You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Mohamed GhayatiMG

Mohamed Ghayati

Cybersecurity Engineer

€125/day
Casablanca, MA
0-2 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Mohamed

It all started with an obsession: understanding how attackers think. I spent hundreds of hours on HackTheBox (Hacker rank) and TryHackMe breaking machines, exploiting Active Directory, and learning offense through practice, long before it became my profession. This curiosity led me to a cybersecurity engineering program at INPT (one of the top engineering schools in Morocco), which I will complete in 2026.
But attacking was never enough for me – what interests me is transforming that offensive knowledge into defenses that actually work. This has been the common thread throughout my professional experiences.
During my cloud security internship at SEKERA, I worked on correlating Active Directory, Azure, and Office 365 telemetry, and on automating SOC operations. Then, during my PFE at PwC, I designed detections on Microsoft Sentinel: custom KQL rules, data connector integration, and especially automated SOAR playbooks (Logic Apps) to reduce incident response time – for example, approval workflows for GPO changes or detecting connections from unauthorized countries.
What sets me apart: I know both sides of the field. Certified CRTP (Altered Security) and SC-200, I master AD attack techniques and know how to write the detections that stop them. My detection rules are not theoretical – they are designed by someone who knows how the attack really unfolds.
What I can do for you:

Detection engineering Microsoft Sentinel (KQL rules, tuning, false positive reduction)
SOAR automation / Logic Apps playbooks
Azure / Entra ID configuration audit & hardening
Purple team approach: I simulate the attack, then build the detection
Available remotely. If you're looking for someone who secures your Microsoft environment with a real offensive eye, let's talk.
  • English

    Fluent

  • French

    Fluent

  • Arabic

    Fluent

Remote only
Primarily works remotely

Experience

  • PwC
    End-of-Studies Project Internship
    SOFTWARE PUBLISHING
    January 2026 - Today (5 months)
    Casablanca, Morocco
    Development and integration of new data sources (connectors) in Microsoft Sentinel
    Creation of KQL detection rules (Analytics Rules) covering advanced attack scenarios
    Development of automation Playbooks (Logic Apps / SOAR) for incident response
    Development of SOAR capabilities with Microsoft Sentinel
    Incident Response Incident Management Azure Sentinel Azure Logic Apps KQL
  • SEKERA
    Technical Internship
    SOFTWARE PUBLISHING
    June 2025 - September 2025 (3 months)
    Casablanca, Morocco
    Cloud Security Technical Internship
    Collection, analysis, and correlation of telemetry from Active Directory, Azure, and Office 365
    • Automation of SOC tasks and optimization of investigation workflows
    Microsoft Azure Cloud Cloud Integration External API Integration Cloud Administration Microsoft Graph API

Recommendations

Be the first to recommend Mohamed

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • CRTP
    CRTP
  • Engineering Degree — Cybersecurity & Digital Trust
    National Institute of Posts and Telecommunications (INPT)
    2023
    Cycle Ingénieur — Cybersécurité´ e & Confiance Numérique

Certifications

Skill set

Categories