About Ian Job
SOC Analyst & Web Security Specialist based in Mombasa, Kenya.
The Transition from Web Engineering to Defensive Security
My entry point into technology began on the operational side of the web: developing websites, managing WordPress deployments, configuring DNS records, monitoring analytics, and maintaining client web applications. In that role, keeping systems accessible and performing well meant dealing directly with the reality of the public internet.
Over time, the technical problems that consistently demanded the most attention were not design changes or feature updates—they were defensive problems: automated brute-force attacks against XML-RPC endpoints, persistent bot scraping, malicious SQL injection attempts reflected in Apache access logs, domain impersonation attempts, and misconfigured edge rules.
Investigating these events revealed where my real passion lay. Instead of simply building web interfaces, I became fascinated by how systems fail under adversarial pressure, how threat actors execute reconnaissance, and how defenders can surface subtle anomalies in log telemetry before an intrusion causes harm.
Why Web Security & SOC Operations?
Modern cybersecurity is often treated as purely theoretical or heavily abstracted. However, in an actual Security Operations Center, effective triage requires knowing how real protocols, operating systems, and web stacks behave under normal conditions.
Because I have personally configured Nginx reverse proxies, written SQL queries, debugged PHP runtimes, and managed DNS records, I understand what normal application behavior looks like. When analyzing a suspicious Apache access log or evaluating an alert for broken access control, I do not just see a string of bytes; I understand the software stack that handled that request and the specific threat model at play.
Similarly, in host-based security, my focus is grounded in observable telemetry: Windows Sysmon process trees, PowerShell command-line de-obfuscation, and Linux auth logs. I believe in proving competence through documented lab investigations rather than unverified assertions.
Analytical Approach & Principles
Current Professional Objective
I am actively seeking opportunities as a SOC Analyst (Tier 1 / Tier 2), Junior Cybersecurity Analyst, Security Operations Analyst, or Web Security Analyst with forward-thinking blue teams and security consultancies.
I bring methodical investigative discipline, strong technical literacy across Windows and Linux, real-world web infrastructure familiarity, and a relentless commitment to defensive engineering.