Skip to main content
HimalayasHimalayas logo
wassim ben guiratWG
Open to opportunities

wassim ben guirat

@wassimbenguirat

I’m a Network & System Security Engineer focused on SOC operations and incident response.

Tunisia
Message

What I'm looking for

I’m seeking SOC Analyst, IT Security Manager, or Security Infrastructure Engineer roles where I can run multi-SIEM monitoring, lead incident response, and harden Linux/Windows environments. I want to keep growing in Linux distributed systems and forensics.

I’m a results-driven Network & System Security Engineer with 4+ years of experience in SOC operations, IT infrastructure security, and team leadership. I’m an active member of CERT Tunisia, and I build reliable detection and response workflows that turn security signals into actionable outcomes.

In SOC L1/L2 roles, I monitored and correlated security events across multiple SIEM platforms (Microsoft Sentinel, IBM QRadar, Splunk, LogRhythm, FortiSIEM, OSSIM AlienVault, Security Onion) and tuned correlation rules to reduce false positives. I investigated phishing campaigns, suspicious URLs, unauthorized access attempts, and malware alerts—then executed initial containment like account disabling, host isolation, and firewall rule modifications—while documenting incident timelines, IOCs, and root cause analysis.

I also strengthen threat intelligence and adversary understanding through OSINT and proactive hunting. I performed dark web monitoring with Tor, Ahmia, and Recon-ng, tracked leaked credentials, and delivered weekly intelligence reports to help clients reset compromised credentials and mitigate risks before exploitation. When handling TA505 ransomware, I led post-breach reconstruction, contained the threat within 45 minutes by isolating hosts and blocking C2 domains, and performed reverse engineering with IDA Free, Ghidra, x64dbg, and dnSpy—then documented YARA rules for detection and shared IOCs with CERT Tunisia.

Beyond detection, I secure the environment end-to-end through hardening, governance, and service tooling. As Head of IT Department, I designed backup and disaster recovery strategies using Veeam Backup & Replication and Duplicati, hardened Windows/Linux systems using CIS benchmarks and controls like fail2ban, AppArmor, and iptables, deployed GLPI with RBAC/LDAP and audit logging, managed Microsoft 365 security (Conditional Access, MFA enforcement, Defender for Office 365, and DLP), and improved monitoring with VLAN segmentation and Wazuh XDR (FIM, log analysis, real-time alerts). I bring the same discipline from SOC to infrastructure security: playbooks, SOPs, standardized incident response documentation, and continuous improvement.

Experience

Work history, roles, and key accomplishments

PT

Head of IT Department

Printea Tunis

Jan 2025 - Dec 2025 (11 months)

Designed and managed backup and disaster recovery using Veeam Backup & Replication and Duplicati, implementing a 3-2-1 strategy with automated restore testing to meet RPO/RTO requirements. Hardened Windows Server (2019/2022) and Linux per CIS benchmarks, deployed GLPI with RBAC/LDAP and audit logging, governed Microsoft 365 security (Entra ID, MFA, Defender for Office 365, DLP), and ran phishing s

KG

SOC Engineer L1/L2

Keystone Group

May 2024 - Dec 2024 (7 months)

Monitored and correlated security events across multiple SIEMs (Microsoft Sentinel, IBM QRadar, Splunk, and others), performing L1/L2 triage and tuning detections to reduce false positives. Investigated phishing and malware activity, conducted dark web OSINT monitoring with weekly reports, and led TA505 ransomware incident reconstruction, containing the threat within 45 minutes and mapping the att

HE

Service Desk Analyst

HelpLine (Everience)

Jan 2023 - May 2024 (1 year 4 months)

Monitored cloud-based contact center infrastructure for Odigo using Splunk and Netcool, created dashboards and alerts for system health metrics, and reduced MTTD for critical incidents through faster detection. Managed incidents and tickets via Remedy and ServiceNow (ITIL workflows), supported Windows/Linux administration and security hardening, assisted network migration and firewall rule reviews

CO

Customer Service Representative

Concentrix

Aug 2022 - Jan 2023 (5 months)

Handled account management and complaint processing for French customers, managing after-sales service requests and customer support workflows. Coordinated responses to service issues and ensured timely resolution for customer inquiries.

Education

Degrees, certifications, and relevant coursework

IT

Iteamuniversity

Network and System information Security Engineer, Network and System Information Security

2020 - 2024

Completed a Network and System Information Security Engineer program at Iteamuniversity in Tunis, Tunisia from 2020 to 2024.

HT

High Institut of Technologie

Network and computer Services

2015 - 2020

Studied Network and computer services at High Institut of Technologie in Tunis, Tunisia from 2015 to 2020.

Tech stack

Software and tools used professionally

Find your dream job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan