About me
Curious by default. Hands-on by habit.
I'm Muhammad Mubashir (most people call me Mubi), a SOC Analyst and Security Engineer based in Karachi.
My work spans security operations, SIEM administration, incident investigation, and the infrastructure that keeps monitoring useful. I have worked on QRadar integrations and troubleshooting, investigated a phishing campaign and a compromised-server incident, and I am working on a cloud-to-cloud QRadar migration from AWS to GCP.
I enjoy getting beneath the first error message: checking the logs, understanding the system, and finding the next useful step. Outside production work I keep learning through labs, experiments, and questions that usually lead to more questions.
How I work
Start with the evidence
Logs, process paths, service state, and what changed. I would rather confirm a cause than collect symptoms.
Work down the stack
A security tool failing is often a certificate, a disk, a permission, or a route failing. I follow the problem to the layer where it actually lives.
Respect the constraint
Production systems have uptime requirements and people depending on them. The right fix is the one that solves the problem without creating a new one.
Write it down
Notes, timelines, and plain-language summaries for the people who need to make decisions, and for whoever hits the same problem next.
What I work with
Grouped by how I have used each tool, not by a self-rating. Familiarity with a product is not the same as depth in it, and I would rather be clear about which is which.
Used in professional work
Production environments at SOCByte and during my internship.
- SIEM administration
- IBM QRadar (administration, log source onboarding, DSM and event mapping, AQL searches and reports), Wazuh, LogRhythm (internship exposure)
- Monitoring and response
- CrowdStrike, Trend Micro Vision One, Rapid7 InsightIDR, Vectra AI, WAF and HTTP log review
- Threat intelligence
- MISP, Group-IB and CTM360 feeds, VirusTotal
- Infrastructure
- Linux, Windows, VMware ESXi, AWS, GCP, PowerShell
- Vulnerability management
- Rapid7 InsightVM
Built and tested in labs
Self-hosted experiments where breaking things is the point.
- SIEM
- Wazuh standalone and two-node cluster, Agent onboarding, Syslog ingestion, Load testing around 5–6K EPS
- Systems and network
- Ubuntu, TLS, Firewall policy, NAT/PAT, port forwarding, DDNS, Server hardening with scan-and-verify loops
- Code
- Python, Bash, SQL, Django (earlier development work)
Learning now
Areas I am actively building, not claiming.
- Networking
- CCNA preparation: routing, switching, secure network design
- Cloud security
- GCP and AWS security, through migration work
- Familiarity
- Splunk, Wireshark, Nmap
Learning now, and where I am heading
Where I want to grow: broader security engineering and architecture, eventually consulting and leading technical work. I want to be the person who designs monitoring that holds up, not only the one who keeps it running. That is a direction, not a title I claim today.
- Preparing for CCNA, to go deeper on routing, switching, and secure network design.
- Cloud security, picked up hands-on through the QRadar AWS-to-GCP migration.
- Linux and QRadar internals, one troubleshooting session at a time.
The people part
Much of what I know came from colleagues and mentors who answered my questions, let me take on real problems early, and told me honestly what to improve. I try to pay that forward by documenting what I learn.
Off the clock
Away from work I build lab setups from whatever hardware I can get my hands on, and I am into PC performance and gaming. Same root cause, really: I like knowing how the machine actually behaves.
Education
BS Computer Science
University of Karachi (UBIT), 2022 – 2026
Certifications
- Certified in Cybersecurity (CC), ISC2 (January 2026)
- IBM & ISC2 Cybersecurity Professional Certificate, IBM & ISC2 (June 2025)
- Google Cybersecurity Professional Certificate, Google (May 2025)
- Palo Alto Networks Cybersecurity Professional Certificate, Palo Alto Networks (May 2025)
Want the short version?
The résumé has everything on one page, with a PDF you can download.