Esmail Al_Rahbi
@esmailal_rahbi
I build threat detection and incident response capabilities across SIEM and endpoint security platforms.
What I'm looking for
I've supported Security Operations Center monitoring at Yemen Armored Security & Safety, using Wazuh and Splunk to investigate Windows Event Logs, Syslog, and network traffic across client environments.
I triage alerts through detection and containment following NIST 800-61, map IOCs and TTPs to MITRE ATT&CK, and use MISP, VirusTotal, and AbuseIPDB to enrich investigations. I also contribute to threat hunting, SIEM correlation-rule tuning, SOC shift logs, escalation records, and asset inventory.
In a financial-wallet mobile security assessment, I performed Android APK reverse engineering, static and dynamic analysis, runtime manipulation, traffic interception, and API security testing. I identified three critical static-analysis vulnerabilities, including hardcoded API keys rated CVSS 8.5+, and delivered PoC-backed remediation guidance.
I'm building on hands-on work with SIEM, EDR, vulnerability assessment, OSINT, Active Directory, LDAP, and Python automation. I developed Smart Executive Agent, an AI-powered SIEM/SOAR platform designed to process over 10,000 events per second, achieve 94% anomaly-detection accuracy, and reduce analyst investigation time by 40%.
Experience
Work history, roles, and key accomplishments
1. Performed full-scope mobile penetration test on a financial wallet application (Android)
1. Conducted APK reverse engineering and static analysis to identify hardcoded secrets and insecure configurations
1. Executed dynamic analysis including runtime manipulation, traffic interception, and API security testing
1. Identified and documented critical vulnerabilities including insecure data stor
Security Operations Center Analyst
Apr 2025 - May 2026 (1 year 1 month)
Supported real-time security monitoring using Wazuh and Splunk, analyzing Windows Event Logs, Syslog, and network traffic (Wireshark) across client environments. Assisted in triaging security alerts through full incident lifecycle (detection → containment) per NIST 800-61, mapping IOCs and TTPs to MITRE ATT&CK. Participated in threat hunting exercises and contributed to SIEM correlation rule tunin
Education
Degrees, certifications, and relevant coursework
AL Jeel AL Jadeed University
Bachelor of Science, Cyber/Electronic Operations and Warfare
2021 - 2025
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Job categories
Skills
Interested in hiring Esmail?
You can contact Esmail and 90k+ other talented remote workers on Himalayas.
Message EsmailGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
