UAE · Open to SOC Analyst L1 opportunities

An operator’s instinct.
A defender’s mindset.

I’m Farhan. After 13 years keeping critical systems running, I’m turning that experience toward protecting them.

+IT & NOC operations → Security operations
FARHAN FATHAHCuriosity. Discipline. Evidence.
01 / A new layer, built on experienceScroll to explore ↓
The foundationISC2 CCMicrosoft SC-300EC-Council CEH v13Cisco CCNAAlways learning ↗

Cybersecurity wasn’t a reset.
It was the next layer.

Years of troubleshooting taught me how systems fail. Now I’m learning how attackers exploit those failures—and how defenders find the evidence.

13years

IT support, infrastructure,
identity, and NOC operations.

3,500+ users

Enterprise support experience
at ENOC.

I bring the context behind the alert.

A VPN sign-in, a failing service, or an unexpected account change makes more sense when you understand the environment. My operations background gives me that starting point.

My next chapter is SOC analysis: validating signals, connecting authentication and endpoint evidence, understanding impact, and documenting clear next actions.

Understand the system↗Follow the evidence↗Explain the decision
2013

Infrastructure

Infosys · Daimler data centre

2015

IT ownership

KPFF Global

2021

Operations at scale

Expo 2020 Dubai

2022 — NOW

NOC & identity

ENOC

THE NEXT CHAPTER

Security operations ↗

Building toward SOC Analyst L1

Follow the signal.

Tools are a starting point. These case files show the questions, detection logic, and decisions behind my learning.

Click a case to explore ↗
CASE / 002 Completed lab
⌘

One password.
Many accounts.

Password-spraying analysis: distinguish targeted accounts from repeated attempts against a single user.

AuthenticationSPL / KQL
CASE / 003 Configured & practiced
⌕

From syslog
to Sentinel.

Connected Linux and Windows telemetry, practiced KQL, and configured an Ubuntu authentication analytics rule.

SentinelAMA / DCR
CASE / 004 Onboarding completed
⊡

An endpoint.
A clearer picture.

Onboarded Windows and Ubuntu to Defender for Endpoint and verified health and telemetry.

Defender for EndpointXDR
BUILD / 005 Developing
⌁

The network
leaves clues.

Zeek connection and DNS analysis, with a broader OPNsense and Suricata telemetry pipeline in development.

ZeekOPNsenseSplunk
BUILD / 006 Developing
⎔

Go beyond
the alert.

Velociraptor server and client deployment on ARM Linux, exploring authentication artifacts and endpoint evidence.

VelociraptorDFIRLinux

One environment.
Multiple perspectives.

I built a personal lab to connect attacker activity, network telemetry, endpoint evidence, and SIEM investigation. Select a layer to see its role.

THE TELEMETRY PATH CONCEPTUAL LAB ARCHITECTURE

Architecture overview, not a live dashboard. Network forwarding and deeper DFIR work are still developing.

My investigation rhythm
  1. 01Detect

    Find the signal.

  2. 02Validate

    Check the evidence.

  3. 03Scope

    Understand the impact.

  4. 04Respond

    Explain the next action.

Different environments.
The same ownership.

Enterprise infrastructure, event operations, identity, and monitoring. Each role sharpened the discipline I bring to security.

ENOCIT Support Specialist & NOC AnalystDubai, UAE · Assignment through TransguardFeb 2022 — Present Current role+

Security Operations & Incident Response

  • Triaged abnormal user activity, suspicious browser behavior, and identity-related incidents across Active Directory/Entra ID for 3,500+ users.
  • Investigated suspicious VPN logins — foreign IPs, mismatched geolocation, MFA failures — blocking unauthorized access attempts.
  • Remediated compromised accounts via password resets and MFA re-enforcement, closing confirmed identity incidents.
  • Validated and cleaned phishing-exposed endpoints through AV scanning and malware checks.
  • Logged and categorized incidents in BMC Remedy with root-cause notes, maintaining escalation workflow compliance.

Monitoring & Alert Triage

  • Monitored enterprise infrastructure in BMC TrueSight, Entuity, Site24x7, and NetFlow Analyzer, flagging anomalies and traffic deviations before service impact.
  • Triaged first-level alerts — latency spikes, abnormal device behavior — and escalated confirmed incidents to L2/L3.
  • Monitored POS, Pumpomat, and NCR retail systems across 800+ locations, sustaining stable and secure operation.

Identity & Access Security

  • Administered access controls (privileged accounts, groups, licenses, hybrid identity sync) in Active Directory/Microsoft 365 for 3,500+ users.
  • Validated MFA challenges and sign-in anomalies, escalating confirmed cases to L2/L3 security teams.

Recognition

  • Earned a Certificate of Recognition (Q2 2023) from ENOC for monitoring responsiveness and incident handling.
Identity & accessNOC monitoringIncident ownership
Expo 2020 DubaiIT Operations & Support EngineerDubai, UAEJun 2021 — Feb 2022+
  • Secured IT operations supporting delegations from 190+ countries during Expo 2020 Dubai.
  • Enforced patch and software-deployment compliance via ManageEngine Desktop Central, reducing endpoint attack surface.
  • Resolved security incidents across Active Directory, Exchange/Outlook, and Cisco AnyConnect VPN.
  • Standardized endpoint builds via Acronis imaging, cutting deployment time and configuration drift.
  • Maintained AV, CCTV, and VMS/SMS physical-security systems for continuous operation.
  • Managed mobile device compliance via Microsoft Intune and monitored network health via ManageEngine OpManager, flagging incidents for NOC escalation.
  • Logged and resolved tickets via ServiceNow and ManageEngine ServiceDesk Plus, maintaining SLA compliance.
  • Onboarded endpoints to Microsoft Defender ATP, extending threat-detection coverage across the device fleet.
Endpoint managementITSMEvent operations
KPFF GlobalIT CoordinatorDubai, UAEAug 2015 — Jul 2020+
  • Administered identity and access on Windows Server 2012 R2 Active Directory and Exchange Online for 40+ users.
  • Managed patching, antivirus, licensing, and backups across the IT asset lifecycle, reducing unlicensed/unpatched exposure.
  • Administered firewalls, routers/switches, and biometric access control for facility security.
IT administrationBackups & recoveryNetworking
InfosysSystem EngineerBangalore, India · Daimler Mercedes-Benz European Data CentreJun 2013 — Dec 2014+
  • Delivered L1/L2 infrastructure support for Daimler Mercedes-Benz's European Data Centre under regulated change control.
  • Monitored infrastructure via SCOM and Nagios, flagging service risks before customer impact.
  • Administered Active Directory, HP/Dell servers, VMware, SCCM, and LAN/WAN under ITIL-aligned change management.
Enterprise infrastructureITILL1 / L2 support

What I bring
to the table.

01

Security monitoring

Splunk · Sentinel · SPL · KQL · Authentication analysis · Alert triage

Turn events into an investigation question.
02

Identity & endpoint

AD / Entra ID · MFA · Conditional Access · Defender for Endpoint · Intune

Understand the user, device, and access context.
03

Network visibility

Zeek · OPNsense · Suricata · TCP/IP · DNS · DHCP · Packet analysis

Follow activity beyond a single host.
04

Operational discipline

ITIL · Incident / problem / change · ServiceNow · BMC Remedy · Windows / Linux

Document clearly. Escalate responsibly. Own the outcome.

Keep the curiosity.
Build the capability.

Completed credentials, active study, and a practical roadmap toward a SOC Analyst L1 role.

COMPLETED CREDENTIALS
◈

Certified in Cybersecurity

ISC2 · CC

✓
⊞

Identity & Access Administrator

Microsoft · SC-300

✓
⌘

Certified Ethical Hacker v13

EC-Council · CEH with AI

✓
⌁

Cisco Certified Network Associate

Cisco · CCNA

✓

Also completed: cybersecurity internship with NIELIT, Government of India.

NOW / STUDYING

SC-200 + Security+

Security operations meets security fundamentals. Practicing Sentinel, Defender XDR, KQL, threats, and response decisions.

NEXT / BUILDING

Deeper, clearer case files

Connect network and endpoint evidence, map detections to MITRE ATT&CK, and document tuning and escalation decisions.

DIRECTION / SOC ANALYST L1

Make the transition.

Bring operations experience, practical lab work, and an evidence-led mindset into a UAE security operations team.

THE CYBER DEBATE

Two perspectives.
You steer the conversation.

Challenge an idea. Hear an attacker’s perspective, then a defender’s response. Pick a topic, move through three rounds, and ask both sides your own question.

Choose a topic to beginAI-generated simulation · One model, two roles

Choose a topic and press Start debate.

For cybersecurity learning. AI can make mistakes. Topics and recent debate turns are processed by Cloudflare; avoid confidential information.

THE NEXT CHAPTERBased in the UAE

Let’s talk about
what comes next. ↗

Hiring for SOC Analyst L1 or cybersecurity operations?
I’d welcome a conversation about the experience I bring and the capability I’m building.

FARHAN’S AI ASSISTANT

What would you like to know?

BEFORE WE CHAT

What should I call you?

Farhan can review your name and chat messages, saved privately through Cloudflare. Please don’t share passwords or confidential information.