Skip to main content
Zain AliZA
Open to opportunities

Zain Ali

@zainali20

Senior security engineer building automated SOCs, SIEM detections, and vulnerability programs.

Australia
Message

What I'm looking for

I’m looking for a role where I can keep building and automating SOC operations—SIEM/EDR detections, incident response runbooks, and vulnerability management—while partnering cross-functionally to improve measurable security outcomes and compliance.

I’m a Senior Security Engineer who built a Security Operations Center (SOC) from the ground up, scaling maturity from 1 to maturity 3 with automated processes and workflows. I also lead brand reputation management work with threat intelligence providers to resolve domain reputation issues and whitelist legitimate domains.

I design and implement SIEM capabilities end-to-end, including building Splunk SIEM from scratch with data ingestion, detection rules (correlation searches), and dashboards. I’ve also implemented risk-based alerting (RBA) to correlate events, reduce alert fatigue, and improve threat detection efficiency, while fine-tuning SIEM rules to lower noise and false positives. In parallel, I administer LogRhythm and have used LogRhythm threat detection with AI Engine and LogRhythm Custom MPE Rules using regular expressions.

I engineer vulnerability management programs from the ground up, setting up vulnerability scanning, risk prioritization, and remediation processes aligned to security policy and risk posture. I deploy Endpoint Detection and Remediation (EDR) to increase visibility, strengthen detection, and improve incident response, and I develop incident response playbooks and runbooks to standardize investigations. I also work across Zero trust principles and conditional access policies, and enhance data security with Microsoft 365 DLP policies including tagging and alerting.

I’m hands-on with governance and readiness: I led the evaluation, selection, and implementation of an enterprise email security solution, and I manage the approval lifecycle for AI applications and browser extensions to mitigate internal AI risks. I’ve mentored junior SOC analysts and engineers, run purple team exercises with reporting, and strengthened SOC procedures through continuous improvement.

Experience

Work history, roles, and key accomplishments

WR
Current

Senior Security Engineer

WRKR

Oct 2023 - Present (2 years 9 months)

Built and scaled a Security Operations Center (SOC) with automated workflows, and led vulnerability management, EDR deployment, and SIEM engineering. Delivered security awareness programs, detection/risk-based alerting improvements, and incident response runbooks/playbooks.

OF

Senior Security Operations Engineer

Officeworks

Oct 2021 - Aug 2023 (1 year 10 months)

Led MSSP SOC/MDR oversight and managed organization-wide vulnerability management and incident response activities. Reengineered SOC and SIEM operations to reduce noise, improved compliance-related controls, and supported Microsoft stack security uplift projects.

SM

Network Security Administrator

Sparx Solutions (MSP)

Aug 2020 - May 2021 (9 months)

Managed security monitoring and firewall-related alerting while supporting patching automation and incident handling across endpoints and network infrastructure. Deployed and configured Palo Alto controls and administered monitoring and reporting tools for network visibility.

Education

Degrees, certifications, and relevant coursework

Swinburne University of Technology logoST

Swinburne University of Technology

Bachelor of Computer Science, Cybersecurity

Bachelor of Computer Science with a major in Cybersecurity at Swinburne University of Technology.

Get matched with your dream remote job

Sign up now and join over 250,000+ remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan