Open to new opportunities

Shaheer Ul Islam builds detections, not just dashboards.

Cybersecurity professional with 3+ years across SIEM monitoring, alert triage, and detection engineering — mapping real attack simulations to MITRE ATT&CK in Splunk, Microsoft Sentinel, and AWS.

SOC Analyst Threat Analyst Cybersecurity Analyst Cybersecurity Engineer Blue Team
3+
Years in IT & security operations
30+
Security events triaged monthly
30%
False-positive reduction delivered
MSc
Cybersecurity, Birmingham City University
About Us

Cybersecurity Analyst focused on practical detection engineering

My interest in cybersecurity is rooted in outcomes: turning raw log data into detections that an analyst can act on with confidence. I specialise in detection engineering — designing and tuning detection rules, reducing alert noise, and mapping findings to the MITRE ATT&CK framework so each alert carries clear, actionable context.

3+ years of combined IT and security operations experience. Core areas of expertise:

SIEM & Detection
Microsoft Sentinel, Splunk, and Wazuh, applied to alert triage, incident response, and detection engineering
Frameworks & Compliance
MITRE ATT&CK mapping; GDPR, ISO 27001, PCI DSS, and NIST CSF compliance frameworks
Identity & Cloud
Azure AD and Microsoft 365 identity management, conditional access and MFA, AWS and Azure security fundamentals
Education & Certifications
MSc in Cybersecurity, Birmingham City University; IBM and Google Cybersecurity Professional Certificates
Communication
Experienced in presenting technical findings clearly to both technical and non-technical stakeholders
Availability
Full right to work in the UK; open to SOC, blue team, threat analyst, and cybersecurity engineer roles, including shift-based work
Background

Experience

Security Operations Analyst — Self-Employed (Freelance)
Oct 2023 – Present
  • Delivered SOC monitoring and incident investigation for two small-business clients and one mid-sized business, triaging 30+ security events per month across Microsoft Sentinel, Splunk, and Wazuh.
  • Analysed Windows Event Logs (Event IDs 4624, 4625, 4648, 4720) to detect authentication failures, brute-force patterns, and privilege escalation attempts, mapped to MITRE ATT&CK TTPs.
  • Reviewed and investigated endpoint detections in Microsoft Defender for Endpoint, including isolating a compromised device and tuning detection policies to reduce noise.
  • Deployed and monitored Suricata and Snort IDS sensors, investigating real network intrusion alerts and suspicious traffic patterns.
  • Ran vulnerability scans using Nessus, OpenVAS, and Qualys across client networks and lab environments, reviewing findings to support remediation prioritisation.
  • Configured DDoS mitigation controls and monitored traffic during an active event to support service continuity.
  • Built and tuned 10+ SIEM detection rules, reducing false-positive noise by an estimated 30% and improving alert fidelity and triage efficiency.
  • Executed SOC Tier 1 workflows: alert prioritisation, escalation decisions, and structured incident documentation aligned with ITIL practices.
  • Configured SOAR playbook automations to accelerate response to recurring alert types, cutting average investigation time by 25%.
  • Supported a real server recovery following a client incident, alongside scheduled backups and test restores after software updates.
  • Managed Microsoft 365 / Azure AD identities and IAM controls, enforcing MFA and conditional access policies for client environments.
  • Set up and supported a client website (ai-reachoutsolutions.com), bringing the same attention to detail to broader technical delivery work.
IT Support Assistant — New Era OS
Jun 2021 – Jun 2022
  • Resolved 20–30 support tickets per week with a 95%+ first-call resolution rate, handling L1/L2 hardware, software, Windows, and networking incidents within SLA targets.
  • Administered Active Directory accounts for 50+ users, including account provisioning, password resets, group policy, and access control (IAM).
  • Maintained structured incident records and knowledge base documentation aligned with ITIL v4 service management practices.
IT Technical Roles (Early Career) — East West Trade, EFA School, Digital Marketing Agency, Pakistan Post Office
2019 – 2021
  • Delivered first-line IT support across four organisations, covering hardware, software, networking, and user-access requirements for 100+ end users.
  • Troubleshot Windows, network, application, and peripheral issues, escalating complex incidents where required.
Projects

Detection engineering, SIEM & cloud security work

A complete SOC environment I built end to end, plus a set of focused projects across SIEM, cloud security, and automation.

Featured — Sysmon + Splunk Detection Engineering Lab
6
Detections built & mapped to MITRE ATT&CK
5
ATT&CK tactics covered in one lab
193+
Simulated detection events analysed
25+
Hands-on SOC investigation labs (across all projects)
01
Environment & Ingestion Pipeline
Stood up a Windows 11 VM instrumented with Sysmon (SwiftOnSecurity config), forwarding Security, Sysmon, and Windows Defender telemetry into Splunk Enterprise via Universal Forwarder. Debugged Windows Event Log channel permissions and Splunk license-violation lockouts along the way.
SysmonSplunk Universal ForwarderSplunk Enterprise
02
Attack Simulation & Detection Engineering
Used Atomic Red Team to simulate 6 real attack techniques across 5 MITRE ATT&CK tactics, then wrote and validated 6 custom SPL detections — including catching and fixing a case() logic-ordering bug that was silently miscategorizing events.
Atomic Red TeamSPLMITRE ATT&CK
03
Live SOC Dashboard
Built a Splunk Simple XML dashboard visualising detection volume, technique breakdown, and event-level detail with colour-coded severity — including debugging real schema validation errors when editing the dashboard source directly.
Simple XMLSplunk Dashboards
04
Formal Incident Report
Chained three detections into one narrative — Discovery → Credential Access → Persistence — and documented it the way a real analyst would: timeline, technique analysis, impact assessment, response actions, and remediation recommendations.
Incident ResponseReporting
View full repo on GitHub → Read the Incident Report →
Splunk SOC Overview Dashboard showing 193 total detections, 5 MITRE techniques covered, 184 Defender blocks, detection activity over time, and a colour-coded event table.
SOC Overview Dashboard — live Splunk instance 193 events · 5 techniques · dark theme
Technique
Detection
Status
T1082
System Information Discovery — systeminfo / registry recon via cmd, spawned from PowerShell
Detected
T1059.001
Encoded PowerShell command execution (-EncodedCommand)
Detected
T1047
PowerShell spawned via WMI Provider Host (WmiPrvSE.exe)
Detected
T1003.005
Credential Manager access via rundll32 / keymgr.dll (LOLBin)
Detected
T1053.005
Scheduled task persistence, created to run as SYSTEM on startup
Detected
T1055 / T1003
Process injection & credential-dumping tooling quarantined by Defender AV in real time
Blocked
Splunk Searches, Reports, and Alerts page listing 6 saved detection reports, each titled with a MITRE ATT&CK technique ID and description.
6 saved SPL detections, each mapped to a MITRE ATT&CK technique ID Splunk · Search & Reporting
Other Projects

A selection of independent projects covering the range a SOC or blue team role actually touches: on-prem SIEM, cloud log analysis, SOAR automation, and applied detection logic.

CloudTrail Security Analyzer
Python · AWS (CloudTrail, S3, IAM) · YAML · MITRE ATT&CK
Live-validated

Near real-time cloud threat detection pipeline: automated S3 log ingestion every 15 minutes, 11 Sigma-style YAML detection rules, and a multi-event correlation engine surfacing multi-step attack chains.

15real events detected
1,253CloudTrail logs parsed
11detection rules
CloudTrail Security Dashboard showing correlated multi-step incidents including Intrusion and Cover Tracks, Root Compromise, Persistence and Defense Evasion, Data Exfiltration Setup, and Destructive Attack chains.
View repo →
Sentinel SOC Ops & Automated IR
Microsoft Sentinel · Logic Apps · KQL · Azure RBAC
SOAR

Tuned noisy analytics rules, integrated threat intelligence, and built a fully automated detect-to-remediate lifecycle for a simulated leaked storage key — IP enrichment, auto-escalation, and automated key rotation.

0manual steps at remediation
T1098ATT&CK coverage extended
Full SOAR automation architecture: leaked storage key trigger chain, Logic App playbook determining severity based on IP reputation, role assignment, second automation rule, and automated key rotation outcome.
SOC Credential Access Monitoring Dashboard
Splunk · SPL · Regex Field Extraction
Dashboard

Multi-panel Splunk dashboard tracking Windows Security Event Log credential access activity, user behaviour, and system-level events, with regex-based field extraction for inconsistent log formats.

3hosts monitored
View repo →
SOC Brute Force Detection
Splunk · SPL · Windows Security Event Logs
T1110

Engineered SPL detection logic identifying repeated authentication failures (Event ID 4625), investigated 500+ simulated log events, and documented a full SOC Tier 1 triage workflow.

500+events investigated
12suspicious source IPs
Splunk search for failed authentication events, showing 626 matching events across Windows Application logs.
View repo →
AI-Powered Phishing Detector
Python · TensorFlow · Keras · NLTK · Flask
T1566

Bidirectional LSTM deep learning model trained on 82,486 real emails, deployed as a live Flask dashboard with confidence scoring — directly applicable to SOC phishing triage workflows.

98.46%test accuracy
82,486emails trained on
Phishing detector correctly classifying a legitimate team standup email with 99.98% confidence.
Phishing detector flagging a fraudulent account-suspension email with 99.97% confidence, highlighting suspicious keywords.
View repo →
AI-Powered Network Intrusion Detection
Python · scikit-learn · Random Forest · Flask
Live demo

Random Forest model trained on 125,973 NSL-KDD network traffic records, deployed as a live traffic-scanning dashboard classifying DoS, Probe, R2L, and U2R attacks in real time.

77.3%model accuracy
100decision trees
NetGuard AI-powered intrusion detection dashboard showing model accuracy, demo traffic scan results, and a live scan panel.
View repo →
Practical Training

CyberDefenders — SOC Analyst Tier 1

Hands-on investigation labs across four forensics disciplines, using the tools a Tier 1 / Tier 2 analyst reaches for daily.

Network Forensics
PCAP analysis, 7+ scenarios
Web server exploitation, XSS/session hijacking, LLMNR/NBT-NS poisoning, PsExec lateral movement, and malware C2 traffic (DanaBot) including deobfuscating malicious JavaScript — mapped to MITRE ATT&CK.
Wireshark · NetworkMiner · Brim · ANY.RUN
Cloud Forensics
AWS CloudTrail investigation
Identified unauthorized access, configuration changes, and persistence mechanisms in AWS log data.
Splunk
Threat Intelligence
IOC extraction, malware, C2 & supply chain analysis
Extracted IOCs and C2 infrastructure from phishing kits and malware samples (IcedID, RAT payloads); analysed executables and sandbox reports to identify stealer malware behaviour and privilege escalation mechanisms; reconstructed a real-world supply chain compromise (3CX) from MSI/DLL artifacts to attribute the incident to a threat actor.
VirusTotal · MalwareBazaar · ThreatFox · ANY.RUN
Endpoint Forensics
Memory, mobile & multi-stage attack reconstruction
Traced malicious processes and extracted network IOCs from memory dumps; analysed mobile device artifacts; investigated anti-NIDS evasion; reconstructed a multi-stage attack from a Windows memory dump, correlating findings with external threat intelligence to assess breach scope.
Volatility 3 · ALEAPP · Strings
Toolset

Technical skills

skills.sh
$ siem --list
Microsoft Sentinel, Splunk, Wazuh, Google Chronicle
$ frameworks --list
MITRE ATT&CK, ITIL v4, OWASP Top 10, STRIDE, PASTA, NIST CSF
$ cloud --list
AWS (CloudTrail, IAM), Microsoft Azure, Azure AD, Microsoft 365
$ forensics --list
Wireshark, NetworkMiner, Volatility 3, Autopsy, FTK, VirusTotal
$ scripting --list
Python, PowerShell, Bash, SQL, SPL, KQL
$ os --list
Windows Server, Linux (Ubuntu / Bash)
IBM Cybersecurity Analyst Professional Certificate
Google Cybersecurity Professional Certificate
ISC² Cybersecurity Certificate
Splunk Fundamentals
AWS Cloud Practitioner Essentials
Microsoft Azure Fundamentals
ITIL v4 Foundation
MSc Cybersecurity, Birmingham City University
KC7 Security Analyst 1 Badge →
From Colleagues & Clients

What people say about working with me

LinkedIn recommendations from classmates and clients I've worked with directly.

“

I worked with Shaheer in a freelance capacity, where he provided Security Operations Center support, including cybersecurity monitoring, SIEM log analysis, and incident investigation. His journey is genuinely impressive — he moved from Pakistan to build his career here, balancing his studies with part-time work while supporting his family. That discipline shows in how he works: methodical, reliable, and always keen to improve. I'm happy to recommend Shaheer for SOC Analyst roles.

Zafar Mahmood
Senior Business Analyst | Product Owner (PSPO I) | AI Automation Consultant
Managed Shaheer directly (freelance client)
“

I highly recommend Shaheer to any team seeking an exceptional cyber security operation analyst. He is undoubtedly one of the most dedicated professionals I know. Shaheer brings a rare combination of soft skills and deep technical expertise — a natural problem-solver, a dependable collaborator, and someone who consistently elevates the performance of those around him.

Junaid Karim
Senior Data Solution Architect
Worked with Shaheer on the same team
“

I had the pleasure of studying alongside Shaheer during our MSc in Cybersecurity at Birmingham City University. He consistently demonstrated a strong commitment to learning and excellence, with great interest in security operations, threat analysis, and incident response. His collaborative nature, problem-solving mindset, and determination to continuously improve make him a valuable asset to any cybersecurity team.

Areeba Sabahat
SOC Analyst | Microsoft Sentinel | Splunk | Blue Team Labs
Studied together, MSc Cybersecurity
“

I have known Shaheer as both a classmate and a friend, and one thing that has always stood out is his passion for cybersecurity. His practical experience in SOC operations, SIEM technologies, threat detection, and cloud security demonstrates the effort he has invested in building real-world expertise. He is approachable, dependable, and a great team player.

Sohail Ahmad
Artificial Intelligence Engineer | Cyber Security | Software Engineer
Studied together