
soufiane taoufik
@soufianetaoufik
I investigate security alerts, endpoint evidence, and identity activity across SOC environments.
What I'm looking for
I've monitored managed customer environments at Abacus Group, triaging suspicious sign-ins, phishing alerts, account lockouts, and endpoint activity in Rapid7 InsightIDR.
I investigated authentication, email, and endpoint evidence using Microsoft 365, Entra ID, SentinelOne, Microsoft Defender, Proofpoint, Mimecast, and Duo MFA. I documented findings, user impact, affected accounts, and recommended next steps for escalation and case closure.
I've also built Splunk searches and dashboards for Lloyds Banking Group / GlobalLogic, and maintain a home SOC lab using Splunk, Sysmon, Windows Event Logs, KQL, Wireshark, Active Directory, and Windows endpoints.
Experience
Work history, roles, and key accomplishments
Security Operations Analyst Intern
Abacus Group
Apr 2024 - Aug 2024 (4 months)
Monitored alerts in Rapid7 InsightIDR and reviewed suspicious sign-ins, account lockouts, phishing alerts, and endpoint activity. Investigated authentication, email, and endpoint evidence using Microsoft 365, Entra ID, SentinelOne, Microsoft Defender, Proofpoint, Mimecast, and Duo MFA.
Splunk Engineer Intern
Lloyds Banking Group / GlobalLogic
Jul 2023 - Sep 2023 (2 months)
Built and refined Splunk searches and dashboard panels to support log review and monitoring use cases. Filtered security and operational logs by fields, timestamps, sourcetypes, and hosts to make events easier to review.
During my internship at Lloyds, I gained hands-on experience with a variety of cybersecurity technologies, including Splunk, Sentinel, and SentinelOne. One of my key accomplishments was learning how to set up and configure Splunk rules, based on the criteria defined by threat modelers. This allowed me to deepen my understanding of proactive threat detection and response.
Beyond the technical skil
Education
Degrees, certifications, and relevant coursework
Microsoft
SC-200 Microsoft Security Operations Analyst, Security Operations
Currently studying for the SC-200 Microsoft Security Operations Analyst certification, focusing on Microsoft Sentinel, Defender, incident queues, KQL, alert investigation and response workflows.
Edinburgh Napier University
BEng (Hons) Cybersecurity & Forensics
2020 - 2024
Rapid7
InsightIDR Certified Specialist
Issued May 2024
SentinelOne
Singularity Enterprise Foundations
Issued May 2024 · Expired May 2025
Edinburgh Napier University
BEng (Hons), Cybersecurity and Forensics
Grade: 2:1
BEng (Hons) Cybersecurity and Forensics degree from Edinburgh Napier University, completed in 2024 with a 2:1 classification.
Edinburgh College
HND, Networking
2020 - 2022
HND Networking from Edinburgh College, covering routing, switching, TCP/IP, subnetting, network services and troubleshooting fundamentals.
Tech stack
Software and tools used professionally
Availability
Location
Authorized to work in
Salary expectations
Social media
Job categories
Skills
Interested in hiring soufiane?
You can contact soufiane and 90k+ other talented remote workers on Himalayas.
Message soufianeGet matched with your dream remote job
Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!
