Summary
Overview
Work History
Education
Skills
Certification
Languages
Timeline
Generic
Soufian EZ-ZBAKH

Soufian EZ-ZBAKH

Bezons

Summary

Dedicated SOC/CSIRT Analyst with extensive expertise in cybersecurity operations and incident response. Proficient in utilizing a wide range of technologies, including SIEM , EDR, and various threat intelligence platforms. Demonstrated ability to analyze and mitigate security incidents, conduct forensic investigations, and implement robust security measures. Adept at collaborating with cross-functional teams to enhance security posture and ensure compliance with industry standards. Open to new opportunities to leverage skills and contribute to the protection of organizational assets

Overview

7
7
years of professional experience
1
1
Certification

Work History

CSIRT Analyst

BNP Paribas
11.2023 - Current

• Perform daily monitoring of security events/alerts, generated on the SIEM.
• Investigating EDR alerts and conducting investigations via EDR.
• Proposing and developing new use cases (Detection scenarios).
• Analyzing phishing emails and creating Yara rules to block them on the sandbox.
• Reporting and monthly security bulletins presentation.
• Onboarding of new entities.
• Investigating NDR alerts.
• Log collection optimization and review
• Report security incidents using ServiceNow ticketing system.
• Investigating DDOS attacks targeting web sites and internet published services.

• Finetunning and ameliorating old detection rules



SOC Analyst L2

Techsogroup
10.2022 - 09.2023
  • Participating in the building of the SOC
  • Log sources integration and review.
  • ELASTIC Deployment.
  • Deployment and the integration of MISP platform with ELastic and QRadar SIEM
  • Deployment of OpenCVE and SpiderFoot platforms
  • Use cases and playbooks implementation
  • New Clients Onboarding
  • training of L1 analysts and team leading


SOC Analyst L2

DATAPROTECT
10.2021 - 10.2022
  • Managing L1 Analysts team.
  • Handling L1 analysts escalations.
  • Audit of SIEM platforms, audit of the quality of the security data collected.
  • Implementations of Use Cases (detection rules on SIEM solutions).
  • Tunning and optimization of detection rules
  • Support for SOC L1 Analysts in their skills development.
  • Forensic investigation of infected Windows machines and artifact analysis.

SOC Analyst L1

DATAPROTECT
09.2019 - 10.2021
  • Surveillance 24h/24 7j/7.
  • Follow detailed processes and procedures to analyze, escalate, and assist in the resolution of security incidents.
  • Log analysis on IBM QRadar SIEM and ELK Stack.
  • Analysis of phishing emails.
  • Dynamic malware analysis


Internship (pre-employment)

Huawei Technologies
06.2019 - 09.2019

Engineering and maintenance of the OCS (Online Charging System).

End-of-study Internship

IT6 Consulting
03.2017 - 07.2017

Internship under the theme: implementation of the SIEM (Siemonster), benchmark of (ossim, siemonster, elastick stack) and functional enrichment of the SIEM ELASTIC STACK Solution for the management of Cyber Security Events and Incidents.

Education

Engineering Degrees - Networks And Telecommunication Systems

National School of Applied Sciences
Kenitra, Morocco
09.2017

Bachelor of Science - Physical Sciences

Ibn Toufail University
Kenitra Morocco
07.2014

Skills

  • Documentation
  • Managing Security incidents
  • Creation of detection rules and detection use cases
  • Elastic, QRadar, LogRhythm and Splunk SIEM
  • Threat intelligence and venerability management
  • Digital Forensics (Kape, Autopsy, EDR)
  • Teamwork and project management
  • Dynamic Malware Analysis

Certification

  • Fortinet : NSE1, NSE2, NSE3.
  • Ec-Council: CEH v11 - ECIH v2
  • Intermediate MITRE ATT&CK
  • British Council, Rabat: IELTS Academic IELTS (International English Language Testing System) ACADEMIC, Score 6/9.
  • SANS 508 (In progress)

Languages

Arabic
Bilingual or Proficient (C2)
French
Upper intermediate (B2)
English
Upper intermediate (B2)

Timeline

CSIRT Analyst

BNP Paribas
11.2023 - Current

SOC Analyst L2

Techsogroup
10.2022 - 09.2023

SOC Analyst L2

DATAPROTECT
10.2021 - 10.2022

SOC Analyst L1

DATAPROTECT
09.2019 - 10.2021

Internship (pre-employment)

Huawei Technologies
06.2019 - 09.2019

End-of-study Internship

IT6 Consulting
03.2017 - 07.2017

Engineering Degrees - Networks And Telecommunication Systems

National School of Applied Sciences

Bachelor of Science - Physical Sciences

Ibn Toufail University
Soufian EZ-ZBAKH