You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Khalifa FarhatKF

Khalifa Farhat

Cybersecurity Consultant

€350/day
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Khalifa

Experienced cybersecurity engineer with 3-4 years of experience, specializing in detection, incident response, and risk management for critical IT environments (>100 endpoints).

SOC & SIEM Expertise: SOC design and management, Wazuh and Splunk SIEM deployment and optimization, multi-source ingestion (Windows, AD, Palo Alto firewalls, Cisco), dashboards, correlation, and alerts.

Incident Response & DFIR: N2/N3 investigation, disk & memory analysis (Autopsy, Volatility, Eric Zimmerman tools), report writing in FR/EN.

Cloud & Messaging Security: AWS/Azure deployment, Microsoft Sentinel monitoring, Exchange / M365 protection against phishing.

Red Team & Pentesting: Linux and web application penetration testing to strengthen controls and harden systems.

GRC & Compliance: Contribution to DORA and GDPR requirements, security / business alignment.

Certified CompTIA CySA+, eCIR, eJPT, CDSA (Certified Defensive Security Analyst), Splunk Core Certified Power User (In Progress), Microsoft SC-200 (In Progress)
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • INTERNATIONALSOFTWARE COMPANY (ISC)
    SOC Analyst N2
    BANKING AND INSURANCE
    June 2024 - Today (2 years and 2 months)
    Paris, France
    Preparation and security of IT environments for clients such as IBM, HCL Software, La Banque Postale, BNP Paribas, Crédit Mutuel, AXA Assurance, Opcon, and various financial institutions, ensuring safe and compliant systems.

    SOC & SIEM
    Design and management of a SOC >100 endpoints
    Deployment of a Wazuh SIEM: ingestion of Suricata, FortiGate, Cisco logs, systems & applications
    Creation of dashboards, visualizations, and correlations
    Management of an isolated Splunk SIEM: dashboards, data models, flow optimization
    Results: improved visibility, reduced noise, and improved MTTD
    Detection & Automation
    Creation of Sigma rules based on MITRE ATT&CK
    Deployment of TheHive + SOAR (Shuffle, Slack) for IR automation
    Results: reduction in false positives and accelerated incident processing
    Incident Response & DFIR (N2/N3)
    Management of critical incidents and advanced investigations
    Disk & memory forensics (Autopsy, Volatility, Eric Zimmerman tools)
    Writing reports in FR / EN
    Results: improved resilience and response capability
    Cloud & Messaging
    Deployment of AWS environments (web VM, load balancer)
    Monitoring via Microsoft Sentinel
    Creation of Exchange / M365 anti-phishing rules
    Results: securing cloud workloads and reducing email attacks
    Red Team
    Penetration testing of Linux servers and web applications
    Results: hardening of systems and improvement of security controls
    GRC
    Contribution to DORA and GDPR requirements
    Results: risk reduction and security / business alignment
    Linux SIEM Microsoft Azure Active Directory EDR
  • IGBAT
    SOC Analyst
    CIVIL ENGINEERING
    September 2023 - June 2024 (9 months)
    Paris, France
    Guardian of IT service continuity, workstation security, and access optimization for over 150 employees.

    Endpoint Security, Identity & Vulnerabilities
    Responsibility for endpoint security on 150+ workstations
    Deployment and maintenance of Antivirus / EDR solutions
    Patch and vulnerability management (Nessus) with a reduction of approx. 20% in exposure to critical CVEs
    Windows Server & Active Directory Administration: account lifecycle, access rights, GPO, password policies, and MFA
    Results: reduced attack surface and improved security posture
    Log Management & Monitoring – Elastic Stack
    Complete management of an Elasticsearch / ELK platform
    Ingestion of Windows, Active Directory, EDR, Palo Alto firewalls, and Cisco equipment logs
    Design of ingestion pipelines, indexes, aggregations
    Creation of Kibana dashboards for security and performance monitoring
    Implementation of real-time Watchers / alerts (authentication failures, abnormal behaviors, suspicious activities)
    Event correlation and root cause analysis (RCA)
    Results: better visibility, faster detection, and proactive monitoring
    Support & Incident Response (N1 / N2)
    Handling of IT and security incidents N1/N2 (remote and on-site)
    Initial handling of phishing alerts and minor security incidents
    Maintenance of a first-contact resolution rate >85%
    Results: reduced downtime and improved user satisfaction
    IT Asset Management
    Complete management of the IT hardware lifecycle (deployment, configuration, commissioning) for 150+ workstations
    Results: standardized environments and increased operational efficiency
    Elasticsearch Windows Server Nessus Azure Sentinel EDR
  • France Knowledge Institute
    IT Support & Security Technician
    EDUCATION AND E-LEARNING
    June 2022 - September 2023 (1 year and 3 months)
    Paris, France
    Ensuring the reliability, availability, and basic security of the network and critical data.
    Network Security & Firewall Configuration:
    Installation and configuration of critical network equipment (routers, switches).
    Application of filtering rules on firewalls to secure the perimeter (segmentation and control of inbound/outbound traffic) in compliance with security policies.
    Basic monitoring of network performance to detect potential traffic anomalies.
    Backup & Business Continuity (DRP):
    Implementation and regular testing of backup and data restore procedures (DRP) to ensure the recovery of 500 GB of critical data in case of disaster.
    Management of access rights to file shares and sensitive resources.
    Preventive Maintenance & Repair:
    Effective diagnosis and resolution of failures to minimize user downtime.
    Updating and hardening of basic server operating systems.
    Linux Windows Server Network Administration System Administration Cybersecurity

Recommendations

Be the first to recommend Khalifa

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Bachelor in
    IPSSI
    Bachelor en
  • CompTIA CySA+ (Cybersecurity Analyst), ECIR - Incident Response Certification (INE Security)
    CySA+ CompTIA (Cybersecurity Analyst), ECIR - Incident Response Certification (INE Security)

Skill set

Categories