MuhammadMubashir

SOC Analyst & Security EngineerKarachi, Pakistan

I keep security monitoring trustworthy, from the log source and the parser to the alert someone has to act on, and I work the incidents that come out the other end.

In progressCurrently working on: IBM QRadar migration from AWS to GCP

The path of a log line, and where I have worked on it

Security monitoring is a pipeline. An alert is only as good as every step before it, so that is where most of my work happens.

  1. Log sources

    Get the data in

    Identified 190 unintegrated assets in a client environment and remediated their log source integrations.

    The audit
  2. Parsing

    Make it readable

    Corrected parsers and DSM mappings for 50+ assets stuck in SIM Generic. Unknown events down 80%.

    Same audit, separate result
  3. SIEM platform

    Keep the platform up

    Traced an hourly QRadar crash to expired certificates. Now moving a QRadar deployment from AWS to GCP.

    The migration
  4. Triage

    Read what it says

    Pivoted from one quarantined email to a 90-day, multi-domain phishing campaign.

    The phishing case
  5. Response

    Act on it

    Contained C2 and crypto-mining on production servers that could not go offline.

    The server case

A migration still in motion and two incidents I helped work. Each one is written up with what I did, what I did not, and what I learned.

All 7 case studies

There is usually another layer worth checking.

I like understanding what the error message leaves out. When something breaks, I work down until I reach the layer where the problem actually lives, and I keep in mind what else moves if I change it.

How I work

  1. The visible errorWhat the screen says went wrong.
  2. The application or serviceWhich process failed, and what its own logs say.
  3. The operating systemServices, scheduled jobs, resource limits.
  4. Storage and permissionsDisk space, mount points, ownership, certificates.
  5. The network pathRoutes, firewall rules, name resolution, reachability.
  6. The vendor's expected behaviourWhat the documentation says should happen.
  7. The consequence of changing itWhat else moves if I fix this one thing.

Experience

From web development into infrastructure, then into the SOC and security engineering. That route is why I keep asking what the system underneath is doing.

  1. April 2026 – Present

    Jr. Security Engineer & Engineering Team Lead, SOCByte

    QRadar administration and audits, log source integration, incident response, VMware ESXi, and the migration work.

  2. February – April 2026

    SOC Analyst Trainee, SOCByte

    Alert triage across SIEM, XDR, NDR and EDR platforms, phishing investigation, WAF log review, and IOC curation in MISP.

  3. February – April 2025

    IT Intern, Pakistan Petroleum Limited

    Network design support, an ISO 27001 control review, vulnerability scanning, and SIEM exposure.

  4. May – July 2024

    Junior Software Developer, Devtects

    Django and MySQL web applications. Still useful whenever a security product turns out to be a web app with problems.

Full résumé

Security gets interesting when you have to make it work.

If you are hiring for SOC, SIEM, or security engineering work, or you just want to compare notes on a stubborn QRadar problem, I would like to hear from you.

Search the site