Experience
SOC leadership, defense architecture, security engineering and investigations across enterprise and managed-service environments.
Nov 2025 - Present
Spark Professional Services
SOC Lead
Leadership & operations
- Lead and manage Resident SOC (RSOC) and Managed SOC (MSOC) teams, overseeing daily operations, service delivery, analyst performance, and technical development across client environments.
- Conduct SOC maturity assessments and develop roadmaps addressing people, processes, technology, and detection coverage.
- Develop and maintain SOC procedures for triage, investigation, escalation, incident response, and client reporting.
- Mentor L1–L3 analysts and engineers, reviewing investigation quality and supporting technical development.
Architecture & detection
- Design cyber defense architectures, aligning security telemetry, monitoring platforms, integrations, detection capabilities, and response workflows with client requirements and threat priorities.
- Design and govern a standardized detection use-case framework, including MITRE ATT&CK mapping, rule tuning, playbooks, and coverage review.
- Architect and maintain SIEM, SOAR, EDR, and threat intelligence integrations, aligning monitoring capabilities with client requirements.
- Support pre-sales and solution architecture through technical assessments, service design, and security platform integration planning.
Investigations & ThreatOps
- Lead and conduct Digital Forensics and Incident Response (DFIR) investigations, combining hands-on technical analysis with investigation coordination, response recommendations, and reporting.
- Manage ThreatOps across CTI, threat hunting, detection engineering, compromise assessments, and incident response, translating findings into defensive priorities and improvements.
- Lead and execute compromise assessments to identify evidence of adversary activity, assess affected systems, and recommend response actions.
Apr 2025 - Nov 2025
Fawry
Sr. Cyber Defense DFIR Analyst
Investigations & hunting
- Supported cyber defense investigations and incident response through analysis of security telemetry, threat intelligence, and adversary behavior.
- Conducted proactive threat hunting across EDR and SIEM telemetry, using MITRE ATT&CK to investigate suspicious behavior and identify detection gaps.
- Analyzed adversary techniques and campaign activity to guide hunting priorities, detection development, and response tuning.
Intelligence & automation
- Developed ThreatOps workflows connecting threat intelligence, hunting, investigations, and detection engineering to support coordinated defensive operations.
- Built and operated a CTI automation pipeline using MISP, n8n, and Python for IOC ingestion, enrichment, tagging, and correlation with internal telemetry.
- Developed intelligence collection and processing capabilities, including RSS feed ingestion and parsing, to support internal threat intelligence requirements.
- Established CTI procedures covering collection planning, analysis, and dissemination to technical teams and stakeholders.
- Integrated threat intelligence, hunting, and incident response workflows across security platforms, reducing manual processing and improving access to relevant context.
Aug 2024 - Mar 2025
Fawry
Sr. Cyber Defense Engineer
SOC leadership & engineering
- Led the SOC team, coordinating daily security operations, technical priorities, and investigation escalations.
- Administered and optimized SIEM, SOAR, EDR, XDR, NDR, and threat intelligence platforms supporting enterprise security monitoring and response.
- Implemented security platform integrations and automated workflows to connect telemetry, enrichment, investigation, and response capabilities.
- Developed detection use cases and assessed security technology coverage against MITRE ATT&CK, producing heat maps to help management prioritize defensive improvements.
Assessment & intelligence
- Conducted security product assessments and contributed to proofs of concept across EDR, NDR, XDR, SOAR, threat intelligence, email security, Attack Surface Management, and Digital Risk Protection solutions, evaluating capabilities, integration requirements, and operational suitability.
- Built a cyber threat intelligence program using MISP, threat intelligence platforms, and open-source intelligence to support detection and investigation activities.
- Managed Digital Risk Protection, Attack Surface Management, and dark web monitoring cases, investigating findings and coordinating escalation and follow-up.
Operations & reporting
- Automated recurring SOC tasks to reduce manual processing and support timely investigations and response.
- Prepared incident response reports for management, communicating findings, lessons learned, and recommended improvements.
- Collaborated with GRC on PCI DSS log simulation and SOC-related compliance requirements.
Jan 2024 - Aug 2024
Fawry
Cyber Defense Engineer
- Managed TheHive for security incident case management and SOC investigation workflows.
- Automated recurring SOC processes to reduce manual work and support investigation efficiency.
- Conducted EDR assessments to evaluate endpoint security capabilities and identify areas for improvement.
- Supported the SOC team in investigating and handling complex security incidents.
- Administered SIEM capabilities supporting security monitoring and analysis.
- Collaborated with GRC on SOC-related requirements and operational processes.
Nov 2023 - Aug 2024
onebank (formerly MDI)
Sr. SOC Analyst
Outsourced via ITS.
- Helped establish SOC operations for onebank, contributing to monitoring capabilities, investigation workflows, and operational processes.
- Implemented TheHive to support incident case management and SOC response workflows.
- Developed detection use cases, rules, and playbooks aligned with the bank’s requirements, collaborating with GRC and operational teams.
- Improved threat detection, monitoring, and response capabilities through ongoing review of SOC tools and processes.
- Reviewed L1 analysts’ investigations, identified quality and process gaps, and recommended improvements.
- Mentored L1 analysts and recommended training based on their technical development needs.
- Supported SIEM and SOAR administration to maintain effective monitoring and investigation capabilities.
- Reviewed threat intelligence feeds and indicators of compromise to inform monitoring and proactive investigations.
Aug 2022 - Nov 2023
Fawry
Sr. SOC & Incident Response Engineer
- Conducted in-depth investigations of incidents escalated by L1 analysts and prepared incident response reports documenting findings and recommendations.
- Improved detection and response capabilities through purple team exercises, translating findings into detection and monitoring improvements.
- Designed automated workflows to support threat investigation, analysis, and SOC operations.
- Integrated security platforms with the SIEM and implemented TheHive for incident case management and response workflows.
- Developed SOC procedures, detection use cases, and response playbooks, reviewing their effectiveness as operational needs evolved.
- Conducted threat hunting using adversary tactics, techniques, and procedures, alongside indicators received from the Central Bank of Egypt and threat intelligence platforms.
- Monitored dark web sources for exposed business accounts and potential data breaches, investigating findings and coordinating follow-up actions.
- Reviewed L1 analysts’ work, identified skills gaps, and recommended targeted training.
- Collaborated with GRC on PCI-related log simulation and SOC compliance requirements.
Dec 2021 - Aug 2022
Fawry
SOC Analyst
- Monitored security alerts across multiple platforms as part of 24/7 SOC operations.
- Investigated alerts, filtered false positives, and escalated suspected incidents with supporting evidence to the appropriate response teams.
- Recommended detection-rule tuning to improve alert quality and reduce false positives.
- Reviewed threat intelligence feeds for emerging threats relevant to the organization’s environment.
- Conducted threat hunting across critical systems and log sources to identify suspicious activity and security misconfigurations.
- Investigated indicators of compromise shared by EG-FinCERT and the Central Bank of Egypt.
- Produced periodic SOC reports covering detected threats, investigations, and incident activity.
- Handled brand-protection alerts involving impersonating websites, social media accounts, and mobile applications, supporting takedown actions.
Jul 2021 - Oct 2021
National Telecommunication Institute (NTI)
Cyber Security Trainee
- Completed practical cybersecurity and network-security training covering CCNA, CCNA Security, FortiGate, ethical hacking, CyberOps Associate, and Security Onion.
- Gained hands-on lab experience with Cisco 4000-series routers, 2900-series switches, and ASA 5506-series firewalls.
- Configured VPNs using Cisco routers, Cisco ASA with FirePOWER, and FortiGate firewalls.
- Practiced identifying network attacks and implementing mitigation controls using Cisco ASA and FortiGate.
- Used SIEM and network-monitoring tools in lab exercises to investigate simulated attacks against networks and systems.