Skip to main content
soufiane taoufikST
Looking for a job

soufiane taoufik

@soufianetaoufik

I investigate security alerts, endpoint evidence, and identity activity across SOC environments.

United Kingdom
Message

What I'm looking for

I'm looking for security work supporting AI-enabled products and real user systems, where I can investigate alerts, develop SOC workflows, and continue building my SIEM and incident-response skills.

I've monitored managed customer environments at Abacus Group, triaging suspicious sign-ins, phishing alerts, account lockouts, and endpoint activity in Rapid7 InsightIDR.

I investigated authentication, email, and endpoint evidence using Microsoft 365, Entra ID, SentinelOne, Microsoft Defender, Proofpoint, Mimecast, and Duo MFA. I documented findings, user impact, affected accounts, and recommended next steps for escalation and case closure.

I've also built Splunk searches and dashboards for Lloyds Banking Group / GlobalLogic, and maintain a home SOC lab using Splunk, Sysmon, Windows Event Logs, KQL, Wireshark, Active Directory, and Windows endpoints.

Experience

Work history, roles, and key accomplishments

LG

Splunk Engineer Intern

Lloyds Banking Group / GlobalLogic

Jul 2023 - Sep 2023 (2 months)

Built and refined Splunk searches and dashboard panels to support log review and monitoring use cases. Filtered security and operational logs by fields, timestamps, sourcetypes, and hosts to make events easier to review.

Lloyds Banking Group logoLG

Splunk Engineer Intern

Jul 2023 - Aug 2023 (1 month)

During my internship at Lloyds, I gained hands-on experience with a variety of cybersecurity technologies, including Splunk, Sentinel, and SentinelOne. One of my key accomplishments was learning how to set up and configure Splunk rules, based on the criteria defined by threat modelers. This allowed me to deepen my understanding of proactive threat detection and response.

Beyond the technical skil

Education

Degrees, certifications, and relevant coursework

Microsoft logoMI

Microsoft

SC-200 Microsoft Security Operations Analyst, Security Operations

Currently studying for the SC-200 Microsoft Security Operations Analyst certification, focusing on Microsoft Sentinel, Defender, incident queues, KQL, alert investigation and response workflows.

EU

Edinburgh Napier University

BEng (Hons) Cybersecurity & Forensics

2020 - 2024

RA

Rapid7

InsightIDR Certified Specialist

Issued May 2024

SE

SentinelOne

Singularity Enterprise Foundations

Issued May 2024 · Expired May 2025

Edinburgh Napier University logoEU

Edinburgh Napier University

BEng (Hons), Cybersecurity and Forensics

Grade: 2:1

BEng (Hons) Cybersecurity and Forensics degree from Edinburgh Napier University, completed in 2024 with a 2:1 classification.

Edinburgh College logoEC

Edinburgh College

HND, Networking

2020 - 2022

HND Networking from Edinburgh College, covering routing, switching, TCP/IP, subnetting, network services and troubleshooting fundamentals.

Tech stack

Software and tools used professionally

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan