SOC Consultant | AI for Cybersecurity | Detection Engineering

Sajid
Kiani

SOC Consultant | AI for Cybersecurity | Detection Engineering

Building intelligent Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research & Development, SOC Maturity, and AI for Cybersecurity. Backed by 10+ years of experience across telecommunications, banking, managed security service providers (MSSPs), and advanced malware research.

10+
Years in Cyber
8K+
LinkedIn Reach
10+
Certifications
Read Writeups ↓ Get in Touch
About

Who I Am

Background

I am a SOC Consultant with over 10 years of experience helping organizations strengthen Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, SOC maturity assessments, and AI for Cybersecurity. My experience spans telecommunications, banking, managed security service providers (MSSPs), and cybersecurity research.

My career began in Cybersecurity Research & Development, specializing in malware analysis, reverse engineering, and digital forensics. This research foundation provided deep insight into attacker techniques and continues to shape my approach to threat detection, incident response, and security monitoring.

Today, I design and optimize enterprise Security Operations by developing detection strategies, improving security monitoring capabilities, leading complex incident investigations, implementing SOC maturity initiatives, and helping organizations adopt AI securely within modern Security Operations.

Alongside my consulting work, I actively research AI security, LLM security, detection engineering, and Security Operations, and regularly publish technical articles focused on strengthening cyber resilience and advancing modern SOC capabilities.

sajid@soc
$ whoami
Sajid Kiani
SOC Consultant
$ specializations
→ SOC Consulting
→ Detection Engineering
→ Security Monitoring Engineering
→ SOC Maturity (SOC-CMM)
→ AI for Cybersecurity
→ Threat Modeling & Hunting
→ Cybersecurity Research & Development
$ location
Riyadh, KSA
$ status
Available for Consulting
Available for Advisory Engagements

Key Achievements

ENGINEERING
Designed and optimized enterprise detection use cases aligned with MITRE ATT&CK, improving detection coverage, reducing false positives, and strengthening threat visibility.
MATURITY
Led SOC maturity initiatives using the SOC-CMM framework, strengthening governance, operational processes, and security monitoring capabilities.
ALERTING
Implemented Risk-Based Alerting (RBA) to prioritize high-risk threats, reduce alert fatigue, and improve analyst efficiency.
LEADERSHIP
Led multidisciplinary Security Operations teams across L1, L2, Detection Engineering, and SIEM, driving operational excellence and continuous service improvement.
AI FOR CYBERSECURITY
Research and engineer AI tools, local LLMs, and intelligent workflows to automate cybersecurity tasks, improve analyst productivity, and strengthen Security Operations through practical AI adoption.
Experience

Career Timeline

2023 – Present

SOC Consultant

Cisco
  • SOC Transformation
  • SOC Consulting
  • Detection Engineering
  • Security Monitoring Engineering
  • AI for Cybersecurity
2020 – 2023

Senior Security Analyst

Cisco
  • Threat Hunting
  • Digital Forensics
  • MITRE ATT&CK
  • Threat Intelligence
2018 – 2020

Assistant Manager - Cyber Security

First MicroFinance Bank
  • Enterprise Security
  • Governance
  • Risk Management
  • Compliance
2017 – 2018

Information Security Executive

Telecom Pakistan
  • Incident Response
  • SIEM
  • Monitoring
  • Hardening
2015 – 2017

Sr. Malware Researcher

Ebryx
  • Malware Analysis
  • Reverse Engineering
  • Digital Forensics
  • Threat Research
2012 – 2015

Independent Security Researcher

Independent Research
  • Bug Bounty
  • Penetration Testing
  • Web Security
  • Vulnerability Research
Skills & Tools

Core Expertise & Technologies

Core Expertise
SOC Consulting Detection Engineering Security Monitoring Engineering SOC-CMM Maturity Assessment Threat Hunting Incident Response & DFIR Cyber Threat Intelligence (CTI) Risk-Based Alerting (RBA) Playbook Development Security Operations Leadership
Tools & Platforms
Splunk Enterprise Security Microsoft Sentinel IBM QRadar Microsoft Defender XDR Carbon Black MITRE ATT&CK Anomali ThreatStream Microsoft Fabric Snowflake Firewall WAF EDR NDR
AI for Cybersecurity
AI Workflow Automation Local LLM Engineering LLM Security Research Prompt Engineering Prompt Injection Research AI Agent Workflows Secure AI Adoption
Research & Innovation
Cybersecurity Research Malware Research Detection Research Threat Intelligence Research AI Security Research Security Monitoring Innovation
Services

How I Help Organizations

Helping organizations strengthen Security Operations through consulting, technical advisory, cybersecurity research, and AI-driven innovation.

SOC Consulting & Maturity
  • Assess SOC capabilities using the SOC-CMM framework
  • Improve SOC governance, operational processes, and security monitoring
  • Develop SOC transformation roadmaps aligned with business objectives
  • Build analyst enablement programs, playbooks, and operational standards
Detection Engineering
  • Design and optimize SIEM detection use cases and correlation rules
  • Implement and fine-tune Risk-Based Alerting (RBA)
  • Improve detection coverage using the MITRE ATT&CK framework
  • Reduce false positives and enhance analyst efficiency
Security Monitoring Engineering
  • Design enterprise logging and monitoring strategies
  • Optimize log onboarding, normalization, and data quality
  • Improve security visibility across endpoint, network, cloud, identity, and applications
  • Build scalable security monitoring frameworks for modern SOCs
Threat Detection & Incident Response
  • Develop Threat Hunting methodologies and detection strategies
  • Build CTI-driven detection capabilities
  • Support incident investigations, DFIR, and root cause analysis
  • Strengthen proactive cyber defense through actionable intelligence
AI for Cybersecurity
  • Automate cybersecurity tasks using AI
  • Engineer practical AI assistants and local LLM workflows
  • Research AI security risks and secure AI adoption
  • Develop practical AI solutions that strengthen organizational cybersecurity
Cybersecurity Research & Innovation
  • Malware Research & Analysis
  • Threat Intelligence Research
  • Detection Engineering Research
  • AI Security Research
  • Emerging Threat Analysis

Helping organizations build intelligent Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research, and AI for Cybersecurity.

Let's Talk
Publications

Writeups & Research

Security Architecture · MICCMAC

MICCMAC: Engineering Networks That Can Be Watched, Controlled, and Defended

A defensible network architecture article focused on monitored, inventoried, controlled, claimed, minimized, assessed, and current network security engineering.

May 2026 · LatestRead ↗
Security Architecture · Zero Trust

Defensible Security Architecture: Think Like an Attacker, Act Like a Defender

The opening article in a technical series on defensible security architecture, Zero Trust engineering, threat-informed defense, and reducing attacker freedom across the enterprise.

May 2026 · Series StartRead ↗
SOC Maturity · Series Final

SOC Maturity: Charting the Path Forward with the SOC-CMM Framework

The culminating article in a 5-part series — mapping the complete SOC maturity journey using SOC-CMM, covering governance, people, process, and technology dimensions.

Feb 2025 · 58 reactionsRead ↗
SOC Maturity · Part 4

The Human Element: Building and Nurturing a Skilled SOC Team

People remain the most critical and underinvested layer of SOC operations. This article covers analyst development, retention, and building a collaborative culture under pressure.

Feb 2025 · 66 reactionsRead ↗
SOC Maturity · Part 3

Tools, Frameworks, and Strategies for Effective SOC Operations

A practitioner's view of the technology layer — SIEM selection, detection engineering frameworks, automation strategies, and avoiding the common tooling traps.

Jan 2025 · 68 reactionsRead ↗
SOC Maturity · Part 2

Building the Foundation for SOC Success

The structural prerequisites that most SOCs skip — processes, measurement frameworks, and the foundational governance elements required before any tooling investment pays off.

Jan 2025 · 34 reactionsRead ↗
SOC Maturity · Part 1

The Journey Towards SOC Maturity: Challenges and Opportunities

The opening article of the series — diagnosing why most SOCs stagnate at reactive operations and the strategic path toward proactive, intelligence-driven defense.

Jan 2025 · 47 reactionsRead ↗
Detection Engineering

Risk-Based Analysis (RBA) in Cybersecurity: Reducing Alert Fatigue with Splunk RBA

A technical walkthrough of implementing Risk-Based Alerting in Splunk Enterprise Security — how to cut alert noise without losing signal, using risk scores and risk objects.

Feb 2025 · 17 reactionsRead ↗
DFIR · Incident Response

SOC Engagement in a Multi-Layered Cybersecurity Breach

Case study analysis of SOC response to a complex, multi-vector breach — detection handoffs between tiers, DFIR investigation workflow, and lessons for improving response playbooks.

Feb 2025 · 20 reactionsRead ↗
AI Security · Critical Analysis

AI Confidence Is Not Cybersecurity Evidence

A critical perspective on AI adoption in security operations — why AI-generated output must always be validated against logs, telemetry, and business context before action.

May 2026 · 7 reactionsRead ↗
AI Security · Infrastructure

AI Runs on GPUs. But Who Is Securing the GPU Cloud?

Security architecture analysis of GPU cloud platforms (NCP/NVIDIA) — covering identity, control plane risks, workload isolation, shared responsibility, and SOC use cases for AI infrastructure monitoring.

May 2026 · LatestRead ↗
Security Operations

Why Comprehensive Asset Management Is Your Best Defense Against Cyber Threats

Asset visibility as a detection prerequisite — why you cannot detect what you cannot see, and practical approaches to building and maintaining a living asset inventory for SOC operations.

Nov 2024 · 12 reactionsRead ↗

Let's Connect

Helping organizations strengthen Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research, and AI for Cybersecurity.

Whether you're looking to improve SOC maturity, modernize security monitoring, enhance detection capabilities, or explore practical AI solutions for cybersecurity, I'd be glad to discuss how I can help.

Contact
Availability

📍 Riyadh, Saudi Arabia

🌍 Available for Global Consulting, Technical Advisory, Research Collaboration, and Speaking Engagements.