You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Bilal FrasniBF

Bilal Frasni

Cybersecurity Consultant SOC & Microsoft 365

€400/day
Montpellier, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Bilal

Cybersecurity consultant specializing in SOC, Microsoft 365, and incident response. I help companies analyze, qualify, and process their security incidents: phishing, account compromise, suspicious logins, EDR alerts, email incidents, and abnormal behaviors.

My experience in a SOC environment allows me to work on operational topics: Microsoft 365, Entra ID, and Exchange Online log analysis, incident investigation, email rule verification, session revocation, fraudulent email analysis, alert enrichment, and clear report writing.

I also work on improving SOC processes: dashboards, KPIs, detection rules, Microsoft Sentinel playbooks, triage automation, alert enrichment, and incident processing assistance through scripts, workflows, and AI-integrated tools.

My goal: to provide clear, actionable analysis tailored to the company's maturity level, with concrete recommendations to reduce risks and improve incident response capabilities.
  • French

    Native or bilingual

  • English

    Fluent

Remote only
Primarily works remotely

Experience

  • Septeo
    SOC Analyst N3
    DIGITAL AND IT
    October 2024 - Today (1 year and 8 months)
    Lattes, France
    SOC Analyst N3 specializing in the investigation and processing of cybersecurity incidents in Microsoft 365, Exchange Online, Entra ID, and user endpoint environments.

    I handle incidents related to phishing, account compromises, suspicious logins, malicious links, EDR alerts, abnormal email behavior, and suspected identity theft.

    My responsibilities include alert qualification, Microsoft 365 / Entra ID / Exchange Online log analysis, event correlation, identification of indicators of compromise, and implementation of remediation actions: password resets, session/token revocation, blocking malicious URLs, and security recommendations.

    I also perform technical analysis of fraudulent emails: headers, links, domains, attachments, SPF/DKIM/DMARC, and indicator reputation using threat intelligence sources.

    In parallel, I contribute to the continuous improvement of the SOC through the creation of Elastic/Kibana queries and dashboards, KPI monitoring, ticket categorization, and standardization of analysis procedures.

    I also develop internal SOC-oriented automations, particularly to facilitate log analysis, incident response assistance, alert enrichment, and report generation using scripts, workflows, and AI-integrated tools.

    Environment: Microsoft 365, Entra ID, Exchange Online, Defender for Office 365, Bitdefender EDR, Elastic/Kibana, Retarus, VirusTotal, Snowflake, DNS, SPF/DKIM/DMARC, threat intelligence, SOC automation, AI applied to cyber analysis.
    Microsoft Entra ID Microsoft 365 Cybersecurity Incident Management EDR Security Operations Center
  • Devensys Cybersecurity
    SOC Analyst N1/N2
    DIGITAL AND IT
    October 2022 - July 2024 (1 year and 9 months)
    Montpellier, France
    SOC Analyst N1/N2 (work-study program). I participated in the supervision, qualification, and processing of security alerts in a SOC environment.

    My responsibilities primarily involved analyzing suspicious events, qualifying incidents, tracking security tickets, and contributing to initial response actions. I worked on topics related to detection, event correlation, incident documentation, and improvement of SOC operating procedures.

    I specifically used Microsoft Sentinel for security monitoring, event correlation, incident tracking, and improving detection capabilities. I contributed to the creation and adaptation of alert rules, workflows, and playbooks to automate certain incident processing steps.

    These automations facilitated triage, alert enrichment, notification, escalation, and standardization of incident responses. The goal was to improve SOC responsiveness, reduce repetitive manual actions, and ensure reliable operational alert processing.

    I also participated in procedure documentation, cybersecurity watch, and continuous improvement of detection and incident response practices.

    Environment: Microsoft Sentinel, alert rules, Sentinel incidents, playbooks, workflows, SOC automation, alert analysis, triage, event correlation, documentation, incident response.
    Cybersecurity Incident Management Microsoft Sentinel Security Awareness Training Incident Response Automation

Recommendations

Be the first to recommend Bilal

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master's in Project Management
    Keyce Informatique
    2024
    Option Cybersécurité

Certifications

  • SC-200 Security Operations Analyst Associate
    Microsoft
    2024
    Microsoft Sentinel
  • SC-300 Identity and Access Administrator Associate
    Microsoft
    2024
    IAM

Skill set

Categories