SOC Team LeadIncident ManagementSplunk EnterpriseELK-Stack...
SOC Team Lead
Managed end-to-end incident response by leading SOC analysts, coordinating with infrastructure and application teams, providing executive and customer status updates, and overseeing containment, forensic analysis, root cause investigations, and lessons learned using the MITRE ATT&CK framework and Cyber Kill Chain.
Owned the design, governance, and continuous improvement of SOC operational processes and service documentation, aligned with ISO/IEC 27001 requirements and security governance best practices. Established standardized workflows, RACI responsibilities, escalation matrices, playbooks, and technical runbooks across Alert Triage, Log Management, Security Monitoring, Detection Engineering, Incident and Major Incident Response, Escalation Management, Change Management, and Problem Management to ensure consistent service delivery, SLA compliance, operational maturity, and effective cross-functional collaboration.
Defined and drove SOC automation initiatives by leveraging SOAR capabilities and Python-based automation to optimize SOC processes, reduce manual effort, and improve service quality. Established automated reporting mechanisms for incident management, SLA monitoring, and SOC performance metrics, enabling transparent operational oversight and KPI tracking.
Led the design and execution of purple team exercises and adversary simulations to assess and enhance SOC detection and response capabilities. Coordinated structured testing against real-world APT techniques and TTPs mapped to the MITRE ATT&CK framework, driving improvements in detection coverage, response playbooks, and SOC maturity.
Incident ManagementSplunk EnterpriseELK-StackIBM QradarTheHiveServiceNowFTKAutopsyForensics Zimmerman toolsetVolatilitySTIXTAXIIMISPOpenCTIuse case management
2 years 7 months
2024-01 - 2026-07
CybAirSOC EU-Project
SOC-ManagerCalderaSplunk EnterpriseSplunk SOAR...
SOC-Manager
Definition of SOC processes and SOC design
Conducting gap analyses and threat hunting
Responsibility for Red Team operations and use case management
Responsible for designing and establishing a comprehensive SOC model within an EU-level aviation cybersecurity project targeting airport environments. Developed SOC architecture, infrastructure, tooling strategy, and operational processes while coordinating the creation of IT, OT, and IoT detection use cases aligned with airport-specific systems. Led SOC service evaluation activities, performed capability gap analysis, and drove improvements across processes, detection coverage, and operational maturity. Established test environments for adversary simulations and detection validation to ensure SOC readiness and effectiveness.
CalderaSplunk EnterpriseSplunk SOARThreat IntelligenceUse Case ManagementIncident ManagementSOC-ProcessesMITRE AttackELK-StackRed-Team
Software Devoloper and Threat Intelligence ExpertPythonGitLabJenkins...
Software Devoloper and Threat Intelligence Expert
Contributed to the design and development of an internal Threat Intelligence Platform for the collection, enrichment, correlation, and operationalization of CTI data.
Integrated multiple intelligence sources, including MISP, CVE feeds, OSINT, and STIX/TAXII, and established workflows for threat monitoring, IOC management, and intelligence processing.
Joined the functional and operational team as SOC Lead to define high-level capabilities, workflows, and use case requirements based on SOC operational needs.
Integrated the Threat Intelligence Platform into SOC operations, enabling intelligence-driven detection, investigation, and response workflows.
SOC-Consulting - MSSP ManagerTahitiThreat HuntingUse Case Management...
SOC-Consulting - MSSP Manager
Owned the Threat Hunting and Threat Intelligence service within an MSSP SOC environment for a critical energy sector client, establishing structured hunting processes based on CTI-driven analysis and APT profiling. Managed hunting activities through prioritized backlogs, defined hypotheses mapped to the MITRE ATT&CK framework, and coordinated investigations using Splunk Enterprise Security and Microsoft Defender to identify advanced threats and improve detection coverage.
TahitiThreat HuntingUse Case ManagementThreat IntelligenceRisk analysisMITRE ATT&CKSplunk EnterpriseWindows Defender
Aus- und Weiterbildung
Aus- und Weiterbildung
1 year 10 months
2014-09 - 2016-06
Master?s degree in computer systems and network security
Central Private University, Tunis
Central Private University, Tunis
Position
Position
Cybersecurity Consultant / SOC Lead & Security Operations Expert
SOC Team LeadIncident ManagementSplunk EnterpriseELK-Stack...
SOC Team Lead
Managed end-to-end incident response by leading SOC analysts, coordinating with infrastructure and application teams, providing executive and customer status updates, and overseeing containment, forensic analysis, root cause investigations, and lessons learned using the MITRE ATT&CK framework and Cyber Kill Chain.
Owned the design, governance, and continuous improvement of SOC operational processes and service documentation, aligned with ISO/IEC 27001 requirements and security governance best practices. Established standardized workflows, RACI responsibilities, escalation matrices, playbooks, and technical runbooks across Alert Triage, Log Management, Security Monitoring, Detection Engineering, Incident and Major Incident Response, Escalation Management, Change Management, and Problem Management to ensure consistent service delivery, SLA compliance, operational maturity, and effective cross-functional collaboration.
Defined and drove SOC automation initiatives by leveraging SOAR capabilities and Python-based automation to optimize SOC processes, reduce manual effort, and improve service quality. Established automated reporting mechanisms for incident management, SLA monitoring, and SOC performance metrics, enabling transparent operational oversight and KPI tracking.
Led the design and execution of purple team exercises and adversary simulations to assess and enhance SOC detection and response capabilities. Coordinated structured testing against real-world APT techniques and TTPs mapped to the MITRE ATT&CK framework, driving improvements in detection coverage, response playbooks, and SOC maturity.
Incident ManagementSplunk EnterpriseELK-StackIBM QradarTheHiveServiceNowFTKAutopsyForensics Zimmerman toolsetVolatilitySTIXTAXIIMISPOpenCTIuse case management
2 years 7 months
2024-01 - 2026-07
CybAirSOC EU-Project
SOC-ManagerCalderaSplunk EnterpriseSplunk SOAR...
SOC-Manager
Definition of SOC processes and SOC design
Conducting gap analyses and threat hunting
Responsibility for Red Team operations and use case management
Responsible for designing and establishing a comprehensive SOC model within an EU-level aviation cybersecurity project targeting airport environments. Developed SOC architecture, infrastructure, tooling strategy, and operational processes while coordinating the creation of IT, OT, and IoT detection use cases aligned with airport-specific systems. Led SOC service evaluation activities, performed capability gap analysis, and drove improvements across processes, detection coverage, and operational maturity. Established test environments for adversary simulations and detection validation to ensure SOC readiness and effectiveness.
CalderaSplunk EnterpriseSplunk SOARThreat IntelligenceUse Case ManagementIncident ManagementSOC-ProcessesMITRE AttackELK-StackRed-Team
Software Devoloper and Threat Intelligence ExpertPythonGitLabJenkins...
Software Devoloper and Threat Intelligence Expert
Contributed to the design and development of an internal Threat Intelligence Platform for the collection, enrichment, correlation, and operationalization of CTI data.
Integrated multiple intelligence sources, including MISP, CVE feeds, OSINT, and STIX/TAXII, and established workflows for threat monitoring, IOC management, and intelligence processing.
Joined the functional and operational team as SOC Lead to define high-level capabilities, workflows, and use case requirements based on SOC operational needs.
Integrated the Threat Intelligence Platform into SOC operations, enabling intelligence-driven detection, investigation, and response workflows.
SOC-Consulting - MSSP ManagerTahitiThreat HuntingUse Case Management...
SOC-Consulting - MSSP Manager
Owned the Threat Hunting and Threat Intelligence service within an MSSP SOC environment for a critical energy sector client, establishing structured hunting processes based on CTI-driven analysis and APT profiling. Managed hunting activities through prioritized backlogs, defined hypotheses mapped to the MITRE ATT&CK framework, and coordinated investigations using Splunk Enterprise Security and Microsoft Defender to identify advanced threats and improve detection coverage.
TahitiThreat HuntingUse Case ManagementThreat IntelligenceRisk analysisMITRE ATT&CKSplunk EnterpriseWindows Defender
Aus- und Weiterbildung
Aus- und Weiterbildung
1 year 10 months
2014-09 - 2016-06
Master?s degree in computer systems and network security
Central Private University, Tunis
Central Private University, Tunis
Position
Position
Cybersecurity Consultant / SOC Lead & Security Operations Expert