Skip to main content
Back to overview
Hire Me
Ready for Immediate Placement

Looking to Hire a SOC or Web Security Analyst?

Experienced with SIEM threat correlation, endpoint telemetry analysis, incident triage, and web application security auditing. Prepared for live technical evaluations.

Ian Job

SOC Analyst & Web Security Specialist
Mombasa, Kenya·Remote opportunities·hello@ianjob.com·github.com/ianjob·linkedin.com/in/ianjob

Professional Summary

Analytical and security-focused professional transitioning into Security Operations Center (SOC) and Web Security analysis, backed by a strong foundation in full-stack web engineering, DNS infrastructure, and web server administration. Experienced in endpoint telemetry correlation (Sysmon, Windows Event Logs, Linux auth.log), SIEM threat hunting (Splunk), and passive web application vulnerability assessments. Dedicated to rigorous evidence collection, methodical alert triage, and defense-in-depth engineering.

Core Cybersecurity Competencies

Security Operations & SIEM

Alert triage, incident classification, Splunk SPL correlation queries, Sysmon v15 deployment, Windows Security Event analysis (4624, 4625, 4688), Linux journald/auth.log parsing.

Threat Detection & Frameworks

MITRE ATT&CK mapping (Initial Access, Execution, Persistence, Discovery), Atomic Red Team emulation, IOC extraction, defanging conventions, CyberChef de-obfuscation.

Web Application Security

OWASP Top 10 vulnerabilities (SQLi, Broken Access Control, XSS), defensive HTTP headers (CSP, HSTS, X-Frame-Options), API security, WordPress hardening, Apache access log triage.

Network & Email Analysis

Zeek conn.log analysis, Suricata NIDS alerts, Wireshark packet inspection, RFC 822 email header dissection, SPF/DKIM/DMARC email authentication validation.

Demonstrated Security Projects

SOC Detection & Telemetry Home Lab2026
Tools: Splunk Enterprise, Sysmon v15, Hyper-V, Ubuntu Server, Atomic Red Team
  • Architected an isolated multi-node virtual lab forwarding Windows endpoint and Linux system telemetry to a centralized Splunk indexer.
  • Tuned SwiftOnSecurity Sysmon XML schema to filter benign noise while maintaining 100% detection coverage for script-based download cradles.
  • Authored and validated 14 SPL correlation alert rules mapped to MITRE ATT&CK techniques.
Website Security Health Monitor & Header Analyzer2026
Stack: Next.js, Node.js DNS/Fetch, TypeScript, Tailwind CSS
  • Engineered a non-intrusive, passive security assessment engine evaluating HTTP response headers, TLS posture, and DNS email security (SPF/DMARC).
  • Implemented strict SSRF validation rejecting private RFC 1918 and loopback IP resolutions.
  • Generates actionable configuration templates for Nginx, Apache, and Next.js environments.
Browser-Native IOC Extractor & Defanger2026
Stack: TypeScript, Web APIs, Client-Only Processing
  • Built a high-performance in-memory parsing utility extracting IPs, domains, hashes, and CVE identifiers with 0% external network transmission.
  • Supports one-click defanging for safe inclusion in ticketing systems and incident response documentation.

Documented SOC Investigations (Sample)

SOC-014: Suspicious PowerShell Execution (True Positive)

Correlated Word macro execution spawning obfuscated Base64 PowerShell download cradles using Sysmon Event IDs 1 and 3 in Splunk. De-obfuscated script and documented host isolation runbook.

SOC-019: Repeated SSH Authentication Failures (True Positive)

Analyzed 12,000+ failed login events across /var/log/auth.log, verified failure of fail2ban due to lock contention, validated absence of successful sessions, and enforced UFW perimeter rules.

Professional Experience & Technical Background

Web Developer & Infrastructure Specialist2022 – Present
Freelance & Client Engagements
  • Developed, audited, and maintained web applications and WordPress deployments across Linux cloud servers (Ubuntu, Debian, Apache, Nginx).
  • Administered Cloudflare edge security (WAF rules, SSL/TLS encryption mode, bot mitigation, DNS management).
  • Monitored web access logs to identify automated scanners, malicious SQLi/XSS probes, and unauthorized admin endpoint access.

Education & Cybersecurity Study Path

CompTIA Security+ (SY0-701)— Active Study & Exam Preparation
Target: Q4 2026
Blue Team Level 1 (BTL1) / TryHackMe SOC Level 1— Practical Defensive Security Track
In Progress
Higher Education Placeholder / Relevant Coursework— Mombasa, Kenya [Details on request]
Verified

Technical Tooling & Environments

SIEM & Logging: Splunk Enterprise, Sysmon, Windows Event Logs, rsyslog, journald, Zeek, Suricata.
Analysis & Utilities: CyberChef, Wireshark, Procmon, VirusTotal, Brim/Zui, curl, awk, sed, grep.
Operating Systems: Windows 10/11, Windows Server, Ubuntu, Debian, Kali Linux, REMnux.
Development: Bash, PowerShell, Python (scripting), TypeScript, Next.js, Git.
Interested in discussing a role or requesting a full formal dossier?