Syed Najam

DevOps Manager

Karachi, Sindh, Pakistan2 yrs 11 mos experience

Key Highlights

  • Expert in end-to-end SIEM engineering and security monitoring.
  • Proficient in detection engineering aligned with MITRE ATT&CK.
  • Strong background in incident response and threat hunting.
Stackforce AI infers this person is a Cybersecurity Engineer specializing in SIEM and SOC operations.

Contact

Skills

Core Skills

Siem EngineeringSecurity MonitoringIncident ResponseThreat DetectionWeb DevelopmentSystem Administration

Other Skills

IBM QRadarMicrosoft SentinelSecurity Control IntegrationSOC OperationsAlert TriageThreat IntelligenceWordPressWazuhWeb SecurityOperating SystemsMicrosoft Defender XDRTrend Micro XDRKaspersky EDRCisco FMC & FTDHuawei Firewall

About

I am a Security & SIEM Engineer with strong SOC operations expertise, experienced in designing, deploying, and optimizing enterprise security monitoring architectures and security controls across large-scale public and private sector environments. My core strength lies in end-to-end SIEM engineering, including All-in-One (AIO) and distributed deployments, log source onboarding, data parsing and normalization, enrichment, and pipeline optimization to ensure high-quality, actionable security telemetry. I specialize in detection engineering, developing and maturing use cases aligned with MITRE ATT&CK and Cyber Kill Chain (CKC) frameworks to improve detection coverage and accuracy. Alongside engineering responsibilities, I actively contribute to SOC operations, performing advanced alert triage, deep log analysis, and Tier-2/Tier-3 level investigations. I support incident response activities, including threat validation, root cause analysis, and coordinated containment and remediation efforts. I have hands-on experience in manual threat hunting, applying hypothesis-driven techniques to identify stealthy threats, anomalous behavior, and attack patterns that bypass automated detections. I also perform phishing detection and analysis, inspecting email headers, URLs, attachments, and payloads to identify credential harvesting, malware delivery, and social engineering attacks. My work involves integrating a wide range of enterprise security controls across endpoint, network, perimeter, cloud, and identity domains, enabling centralized visibility and cross-domain correlation. I focus on ensuring that security technologies generate meaningful telemetry that supports effective threat detection, risk management, and compliance requirements. I apply MITRE ATT&CK, Cyber Kill Chain (CKC), and SOC maturity models (SOC-CMM) to strengthen detection capabilities and improve SOC operational effectiveness. I actively contribute to SOC playbooks, runbooks, and process optimization, supporting consistent and efficient security operations. In addition, I support use case validation, UAT and testing environments, and compliance-driven security monitoring aligned with ISO/IEC 27001, organizational risk management, and business continuity requirements. Currently pursuing a Master’s in Information Security, I continuously enhance my expertise across SIEM architecture, security engineering, detection engineering, threat hunting, and SOC operations, with a strong focus on scalable, resilient, and standards-driven cybersecurity solutions.

Experience

Commtel

2 roles

Security & SIEM Engineer

Promoted

Sep 2025Present · 6 mos · Karachi Division, Sindh, Pakistan · On-site

  • Working as a Security & SIEM Engineer, responsible for the design, deployment, integration, and optimization of enterprise security monitoring platforms and security controls across large-scale public and private sector environments. My role focuses on SIEM architecture, detection engineering, security control integrations, and compliance-aligned security visibility.
  • Key Responsibilities & Engineering Expertise:
  • Designed, deployed, and supported enterprise-grade SIEM architectures, including All-in-One (AIO) and distributed deployments, ensuring scalability, high availability, and performance optimization.
  • Led end-to-end SIEM engineering lifecycle, covering log source onboarding, parsing, normalization, enrichment, data pipeline tuning, and long-term log retention strategies.
  • Implemented and optimized agent-based and agent-less integrations across endpoints, servers, network devices, firewalls, applications, and cloud platforms to ensure centralized and reliable security telemetry.
  • Engineered and matured detection use cases aligned with MITRE ATT&CK and Cyber Kill Chain (CKC) frameworks, focusing on detection accuracy, coverage gaps, and lifecycle maturity.
  • Integrated and managed a broad range of enterprise security controls, including:
  • Endpoint & XDR Platforms: Microsoft Defender XDR, Trend Micro XDR, Kaspersky EDR
  • Network Security Controls: Cisco FMC & FTD, Huawei Firewall
  • Perimeter & Web Security: DOSarrest Web Application Firewall (WAF)
  • Cloud & Identity Security: Microsoft Azure Security Stack, Entra ID, Defender for Cloud
  • Built and maintained UAT and testing environments using Microsoft Sentinel, IBM Qradar and Defender XDR to validate new integrations, detections, and security control changes before production rollout.
  • Aligned SIEM engineering and security control implementations with ISO/IEC 27001, risk management processes, and business continuity requirements.
IBM QRadarMicrosoft SentinelSIEM EngineeringSecurity Monitoring

SOC Analyst

Jun 2025Sep 2025 · 3 mos · Karachi Division, Sindh, Pakistan · On-site

  • Monitored and analyzed security alerts within a 24/7 SOC environment, performing alert triage and investigation to identify true positives and minimize false positives.
  • Conducted end-to-end incident investigations, including alert validation, root cause analysis, impact assessment, escalation handling, and post-incident reporting.
  • Performed phishing detection and analysis activities, including manual inspection of email headers, URLs, attachments, and payloads to identify credential harvesting, malware delivery, and social engineering attacks.
  • Performed manual threat hunting using hypothesis-driven techniques to proactively identify hidden threats, suspicious behaviors, and anomalous activity not detected by automated alerts.
  • Analyzed threat and attack patterns by correlating security events, behavioral indicators, and attacker TTPs to detect ongoing or emerging attack campaigns.
  • Applied MITRE ATT&CK and Cyber Kill Chain (CKC) frameworks to map adversary behavior, identify attack progression, and enhance SOC detection.
  • Conducted deep log analysis across endpoint, network, authentication, and application logs to investigate lateral movement, persistence, privilege escalation, and command-and-control activity.
  • Supported incident response operations, coordinating containment and remediation efforts with internal teams and ensuring timely escalation of high-severity incidents.
  • Integrated threat intelligence and contextual data into investigations to enrich alerts, validate threats, and improve analyst decision-making.
  • Contributed to the development and refinement of SOC playbooks and SOPs, improving response consistency and operational maturity.
  • Supported SOC maturity initiatives aligned with SOC-CMM and security best practices, focusing on detection quality, response time, and operational efficiency.
  • Maintained strong working knowledge of security event lifecycles, incident response processes, networking fundamentals, and Linux-based systems.
SOC OperationsAlert TriageIncident ResponseThreat Detection

Abacuschains website designing agency

Website Developer - System Admin

Oct 2022Dec 2024 · 2 yrs 2 mos · Pakistan · On-site

  • Implemented and maintained secure web environments by applying best practices in access control, encryption (SSL/TLS), and regular security patching.
WordPressWazuhWeb DevelopmentSystem Administration

Fictive hut

Wordpress Developer

Oct 2020Feb 2021 · 4 mos · Karāchi, Sindh, Pakistan · On-site

WordPressOperating Systems

Education

Hamdard University

Bachelor's degree — Software Engineering

Sep 2018Dec 2022

Stackforce found 100+ more professionals with Siem Engineering & Security Monitoring

Explore similar profiles based on matching skills and experience