Skip to content
Open to Security Engineering & SOC roles — 2026

Waleed BukhariEngineering defence across Threat Intelligence

I build the bridge between deep network forensics and intelligent automation — turning raw packets, malware and threat feeds into decisions a SOC can act on.

Dubai, United Arab Emirates
IPv4185.220.101.42
MITRET1566.001 · Spearphishing
URLhxxp://serve[.]html/payload
CVECVE-2014-3566 · POODLE
HASHa3f9…svchost.dll
MITRET1543.003 · Windows Service
FEEDURLhaus sync · 30m
CVECVE-2016-0800 · DROWN
IPv4192.168.121.151 · pivot
MITRET1021.001 · RDP lateral
FEEDThreatFox ingest · OK
IPv4185.220.101.42
MITRET1566.001 · Spearphishing
URLhxxp://serve[.]html/payload
CVECVE-2014-3566 · POODLE
HASHa3f9…svchost.dll
MITRET1543.003 · Windows Service
FEEDURLhaus sync · 30m
CVECVE-2016-0800 · DROWN
IPv4192.168.121.151 · pivot
MITRET1021.001 · RDP lateral
FEEDThreatFox ingest · OK
10+
Technical projects shipped
4
Industry programs
30+
MITRE ATT&CK techniques mapped
100%
Local, air-gapped AI analysis
Selected work

10 deep case studies, not a wall of logos

Each project is written up like an engagement report — the problem, the approach, the architecture and the measured result. Click any card for the full breakdown.

Featured2025–26
Offensive Security · Reverse Engineering

Penetration Testing & Malware Investigations

Black-box pentest + multi-sample malware reverse engineering

Penetration TestingMalware AnalysisReverse Engineering
Case study
Featured2025
Digital Forensics · OT/ICS

Network Forensics & ICS Security

Reconstructing a multi-stage SCADA attack from packets

Network ForensicsICS / SCADAIncident Response
Case study
2025–26
Incident Response · Threat Intelligence

Incident Response Maturity & Threat Intel

A SIM3 maturity assessment and STIX threat-intel structuring for a logistics SME

Incident ResponseThreat IntelligenceSIM3 / ENISA
Case study
2025
Machine Learning · SOC Automation

AI-Driven Phishing Detection

Adversarially-tested ML over 235k URLs for SOC automation

Machine LearningSOC AutomationPhishing
Case study
2025
Applied Cryptography

Cryptography & Encryption

Cipher design, RSA cryptanalysis and protocol attack simulation

CryptographyCryptanalysisRSA
Case study
2025–26
Secure Software · Web App

FreightDesk — Secure Business Application

A hardened Flask logistics portal with live FX, RBAC and a full security self-assessment

Secure CodingWeb AppOWASP
Case study
2025–26
Secure Coding · Systems C++

Secure Password Manager (C++)

An AES-256-GCM credential vault in modern C++ built on real OpenSSL crypto

C++CryptographySecure Coding
Case study
Featured2024–25
Full-Stack · SaaS Platform

ConTrust OS

Data-first construction ERP — logistics, procurement & finance

Full-StackSaaSPostgreSQL
Case study
2025–26
Software Development · Secure Coding

Secure Coding Fundamentals

Two small Python builds that show security thinking, not just working code

PythonSecure CodingTesting
Case study

All work grounded in real coursework, the WalSec final-year project and internship reports.

Capability map

The stack behind the defence

A T-shaped skill set: deep in threat intelligence and network forensics, broad across offensive testing, secure software, applied AI and cloud. The radar is a self-assessment; the columns are the tools I actually reach for.

Threat IntelForensicsOffensiveSoftwareAI / MLCryptoCloud92908285847876
Self-assessed proficiency · 0–100 across core domains

Threat Intel & SOC

  • MITRE ATT&CK (Enterprise + ICS)
  • SIEM / SOC Operations
  • Splunk
  • Wazuh / EDR
  • Threat Hunting
  • Incident Response (NIST SP 800-61)
  • OSINT — ThreatFox · URLhaus · Abuse.ch

Offensive & Forensics

  • Penetration Testing (black-box)
  • Nessus / Nmap / Metasploit
  • Burp Suite
  • Malware Analysis (static + dynamic)
  • Reverse Engineering — IDA · GDB · REMnux
  • Wireshark / TShark / PyShark
  • testssl.sh / OpenSSL

Networking & ICS

  • Packet Analysis & DPI
  • VLAN / NAT / Static Routing
  • Firewall Rules & Segmentation
  • Cisco Packet Tracer
  • SCADA / OT Security
  • CARVER Risk Assessment

Software & AI

  • Python — Flask · PyShark · scikit-learn
  • C++
  • React 18 / Next.js
  • Local LLMs — Ollama · Llama 3.2
  • RAG + BGE-M3 embeddings
  • ML — XGBoost · Random Forest · MLP
  • SQL / SQLite (WAL)

Cloud & DevSecOps

  • Microsoft Azure (Security focus)
  • Docker / Docker Compose
  • CI/CD (GitHub Actions)
  • SAST / DAST
  • JWT · bcrypt · RBAC
  • ISO 27001 / GDPR

Cryptography

  • AES-256 / SHA-256
  • RSA & Cryptanalysis
  • Key-Exchange Protocols
  • Symmetric & Public-Key Crypto
  • TLS / SSL Hardening
Track record

Experience & credentials

Hands-on security work across industry programs, backed by a cybersecurity degree and professional certifications.

Professional experience

Cyber Security Intern

Jun 2025 – Sep 2025
Receptive Tech Communications·Lahore, PakistanInternship
  • Improved threat-detection accuracy by 20% by refining SIEM rules and tuning alert thresholds, reducing false positives during triage.
  • Contributed to a 25% drop in endpoint vulnerabilities via scans, patch verification and flagging misconfigurations across assets.
  • Cut incident-response time 15–20% by updating escalation matrices and drafting playbooks.

Cyber Security Analyst

2025
Telstra Cybersecurity·Virtual ExperienceJob Simulation
  • Responded to a simulated malware attack, reducing threat impact by 80% through timely containment and mitigation.
  • Performed post-incident analysis, identifying 3 key vulnerabilities and recommending 5 targeted hardening improvements.

Security Awareness Analyst

2025
Mastercard Cybersecurity·Virtual ExperienceJob Simulation
  • Served as an analyst on Mastercard’s Security Awareness Team, identifying and reporting phishing threats.
  • Assessed gaps in employee security awareness and helped implement targeted training across high-risk business units.

Cyber Security Analyst

2025
Deloitte Australia Cybersecurity·Virtual ExperienceJob Simulation
  • Analysed web-activity logs for cybersecurity incidents and investigated suspicious user activity.
  • Supported a client through a cyber-security breach, answering investigative questions to identify the source.
Education

BSc (Hons) Cyber Security

De Montfort University, Dubai

EQF Level 6 · Final-year / recent graduate

2023 – 2026

Certifications

Cybersecurity Professional Certificate

May 2025

Google

8-course program — detection & response, Python automation, Linux, SQL, threat analysis

Generative AI Engineering Professional

Aug 2025

IBM

Generative AI applications & prompt engineering

Certified Foundations Associate (AI & Cloud)

Jul 2025

Oracle

AI Foundations + OCI Foundations Associate

Who I am

A SOC analyst who can also write the tooling

BSc (Hons) Cybersecurity from De Montfort University, Dubai, and a hands-on builder. I specialise in threat intelligence, network forensics and SOC automation — and I ship the software to back it up, from a fully-local, LLM-powered SIEM-Lite platform to ML phishing detectors and C++ security tooling. Industry experience across Telstra, Mastercard, Deloitte and Receptive Tech, where I cut response time, hardened endpoints and contained simulated attacks.

Analyst instinct

I read the wire and the logs first — packets, IOCs and behaviour mapped to MITRE ATT&CK before I touch a tool.

Builder’s hands

I ship the software behind the defence: a local LLM SIEM-Lite, ML detectors, C++ security tooling and full-stack products.

Defence that ships

Every finding lands with a fix — detection logic, hardening steps and controls a team can act on Monday morning.

Open to Security Engineering & SOC roles — 2026

Let’s harden something together.

I’m looking for Security Engineering, SOC and Threat-Intelligence roles where I can analyse the threat and build the tooling that answers it. If that’s the kind of person your team needs, let’s talk.

Hire me