Skip to main content
Esmail Al_RahbiEA
Open to opportunities

Esmail Al_Rahbi

@esmailal_rahbi

I build threat detection and incident response capabilities across SIEM and endpoint security platforms.

Yemen
Message

What I'm looking for

I'm seeking challenging cybersecurity environments where I can improve SIEM platforms, strengthen threat detection and incident response, and help build robust security defenses.

I've supported Security Operations Center monitoring at Yemen Armored Security & Safety, using Wazuh and Splunk to investigate Windows Event Logs, Syslog, and network traffic across client environments.

I triage alerts through detection and containment following NIST 800-61, map IOCs and TTPs to MITRE ATT&CK, and use MISP, VirusTotal, and AbuseIPDB to enrich investigations. I also contribute to threat hunting, SIEM correlation-rule tuning, SOC shift logs, escalation records, and asset inventory.

In a financial-wallet mobile security assessment, I performed Android APK reverse engineering, static and dynamic analysis, runtime manipulation, traffic interception, and API security testing. I identified three critical static-analysis vulnerabilities, including hardcoded API keys rated CVSS 8.5+, and delivered PoC-backed remediation guidance.

I'm building on hands-on work with SIEM, EDR, vulnerability assessment, OSINT, Active Directory, LDAP, and Python automation. I developed Smart Executive Agent, an AI-powered SIEM/SOAR platform designed to process over 10,000 events per second, achieve 94% anomaly-detection accuracy, and reduce analyst investigation time by 40%.

Experience

Work history, roles, and key accomplishments

Security Assessment Engagement logoSE

Penetration Tester

Jan 2026 - May 2026 (4 months)

1. Performed full-scope mobile penetration test on a financial wallet application (Android)

1. Conducted APK reverse engineering and static analysis to identify hardcoded secrets and insecure configurations

1. Executed dynamic analysis including runtime manipulation, traffic interception, and API security testing

1. Identified and documented critical vulnerabilities including insecure data stor

Yemen Armored Security & Safety logoYS

Security Operations Center Analyst

Apr 2025 - May 2026 (1 year 1 month)

Supported real-time security monitoring using Wazuh and Splunk, analyzing Windows Event Logs, Syslog, and network traffic (Wireshark) across client environments. Assisted in triaging security alerts through full incident lifecycle (detection → containment) per NIST 800-61, mapping IOCs and TTPs to MITRE ATT&CK. Participated in threat hunting exercises and contributed to SIEM correlation rule tunin

Education

Degrees, certifications, and relevant coursework

AU

AL Jeel AL Jadeed University

Bachelor of Science, Cyber/Electronic Operations and Warfare

2021 - 2025

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan