You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Marwane BelkadiMB

Marwane Belkadi

Security expert

€650/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Marwane

I am an experienced SOC/CSIRT analyst, at the intersection of advanced detection, incident response, and cyber threat intelligence, with a strong specialization in creating custom detection rules and advanced SIEM exploitation. I operate in the first and third lines to detect, investigate, and neutralize the most sophisticated threats.

My areas of expertise:
• Proactive Threat Hunting on EDR (CrowdStrike Falcon, SentinelOne, etc.)
• Custom Detection: rule creation (SIGMA, YARA, KQL, AQL, Falcon Query Language…)
• Advanced SIEM manipulation (QRadar, Splunk, Elastic, LogScale): parsing, correlation rules, dashboards, custom filters
• Forensic investigation (memory, disks, Windows/Linux artifacts, log analysis)
• Incident analysis and response: ransomware, LotL attacks, initial access, privilege escalation, lateral movements
• IoC enrichment, adversary TTP detection (MITRE ATT&CK, CTI, OSINT)
• Production of DFIR playbooks, technical reports & hardened recommendations

What I bring:
• The ability to transform raw visibility into targeted and actionable detection
• An offensive/defensive approach, grounded in attacker tactics
• Proven expertise in optimizing SIEM/EDR/SOAR pipelines
• Complete autonomy in critical environments and sensitive contexts

Available for one-off or long-term missions, on-site or remote, to:
• Improve detection coverage
• Strengthen CSIRT/SOC capabilities
• Respond to a compromise
• Structure a modern defensive strategy
  • French

    Native or bilingual

  • English

    Fluent

  • Arabic

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • Sodexo
    CSIRT expert
    RESTAURANTS AND FOOD SERVICE
    October 2023 - Today (2 years and 8 months)
    Paris, France
    Proactively monitor enterprise systems and networks using industry-leading SIEM and EDR technologies (QRadar, Azure Sentinel / Defender, CrowdStrike) to detect early indicators of compromise, advanced persistent threats, and anomalous behavior. Conduct in-depth digital forensic investigations across Windows and UNIX environments to uncover root causes, trace attacker movements, and collect admissible evidence for potential legal escalation. Orchestrate rapid incident containment and mitigation, leveraging real-time intelligence and automation to neutralize threats and minimize business impact. Collaborate seamlessly with cross-functional teams—including internal CSIRT, global IT security teams, external partners, service providers, and law enforcement when necessary—to coordinate end-to-end incident response. Continuously track emerging threats, vulnerabilities, and adversary tactics (TTPs) to enhance threat models and inform detection strategy. Engineer advanced detection capabilities, developing tailored signatures, YARA rules, and correlation logic for intrusion prevention systems (IPS), malware detection platforms, and SIEMs—optimizing visibility across hybrid infrastructures.
    SIEM CSIRT XDR Qradar SOAR
  • Orange Cyberdéfense
    SOC Information Security Manager
    June 2022 - October 2023 (1 year and 4 months)
    Paris, France
    Leadership across multidisciplinary teams including SOC/CyberSOC analysts, service delivery managers, threat engineers, pre-sales architects, and the Use Case Factory. Strategic oversight of detection scopes, continuously assessing and expanding threat coverage across hybrid environments (on-prem, Azure, AWS). Facilitation of client and stakeholder meetings, driving alignment through operational steering (COSUI), technical committees (COTECH), executive reviews (COPIL), and strategic governance boards (PERCO, COMAC, COSTRAT). Design and presentation of KPIs and success metrics, enabling data-driven decision-making and operational visibility. Lifecycle management of detection rules and log sources, ensuring optimal signal-to-noise ratio and actionable alerts. Vulnerability management and remediation orchestration, aligning with risk posture and compliance requirements. Operational continuity (MCO) and service continuity (MCS) for all detection related platforms, ensuring resilience and high availability. Coordination and prioritization of SOC activities, ensuring team performance, incident readiness, and continuous improvement. Direct client request handling and escalation management, fostering trust and transparency throughout the engagement. Project ownership for detection perimeter extensions, including integrations with Microsoft Sentinel, Azure, AWS, and other cloud-native technologies. Use case development, scenario implementation, and rule fine-tuning, tailored to client-specific threat models and regulatory requirements. MITRE ATT&CK framework coverage assurance, translating adversary behavior into actionable detections. Proactive threat hunting operations, leveraging contextual intelligence to uncover stealthy and sophisticated attack patterns. Change management oversight in accordance with ITIL/ITSM best practices, ensuring smooth transitions and minimal service disruption.
    Personal [IMAGE] [IMAGE] [IMAGE]
  • Société Générale ABS
    SOC Manager
    September 2021 - June 2022 (9 months)
    Strategic planning and orchestration of daily SOC operations, ensuring seamless detection, response, and monitoring across enterprise environments. Operational leadership during major cybersecurity incidents, acting as a key stakeholder in crisis management and incident containment. Coordination with CERT and CSIRT teams, especially under crisis conditions, to synchronize actions across all operational security units and maintain situational awareness. SOC vision and strategy definition, aligning detection capabilities with regulatory mandates, evolving threat landscapes, and the organization's risk appetite. Design and implementation of escalation and notification workflows, supported by real-time KPI dashboards presented during executive meetings (COPIL, COSUI). Evaluation of SOC tool effectiveness, leading continuous improvement initiatives and driving corrective action plans based on operational performance and threat coverage gaps. Threat-informed detection strategy development, leveraging a global view of the organization's vulnerability exposure and attack surface. Architecture and deployment of SOC toolsets, including: Event collection pipelines (SIEM/EDR/NDR) Secure access to security platforms Suspicious event investigation and triage Alert lifecycle management Workflow automation for incident tracking and resolution

Recommendations

Be the first to recommend Marwane

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Certified Ethical Hacker (CEH)
    Certified Ethical Hacker (CEH)
  • Cryptography and PKI
    Brandon University
    Cryptography and PKI

Skill set

Categories