SOC Consultant
- SOC Transformation
- SOC Consulting
- Detection Engineering
- Security Monitoring Engineering
- AI for Cybersecurity
SOC Consultant | AI for Cybersecurity | Detection Engineering
Building intelligent Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research & Development, SOC Maturity, and AI for Cybersecurity. Backed by 10+ years of experience across telecommunications, banking, managed security service providers (MSSPs), and advanced malware research.
I am a SOC Consultant with over 10 years of experience helping organizations strengthen Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, SOC maturity assessments, and AI for Cybersecurity. My experience spans telecommunications, banking, managed security service providers (MSSPs), and cybersecurity research.
My career began in Cybersecurity Research & Development, specializing in malware analysis, reverse engineering, and digital forensics. This research foundation provided deep insight into attacker techniques and continues to shape my approach to threat detection, incident response, and security monitoring.
Today, I design and optimize enterprise Security Operations by developing detection strategies, improving security monitoring capabilities, leading complex incident investigations, implementing SOC maturity initiatives, and helping organizations adopt AI securely within modern Security Operations.
Alongside my consulting work, I actively research AI security, LLM security, detection engineering, and Security Operations, and regularly publish technical articles focused on strengthening cyber resilience and advancing modern SOC capabilities.
Helping organizations strengthen Security Operations through consulting, technical advisory, cybersecurity research, and AI-driven innovation.
Helping organizations build intelligent Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research, and AI for Cybersecurity.
Let's TalkA selection of security initiatives, consulting engagements, and technical projects focused on strengthening Security Operations, Detection Engineering, Security Monitoring, and AI for Cybersecurity.
Strengthened Security Operations using the SOC-CMM framework by improving governance, analyst workflows, operational processes, detection coverage, and documentation across multiple SOC maturity domains.
Designed and implemented Risk-Based Alerting (RBA) in Splunk Enterprise Security to reduce false positives, improve alert prioritization, and enable risk-driven investigations.
Integrated Microsoft Defender telemetry into Splunk Enterprise Security to improve endpoint visibility, strengthen detection coverage, and enhance incident investigation workflows.
Designed security monitoring coverage for Microsoft Fabric and Snowflake environments by developing logging strategies, onboarding security telemetry, and building detection use cases for data analytics platforms.
Developed Cyber Threat Intelligence (CTI) monitoring workflows by integrating threat intelligence with SIEM correlation, historical log analysis, and IOC monitoring to strengthen proactive threat detection.
Research and engineer AI assistants, local LLM workflows, and intelligent automation to streamline cybersecurity tasks, accelerate investigations, and develop practical AI solutions that strengthen organizational cybersecurity.
A defensible network architecture article focused on monitored, inventoried, controlled, claimed, minimized, assessed, and current network security engineering.
The opening article in a technical series on defensible security architecture, Zero Trust engineering, threat-informed defense, and reducing attacker freedom across the enterprise.
The culminating article in a 5-part series — mapping the complete SOC maturity journey using SOC-CMM, covering governance, people, process, and technology dimensions.
People remain the most critical and underinvested layer of SOC operations. This article covers analyst development, retention, and building a collaborative culture under pressure.
A practitioner's view of the technology layer — SIEM selection, detection engineering frameworks, automation strategies, and avoiding the common tooling traps.
The structural prerequisites that most SOCs skip — processes, measurement frameworks, and the foundational governance elements required before any tooling investment pays off.
The opening article of the series — diagnosing why most SOCs stagnate at reactive operations and the strategic path toward proactive, intelligence-driven defense.
A technical walkthrough of implementing Risk-Based Alerting in Splunk Enterprise Security — how to cut alert noise without losing signal, using risk scores and risk objects.
Case study analysis of SOC response to a complex, multi-vector breach — detection handoffs between tiers, DFIR investigation workflow, and lessons for improving response playbooks.
A critical perspective on AI adoption in security operations — why AI-generated output must always be validated against logs, telemetry, and business context before action.
Security architecture analysis of GPU cloud platforms (NCP/NVIDIA) — covering identity, control plane risks, workload isolation, shared responsibility, and SOC use cases for AI infrastructure monitoring.
Asset visibility as a detection prerequisite — why you cannot detect what you cannot see, and practical approaches to building and maintaining a living asset inventory for SOC operations.
Helping organizations strengthen Security Operations through SOC Consulting, Detection Engineering, Security Monitoring Engineering, Cybersecurity Research, and AI for Cybersecurity.
Whether you're looking to improve SOC maturity, modernize security monitoring, enhance detection capabilities, or explore practical AI solutions for cybersecurity, I'd be glad to discuss how I can help.
📍 Riyadh, Saudi Arabia
🌍 Available for Global Consulting, Technical Advisory, Research Collaboration, and Speaking Engagements.