Cybersecurity professional with 3+ years across SIEM monitoring, alert triage, and detection engineering — mapping real attack simulations to MITRE ATT&CK in Splunk, Microsoft Sentinel, and AWS.
My interest in cybersecurity is rooted in outcomes: turning raw log data into detections that an analyst can act on with confidence. I specialise in detection engineering — designing and tuning detection rules, reducing alert noise, and mapping findings to the MITRE ATT&CK framework so each alert carries clear, actionable context.
3+ years of combined IT and security operations experience. Core areas of expertise:
A complete SOC environment I built end to end, plus a set of focused projects across SIEM, cloud security, and automation.
A selection of independent projects covering the range a SOC or blue team role actually touches: on-prem SIEM, cloud log analysis, SOAR automation, and applied detection logic.
Near real-time cloud threat detection pipeline: automated S3 log ingestion every 15 minutes, 11 Sigma-style YAML detection rules, and a multi-event correlation engine surfacing multi-step attack chains.
Tuned noisy analytics rules, integrated threat intelligence, and built a fully automated detect-to-remediate lifecycle for a simulated leaked storage key — IP enrichment, auto-escalation, and automated key rotation.
Multi-panel Splunk dashboard tracking Windows Security Event Log credential access activity, user behaviour, and system-level events, with regex-based field extraction for inconsistent log formats.
Engineered SPL detection logic identifying repeated authentication failures (Event ID 4625), investigated 500+ simulated log events, and documented a full SOC Tier 1 triage workflow.
Bidirectional LSTM deep learning model trained on 82,486 real emails, deployed as a live Flask dashboard with confidence scoring — directly applicable to SOC phishing triage workflows.
Random Forest model trained on 125,973 NSL-KDD network traffic records, deployed as a live traffic-scanning dashboard classifying DoS, Probe, R2L, and U2R attacks in real time.
Hands-on investigation labs across four forensics disciplines, using the tools a Tier 1 / Tier 2 analyst reaches for daily.
LinkedIn recommendations from classmates and clients I've worked with directly.
I worked with Shaheer in a freelance capacity, where he provided Security Operations Center support, including cybersecurity monitoring, SIEM log analysis, and incident investigation. His journey is genuinely impressive — he moved from Pakistan to build his career here, balancing his studies with part-time work while supporting his family. That discipline shows in how he works: methodical, reliable, and always keen to improve. I'm happy to recommend Shaheer for SOC Analyst roles.
I highly recommend Shaheer to any team seeking an exceptional cyber security operation analyst. He is undoubtedly one of the most dedicated professionals I know. Shaheer brings a rare combination of soft skills and deep technical expertise — a natural problem-solver, a dependable collaborator, and someone who consistently elevates the performance of those around him.
I had the pleasure of studying alongside Shaheer during our MSc in Cybersecurity at Birmingham City University. He consistently demonstrated a strong commitment to learning and excellence, with great interest in security operations, threat analysis, and incident response. His collaborative nature, problem-solving mindset, and determination to continuously improve make him a valuable asset to any cybersecurity team.
I have known Shaheer as both a classmate and a friend, and one thing that has always stood out is his passion for cybersecurity. His practical experience in SOC operations, SIEM technologies, threat detection, and cloud security demonstrates the effort he has invested in building real-world expertise. He is approachable, dependable, and a great team player.