API.
MITRE → T1566.002 Spearphishing Link · T1078 Valid Accounts
SPL detection rules for brute force patterns in Windows Security Event logs. Includes threshold tuning notes and a Tier 1 analyst triage playbook.
MITRE → T1110.001 Password Guessing · T1110.003 Password Spraying
Python + Scapy PCAP analyzer. Detects port scans, C2 connections on suspicious ports (4444, 6667, 31337...), and UDP flood activity. Generates structured SOC analyst reports.
MITRE → T1046 Network Service Scanning · T1071 Application Layer Protocol · T1498 Network DoS
Defensive security reference covering DMA attack mechanics, IOMMU/VT-d protections, Kernel DMA Protection, and memory encryption countermeasures.
MITRE → T1200 Hardware Additions
| Language | Level |
|---|---|
| 🇮🇹 Italian | Native |
| 🇬🇧 English | C1 — Trinity ISE III |
| 🇫🇷 French | B2 |
| 🇪🇸 Spanish | B1 |
"The best defenders think like attackers — and document like defenders."