SOC Lead & Incident Response Expert | Detection Engineering | Cyber Threat Intelligence
Aktualisiert am 19.08.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 01.09.2026
Verfügbar zu: 100%
davon vor Ort: 100%
Detection Engineering
Incident Management
Threat Intelligence
ELK
Volatility
Splunk SOAR
Python
PowerShell
SOC
Teamleading
STIX
Splunk Enterprise
Caldera
PeStudio
MISP
ISO IEC 27001
QRadar
NIST
FTK
cyberkillchain
Mitre attack
thehive
autopsy

Einsatzorte

Einsatzorte

Mannheim (+200km)
Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

1 year 7 months
2025-01 - 2026-07

SOC Service Leadership & Operations

SOC Team Lead Incident Management Splunk Enterprise ELK-Stack ...
SOC Team Lead
  • Managed end-to-end incident response by leading SOC analysts, coordinating with infrastructure and application teams, providing executive and customer status updates, and overseeing containment, forensic analysis, root cause investigations, and lessons learned using the MITRE ATT&CK framework and Cyber Kill Chain.
  • Owned the design, governance, and continuous improvement of SOC operational processes and service documentation, aligned with ISO/IEC 27001 requirements and security governance best practices. Established standardized workflows, RACI responsibilities, escalation matrices, playbooks, and technical runbooks across Alert Triage, Log Management, Security Monitoring, Detection Engineering, Incident and Major Incident Response, Escalation Management, Change Management, and Problem Management to ensure consistent service delivery, SLA compliance, operational maturity, and effective cross-functional collaboration.
  • Defined and drove SOC automation initiatives by leveraging SOAR capabilities and Python-based automation to optimize SOC processes, reduce manual effort, and improve service quality. Established automated reporting mechanisms for incident management, SLA monitoring, and SOC performance metrics, enabling transparent operational oversight and KPI tracking.
  • Led the design and execution of purple team exercises and adversary simulations to assess and enhance SOC detection and response capabilities. Coordinated structured testing against real-world APT techniques and TTPs mapped to the MITRE ATT&CK framework, driving improvements in detection coverage, response playbooks, and SOC maturity.
Incident Management Splunk Enterprise ELK-Stack IBM Qradar TheHive ServiceNow FTK Autopsy Forensics Zimmerman toolset Volatility STIX TAXII MISP OpenCTI use case management
2 years 7 months
2024-01 - 2026-07

CybAirSOC EU-Project

SOC-Manager Caldera Splunk Enterprise Splunk SOAR ...
SOC-Manager
  • Definition of SOC processes and SOC design
  • Conducting gap analyses and threat hunting
  • Responsibility for Red Team operations and use case management


Responsible for designing and establishing a comprehensive SOC model within an EU-level aviation cybersecurity project targeting airport environments. Developed SOC architecture, infrastructure, tooling strategy, and operational processes while coordinating the creation of IT, OT, and IoT detection use cases aligned with airport-specific systems. Led SOC service evaluation activities, performed capability gap analysis, and drove improvements across processes, detection coverage, and operational maturity. Established test environments for adversary simulations and detection validation to ensure SOC readiness and effectiveness.

Caldera Splunk Enterprise Splunk SOAR Threat Intelligence Use Case Management Incident Management SOC-Processes MITRE Attack ELK-Stack Red-Team
6 years 7 months
2019-06 - 2025-12

Threat Intelligence Platform ? Design, Build & Operationalization

Software Devoloper and Threat Intelligence Expert Python GitLab Jenkins ...
Software Devoloper and Threat Intelligence Expert
  • Contributed to the design and development of an internal Threat Intelligence Platform for the collection, enrichment, correlation, and operationalization of CTI data.
  • Integrated multiple intelligence sources, including MISP, CVE feeds, OSINT, and STIX/TAXII, and established workflows for threat monitoring, IOC management, and intelligence processing.
  • Joined the functional and operational team as SOC Lead to define high-level capabilities, workflows, and use case requirements based on SOC operational needs.
  • Integrated the Threat Intelligence Platform into SOC operations, enabling intelligence-driven detection, investigation, and response workflows.
Python GitLab Jenkins STIX MISP Threat Intelligence APT-Groups MITRE ATT&CK
11 months
2023-02 - 2023-12

MSSP Threat Hunting & Intelligence services

SOC-Consulting - MSSP Manager Tahiti Threat Hunting Use Case Management ...
SOC-Consulting - MSSP Manager
Owned the Threat Hunting and Threat Intelligence service within an MSSP SOC environment for a critical energy sector client, establishing structured hunting processes based on CTI-driven analysis and APT profiling. Managed hunting activities through prioritized backlogs, defined hypotheses mapped to the MITRE ATT&CK framework, and coordinated investigations using Splunk Enterprise Security and Microsoft Defender to identify advanced threats and improve detection coverage.
Tahiti Threat Hunting Use Case Management Threat Intelligence Risk analysis MITRE ATT&CK Splunk Enterprise Windows Defender

Aus- und Weiterbildung

Aus- und Weiterbildung

1 year 10 months
2014-09 - 2016-06

Master?s degree in computer systems and network security

Central Private University, Tunis
Central Private University, Tunis

Position

Position

Cybersecurity Consultant / SOC Lead & Security Operations Expert

Kompetenzen

Kompetenzen

Top-Skills

Detection Engineering Incident Management Threat Intelligence ELK Volatility Splunk SOAR Python PowerShell SOC Teamleading STIX Splunk Enterprise Caldera PeStudio MISP ISO IEC 27001 QRadar NIST FTK cyberkillchain Mitre attack thehive autopsy

Programmiersprachen

python
Fortgeschritten
powershell
Fortgeschritten

Einsatzorte

Einsatzorte

Mannheim (+200km)
Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

1 year 7 months
2025-01 - 2026-07

SOC Service Leadership & Operations

SOC Team Lead Incident Management Splunk Enterprise ELK-Stack ...
SOC Team Lead
  • Managed end-to-end incident response by leading SOC analysts, coordinating with infrastructure and application teams, providing executive and customer status updates, and overseeing containment, forensic analysis, root cause investigations, and lessons learned using the MITRE ATT&CK framework and Cyber Kill Chain.
  • Owned the design, governance, and continuous improvement of SOC operational processes and service documentation, aligned with ISO/IEC 27001 requirements and security governance best practices. Established standardized workflows, RACI responsibilities, escalation matrices, playbooks, and technical runbooks across Alert Triage, Log Management, Security Monitoring, Detection Engineering, Incident and Major Incident Response, Escalation Management, Change Management, and Problem Management to ensure consistent service delivery, SLA compliance, operational maturity, and effective cross-functional collaboration.
  • Defined and drove SOC automation initiatives by leveraging SOAR capabilities and Python-based automation to optimize SOC processes, reduce manual effort, and improve service quality. Established automated reporting mechanisms for incident management, SLA monitoring, and SOC performance metrics, enabling transparent operational oversight and KPI tracking.
  • Led the design and execution of purple team exercises and adversary simulations to assess and enhance SOC detection and response capabilities. Coordinated structured testing against real-world APT techniques and TTPs mapped to the MITRE ATT&CK framework, driving improvements in detection coverage, response playbooks, and SOC maturity.
Incident Management Splunk Enterprise ELK-Stack IBM Qradar TheHive ServiceNow FTK Autopsy Forensics Zimmerman toolset Volatility STIX TAXII MISP OpenCTI use case management
2 years 7 months
2024-01 - 2026-07

CybAirSOC EU-Project

SOC-Manager Caldera Splunk Enterprise Splunk SOAR ...
SOC-Manager
  • Definition of SOC processes and SOC design
  • Conducting gap analyses and threat hunting
  • Responsibility for Red Team operations and use case management


Responsible for designing and establishing a comprehensive SOC model within an EU-level aviation cybersecurity project targeting airport environments. Developed SOC architecture, infrastructure, tooling strategy, and operational processes while coordinating the creation of IT, OT, and IoT detection use cases aligned with airport-specific systems. Led SOC service evaluation activities, performed capability gap analysis, and drove improvements across processes, detection coverage, and operational maturity. Established test environments for adversary simulations and detection validation to ensure SOC readiness and effectiveness.

Caldera Splunk Enterprise Splunk SOAR Threat Intelligence Use Case Management Incident Management SOC-Processes MITRE Attack ELK-Stack Red-Team
6 years 7 months
2019-06 - 2025-12

Threat Intelligence Platform ? Design, Build & Operationalization

Software Devoloper and Threat Intelligence Expert Python GitLab Jenkins ...
Software Devoloper and Threat Intelligence Expert
  • Contributed to the design and development of an internal Threat Intelligence Platform for the collection, enrichment, correlation, and operationalization of CTI data.
  • Integrated multiple intelligence sources, including MISP, CVE feeds, OSINT, and STIX/TAXII, and established workflows for threat monitoring, IOC management, and intelligence processing.
  • Joined the functional and operational team as SOC Lead to define high-level capabilities, workflows, and use case requirements based on SOC operational needs.
  • Integrated the Threat Intelligence Platform into SOC operations, enabling intelligence-driven detection, investigation, and response workflows.
Python GitLab Jenkins STIX MISP Threat Intelligence APT-Groups MITRE ATT&CK
11 months
2023-02 - 2023-12

MSSP Threat Hunting & Intelligence services

SOC-Consulting - MSSP Manager Tahiti Threat Hunting Use Case Management ...
SOC-Consulting - MSSP Manager
Owned the Threat Hunting and Threat Intelligence service within an MSSP SOC environment for a critical energy sector client, establishing structured hunting processes based on CTI-driven analysis and APT profiling. Managed hunting activities through prioritized backlogs, defined hypotheses mapped to the MITRE ATT&CK framework, and coordinated investigations using Splunk Enterprise Security and Microsoft Defender to identify advanced threats and improve detection coverage.
Tahiti Threat Hunting Use Case Management Threat Intelligence Risk analysis MITRE ATT&CK Splunk Enterprise Windows Defender

Aus- und Weiterbildung

Aus- und Weiterbildung

1 year 10 months
2014-09 - 2016-06

Master?s degree in computer systems and network security

Central Private University, Tunis
Central Private University, Tunis

Position

Position

Cybersecurity Consultant / SOC Lead & Security Operations Expert

Kompetenzen

Kompetenzen

Top-Skills

Detection Engineering Incident Management Threat Intelligence ELK Volatility Splunk SOAR Python PowerShell SOC Teamleading STIX Splunk Enterprise Caldera PeStudio MISP ISO IEC 27001 QRadar NIST FTK cyberkillchain Mitre attack thehive autopsy

Programmiersprachen

python
Fortgeschritten
powershell
Fortgeschritten

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.