Skip to main content
IG
Open to opportunities

Ismail Abdul Ghafoor

@ismailabdulghafoor

Cyber Security Operations Manager at HMRC who cut false positives by 97%+ across 300+ detections.

United Kingdom
Message

At His Majesty’s Revenue and Customs, I moved 300+ detections to entity-based Risk-Based Alerting on Splunk ES and SOAR, cutting alerts from around 4,000 to around 400 a month and false positives by 97%+, while raising true positives by 80%+. I oversee 350+ detections across Splunk, MDE and CrowdStrike, and am developing a CI/CD pipeline to test and benchmark detections before production.

Alongside my government security operations work, I build Rust security tools and systems. Hisn.io is an edge security platform with a custom rules engine; BabySOARus runs sandboxed WebAssembly components inside Splunk; and Rasm compiles Sigma rules into detection formats for multiple SIEMs.

Experience

Work history, roles, and key accomplishments

His Majesty's Revenue and Customs logoHC
Current

Cyber Security Operations Manager & Technical Lead

Mar 2023 - Present (3 years 7 months)

Led the migration of 300+ detections to entity-based Risk-Based Alerting on Splunk ES & SOAR, cutting false positives by 97%+ and raising true positives by 80%+. Oversaw 350+ detections across Splunk, MDE, and CrowdStrike, and developed a detection CI/CD pipeline.

RL

Cyber Security Operations Manager & Technical Lead

Revenue & Customs Digital Technology Services Limited

Nov 2022 - Mar 2023 (4 months)

Led the Detect & Identify (Tier 1) function, managing daily operations and overseeing 20+ staff. Developed KPIs and performance metrics to improve response times and detection, and built relationships with external stakeholders such as the NCSC.

Her Majesty's Revenue and Customs logoHC

Junior Cyber Security Analyst

Jan 2018 - Jun 2018 (5 months)

Worked on External Phishing and Brand Abuse functions within the Customer Protection strand.

Education

Degrees, certifications, and relevant coursework

SANS Institute logoSI

SANS Institute

SANS SEC555: Detection Engineering and SIEM Analytics; FOR610: Reverse-Engineering Malware, Cyber Security

Completed SANS SEC555: Detection Engineering and SIEM Analytics and FOR610: Reverse-Engineering Malware.

Splunk logoSP

Splunk

Splunk Enterprise Security; Splunk Core Certified User; Splunk Fundamentals 1 & 2, Cyber Security

Earned Splunk Enterprise Security, Splunk Core Certified User, and Splunk Fundamentals 1 & 2 certifications.

BCS logoBC

BCS

Level 4 Certificates in Cyber Security, Cyber Security

Earned 5 Level 4 Certificates in Cyber Security from BCS.

City & Guilds logoCG

City & Guilds

Level 4 Cyber Security Technologist, Cyber Security

Achieved Level 4 Cyber Security Technologist qualification from City & Guilds.

CrowdStrike logoCR

CrowdStrike

CST 350: Deriving Intelligence from Falcon Sandbox, Cyber Security

Completed CrowdStrike CST 350: Deriving Intelligence from Falcon Sandbox.

Interested in hiring Ismail?

You can contact Ismail and 90k+ other talented remote workers on Himalayas.

Message Ismail

People also viewed

View all talent

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan