I've investigated escalated incidents at CloudCard Inc. using CrowdStrike NG-SIEM, CrowdStrike, Wazuh, AWS services, and application security tooling to reconstruct attack timelines, identify root causes, and contain affected assets. I also tune detection rules, reduce false positives, and produce incident reports, dashboards, and security advisories.
Previously, I led end-to-end incident response at IT Butler E-Services and assessed SOC operations at National CERT – Pakistan, where I identified 10+ SIEM deficiencies, wrote SOC procedures, and trained eight analysts. I've also led vulnerability assessment work and delivered cybersecurity training and hands-on labs.
