Waleed BukhariEngineering defence across Threat Intelligence
I build the bridge between deep network forensics and intelligent automation — turning raw packets, malware and threat feeds into decisions a SOC can act on.
10 deep case studies, not a wall of logos
Each project is written up like an engagement report — the problem, the approach, the architecture and the measured result. Click any card for the full breakdown.
All work grounded in real coursework, the WalSec final-year project and internship reports.
The stack behind the defence
A T-shaped skill set: deep in threat intelligence and network forensics, broad across offensive testing, secure software, applied AI and cloud. The radar is a self-assessment; the columns are the tools I actually reach for.
Threat Intel & SOC
- MITRE ATT&CK (Enterprise + ICS)
- SIEM / SOC Operations
- Splunk
- Wazuh / EDR
- Threat Hunting
- Incident Response (NIST SP 800-61)
- OSINT — ThreatFox · URLhaus · Abuse.ch
Offensive & Forensics
- Penetration Testing (black-box)
- Nessus / Nmap / Metasploit
- Burp Suite
- Malware Analysis (static + dynamic)
- Reverse Engineering — IDA · GDB · REMnux
- Wireshark / TShark / PyShark
- testssl.sh / OpenSSL
Networking & ICS
- Packet Analysis & DPI
- VLAN / NAT / Static Routing
- Firewall Rules & Segmentation
- Cisco Packet Tracer
- SCADA / OT Security
- CARVER Risk Assessment
Software & AI
- Python — Flask · PyShark · scikit-learn
- C++
- React 18 / Next.js
- Local LLMs — Ollama · Llama 3.2
- RAG + BGE-M3 embeddings
- ML — XGBoost · Random Forest · MLP
- SQL / SQLite (WAL)
Cloud & DevSecOps
- Microsoft Azure (Security focus)
- Docker / Docker Compose
- CI/CD (GitHub Actions)
- SAST / DAST
- JWT · bcrypt · RBAC
- ISO 27001 / GDPR
Cryptography
- AES-256 / SHA-256
- RSA & Cryptanalysis
- Key-Exchange Protocols
- Symmetric & Public-Key Crypto
- TLS / SSL Hardening
Experience & credentials
Hands-on security work across industry programs, backed by a cybersecurity degree and professional certifications.
Cyber Security Intern
Jun 2025 – Sep 2025- Improved threat-detection accuracy by 20% by refining SIEM rules and tuning alert thresholds, reducing false positives during triage.
- Contributed to a 25% drop in endpoint vulnerabilities via scans, patch verification and flagging misconfigurations across assets.
- Cut incident-response time 15–20% by updating escalation matrices and drafting playbooks.
Cyber Security Analyst
2025- Responded to a simulated malware attack, reducing threat impact by 80% through timely containment and mitigation.
- Performed post-incident analysis, identifying 3 key vulnerabilities and recommending 5 targeted hardening improvements.
Security Awareness Analyst
2025- Served as an analyst on Mastercard’s Security Awareness Team, identifying and reporting phishing threats.
- Assessed gaps in employee security awareness and helped implement targeted training across high-risk business units.
Cyber Security Analyst
2025- Analysed web-activity logs for cybersecurity incidents and investigated suspicious user activity.
- Supported a client through a cyber-security breach, answering investigative questions to identify the source.
BSc (Hons) Cyber Security
De Montfort University, Dubai
EQF Level 6 · Final-year / recent graduate
2023 – 2026
Cybersecurity Professional Certificate
May 20258-course program — detection & response, Python automation, Linux, SQL, threat analysis
Generative AI Engineering Professional
Aug 2025IBM
Generative AI applications & prompt engineering
Certified Foundations Associate (AI & Cloud)
Jul 2025Oracle
AI Foundations + OCI Foundations Associate
A SOC analyst who can also write the tooling
BSc (Hons) Cybersecurity from De Montfort University, Dubai, and a hands-on builder. I specialise in threat intelligence, network forensics and SOC automation — and I ship the software to back it up, from a fully-local, LLM-powered SIEM-Lite platform to ML phishing detectors and C++ security tooling. Industry experience across Telstra, Mastercard, Deloitte and Receptive Tech, where I cut response time, hardened endpoints and contained simulated attacks.
Analyst instinct
I read the wire and the logs first — packets, IOCs and behaviour mapped to MITRE ATT&CK before I touch a tool.
Builder’s hands
I ship the software behind the defence: a local LLM SIEM-Lite, ML detectors, C++ security tooling and full-stack products.
Defence that ships
Every finding lands with a fix — detection logic, hardening steps and controls a team can act on Monday morning.
Let’s harden something together.
I’m looking for Security Engineering, SOC and Threat-Intelligence roles where I can analyse the threat and build the tooling that answers it. If that’s the kind of person your team needs, let’s talk.