CV · 2 pages
Mohamad I. Kaimouzmail@mkaimouz.com | London, UK | Arabic - EnglishPortfolio & case studies
Professional SummarySenior Cyber Security Analyst combining incident response, detection engineering and automation with SOC leadership,offensive testing and software development. At UK Water Utility, I build KQL investigations, Sentinel workflows andDefender response tooling. Previously led SOC shifts within a provider monitoring 70,000+ endpoints. MSc InformationSecurity with Distinction.PROFESSIONAL EXPERIENCEUK Water UtilityUKFrom 04/2025 to presentSenior Cyber Security Analyst•Automated incident-response evidence collection through Microsoft Defender for Endpoint Live Response,deploying and running the retainer collector on Windows and Linux and securely uploading results.•Enabled ServiceNow SecOps developers to generate consistent Sentinel test incidents on demand using CopilotStudio and Power Automate, with programmed entities, overlapping-run protection and automatic reset.•Converted 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering backlog items,with MITRE ATT&CK mappings, telemetry dependencies and validation requirements.•Maintained SOC response during an MDR transition, leading knowledge retention and threat hunting and deliveringa defined out-of-hours escalation process.•Onboarded six SOC colleagues and introduced investigation quality reviews, supported by practical coaching onAiTM, NAT and identity attacks.Growing MSSP with Offensive ServicesLondon, UKFrom 12/2022 to 2025Security Engineer•Led SOC shifts and incident response in a seven-person team using MSSP SIEM/SOAR, within a provider servicemonitoring 70,000+ endpoints across 150+ client organisations.•Reconstructed Microsoft 365 and VPN intrusions, identifying malicious MFA and inbox-rule changes and twocompromised VPN accounts through sign-in, network and endpoint forensics.•Oversaw a team portfolio of 50+ monthly offensive engagements, shaping threat-informed scopes, resolvingtechnical delivery obstacles and reviewing findings and remediation reports.•Delivered web, on-prem Active Directory and cloud assessments from scoping to remediation reporting, applyingOWASP Top 10 and MITRE ATT&CK to guide testing.
Digital Publishing Technology CompanyQuebec,Canada –RemoteFrom 03/2021 to 12/2022Lead Full-Stack Developer•Maintained PHP/MySQL publishing platforms serving approximately three million monthly visits, supporting Linux,Nginx, WordPress, Craft CMS and AWS EC2 production environments.•Developed PHP data-migration scripts and database changes, then documented inherited applications andonboarded developers to support production maintenance and handover.EDUCATIONUK UniversityLondon, UKFrom 09/2021 to 09/2022MSc Information SecurityScholarship: Full scholarshipGrade: DistinctionMSc project: Analysed ransomware key-management weaknesses and proposed a classification of recovery difficulty.University in LebanonBeirut,LebanonFrom 09/2016 to 12/2020BSc Computer ScienceScholarship: Full scholarshipGPA: 3.75/4.0 · DistinctionMajor average: 3.86/4.0 · Dean’s Honour List in junior and senior yearsSKILLS SUMMARY•Detection & response: Microsoft Sentinel (SIEM), KQL, Defender for Endpoint (DfE/MDE), EDR, MITRE ATT&CK,threat hunting and incident response.•Investigation & forensics: Microsoft 365, Entra ID, Windows events, NTLM/Kerberos, VPN attribution, Prefetch,Velociraptor, Procmon and PowerShell malware analysis.•Automation & SOAR: PowerShell, Python, Bash, Defender Live Response, Power Automate, Copilot Studio,ServiceNow SecOps/SIR and XSOAR.•Detection engineering: Git, Azure DevOps, detection lifecycles, telemetry requirements, rule versioning, integrationtesting, tuning and operational handover.•Threat modelling & offensive security: Attack-surface mapping, assumed breach, web and on-prem ADassessments, cloud reviews, physical testing, OWASP Top 10 and AI application scoping.•Software & infrastructure: Azure, Linux, PHP, MySQL, Nginx, AWS EC2, Docker, WordPress and Craft CMS;migrations and production troubleshooting.•Leadership: SOC shift leadership, offensive-service oversight, analyst coaching, recruitment, onboarding,investigation standards and client communication.•Qualifications earned: CREST Practitioner Security Analyst (CPSA); TryHackMe Security Analyst Level 1 (SAL1), 2025.