Professional Summary
Mid-level SOC Analyst with hands-on experience in enterprise incident triage, threat detection, and SIEM rule development across hybrid IT environments. Experienced in investigating host and network anomalies, tuning detection logic to reduce alert fatigue, and coordinating containment during critical security events.
Professional Experience
Aethelgard Security Operations GmbH
Berlin, Germany
SOC Analyst (Tier 2)
Mar 2022 – Present
- Investigate escalated Tier 2 security alerts across 12,000 enterprise endpoints utilizing Splunk Enterprise Security and Microsoft Defender for Endpoint.
- Triage suspected phishing, ransomware, and lateral movement incidents, producing actionable containment steps and post-incident reviews.
- Develop and tune custom SIEM correlation rules and KQL detection queries, decreasing false-positive alert volume by 28%.
- Maintain and update incident response playbooks for credential dumping, web application attacks, and unauthorized cloud access.
Novasphere Digital Systems SE
Berlin, Germany
Junior SOC Analyst
Jan 2019 – Feb 2022
- Monitored real-time intrusion alerts and network telemetry using Elastic Stack and Zeek for 35 corporate client environments.
- Performed initial packet capture analysis with Wireshark to identify indicators of compromise during suspected perimeter scans.
- Authored initial triage tickets with severity classifications, escalating substantiated incidents to senior response engineers.
Education
HTW Berlin
Bachelor of Science · Computer Science · Berlin, Germany · 1.6 (German grading scale) · Oct 2014 – Sept 2018
Specialized in network security, operating systems, and distributed architectures. Completed a thesis investigating anomaly detection algorithms in enterprise network traffic.
Technical Projects
Homelab Threat Emulation Environment
Feb 2024 – Aug 2024
- Configured an isolated virtual testbed running Suricata and Sysmon to simulate and analyze adversary techniques from the MITRE ATT&CK matrix.
- Documented detection rules and shared Sigma rule implementations with an internal analyst study group.
Core Competencies
SIEM (Splunk, Elastic)
Endpoint Detection & Response (EDR)
Incident Handling
Network Traffic Analysis (Wireshark, Zeek)
Kusto Query Language (KQL)
Threat Intelligence (MITRE ATT&CK)
Log Analysis
Phishing Triage
Python Scripting
Digital Forensics Basics
Languages
German
C2
English
C1
Certifications
GIAC Certified Incident Handler (GCIH)
GIAC · May 2024
CompTIA Cybersecurity Analyst (CySA+)
CompTIA · Nov 2023
Volunteer Work
Berlin Cyber Youth Initiative
Berlin, Germany · Apr 2023 – Oct 2023
- Volunteer Workshop Mentor
- Assisted high school students with basic concepts of network defense, safe browsing practices, and capture-the-flag challenge walkthroughs.