About Omar
French
Native or bilingual
English
Native or bilingual
Experience
- EconocomCybersecurity Analyst - SOC N3April 2024 - Today (2 years and 2 months)Incident response and security alert handling (RUN)- Proactive monitoring and threat detection: Taking into account and in-depth analysisof alerts generated by security equipment (Cloud / On-premises).- Advanced investigation and real-time response: Incident analysis usingspecialized tools (SIEM, EDR, IDS/IPS, WAF, firewall) to identify attack vectors andpotential impacts.- Optimization of detection rules to refine alert accuracy.- Preparation of detailed reports on security incidents,including investigation findings, corrective actions, andrecommendations to strengthen the security posture.-Advanced Detection: Analyzing needs and designing new detection rules toimprove threat monitoring and detection.- Rule Optimization: Adjusting detectionrules to refine alert relevance and enhance responsiveness to emerging threats.-Development of incident response playbooks: Contribution to the development of playbooks detailingincident response steps, best practices, and appropriate corrective actions.- Planning and execution of vulnerability scans: Deployment and monitoring of monthlyscans (WAS and VMDR) across all entities in different countries.to various attack scenarios.Projects:o Security supervision and management: Creation and management of supervision dashboards onAzure Sentinel and CrowdStrike, enabling real-time visualization of security eventsand rapid decision-making.o Deployment and optimization of Falcon Identity Protection (CrowdStrike): Implementation andadjustment of the solution to detect and block in real-time identity compromise attemptsin a hybrid cloud environment, thereby strengthening resilience against threats.
- AKKodisCybersecurity AnalystOctober 2022 - March 2024 (1 year and 5 months)Security alert and incident managementThreat monitoring and detection: Analysis, qualification, and handling of security incidents reported by defense equipment (SIEM, EDR, IDS/IPS, WAF, firewall), in both Cloud and On-premises environments.Incident response & escalation: In-depth investigation, identification of attack vectors and their potential impacts, with escalation to clients if necessary.Cybersecurity watch: Regular monitoring of vulnerabilities, emerging threats, and new attack techniques, to anticipate risks and adjust defense measures.Process optimization: Reduction of false positives by adjusting detection rules.Recommendations and remediation: Development of corrective measures adapted to detected incidents, and client support in their implementation, including post-remediation follow-up.Malware analysisIn-depth malware study: Static and dynamic analysis of malware detected in monitored environments or received from clients.Threat identification: Determination of capabilities, objectives, obfuscation techniques, and infection vectors, to define concrete countermeasures.Continuous improvement: Use of analysis results to enrich detection rules and develop new protection strategies adapted to the context.Threat watch and analysisMonitoring of cyber trends, ongoing attack campaigns, and critical vulnerabilities, to adapt SOC defenses in real-time.Project:Development of a Purple Team infrastructure: Design and deployment of a platform for testing SOC security tools through realistic attack simulations. Objective: evaluate the effectiveness of detection mechanisms and continuously improve response capabilities through new use cases.
- CapgeminiAnalyst - SOCAugust 2020 - September 2022 (2 years and 1 month)Security alert management & Incident Response- Continuous monitoring: Handling and analysis of security alerts reported bydefense equipment (SIEM, EDR, IDS/IPS), with rapid assessment of impacts andrisks.- In-depth investigation: Threat identification, incident classification, and implementationof appropriate remediation measures.- Detection optimization: Adjustment of rules and refinement of configurations toreduce noise and improve alert relevance.Advanced malware analysis- Static and dynamic malware examination: Behavioral analysis of malwaredetected in monitored perimeters, allowing identification of indicators of compromise (IOC).- Threat detection and neutralization: Study of infection vectors, persistence mechanisms,and evasion capabilities in order to propose effective countermeasures.Projecto Study and deployment of Cuckoo Sandbox: Design and implementation of an automatedmalware analysis environment using Cuckoo Sandbox, allowing simulation of threat executionin a controlled environment to better understand their behavior and refine defense strategies.
Recommendations
Be the first to recommend Omar
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- SEC450: Blue Team Fundamentals: Security Operations and Analysis.2020SEC450: Blue Team Fundamentals: Security Operations and Analysis.
- State Engineer in Computer Science and NetworksENSAO,2017Ingénieur d'Etat en Informatique et Réseaux