About me

Curious by default. Hands-on by habit.

I'm Muhammad Mubashir (most people call me Mubi), a SOC Analyst and Security Engineer based in Karachi.

My work spans security operations, SIEM administration, incident investigation, and the infrastructure that keeps monitoring useful. I have worked on QRadar integrations and troubleshooting, investigated a phishing campaign and a compromised-server incident, and I am working on a cloud-to-cloud QRadar migration from AWS to GCP.

I enjoy getting beneath the first error message: checking the logs, understanding the system, and finding the next useful step. Outside production work I keep learning through labs, experiments, and questions that usually lead to more questions.

How I work

  • Start with the evidence

    Logs, process paths, service state, and what changed. I would rather confirm a cause than collect symptoms.

  • Work down the stack

    A security tool failing is often a certificate, a disk, a permission, or a route failing. I follow the problem to the layer where it actually lives.

  • Respect the constraint

    Production systems have uptime requirements and people depending on them. The right fix is the one that solves the problem without creating a new one.

  • Write it down

    Notes, timelines, and plain-language summaries for the people who need to make decisions, and for whoever hits the same problem next.

What I work with

Grouped by how I have used each tool, not by a self-rating. Familiarity with a product is not the same as depth in it, and I would rather be clear about which is which.

Used in professional work

Production environments at SOCByte and during my internship.

SIEM administration
IBM QRadar (administration, log source onboarding, DSM and event mapping, AQL searches and reports), Wazuh, LogRhythm (internship exposure)
Monitoring and response
CrowdStrike, Trend Micro Vision One, Rapid7 InsightIDR, Vectra AI, WAF and HTTP log review
Threat intelligence
MISP, Group-IB and CTM360 feeds, VirusTotal
Infrastructure
Linux, Windows, VMware ESXi, AWS, GCP, PowerShell
Vulnerability management
Rapid7 InsightVM

Built and tested in labs

Self-hosted experiments where breaking things is the point.

SIEM
Wazuh standalone and two-node cluster, Agent onboarding, Syslog ingestion, Load testing around 5–6K EPS
Systems and network
Ubuntu, TLS, Firewall policy, NAT/PAT, port forwarding, DDNS, Server hardening with scan-and-verify loops
Code
Python, Bash, SQL, Django (earlier development work)

Learning now

Areas I am actively building, not claiming.

Networking
CCNA preparation: routing, switching, secure network design
Cloud security
GCP and AWS security, through migration work
Familiarity
Splunk, Wireshark, Nmap

Learning now, and where I am heading

Where I want to grow: broader security engineering and architecture, eventually consulting and leading technical work. I want to be the person who designs monitoring that holds up, not only the one who keeps it running. That is a direction, not a title I claim today.

  • Preparing for CCNA, to go deeper on routing, switching, and secure network design.
  • Cloud security, picked up hands-on through the QRadar AWS-to-GCP migration.
  • Linux and QRadar internals, one troubleshooting session at a time.

The people part

Much of what I know came from colleagues and mentors who answered my questions, let me take on real problems early, and told me honestly what to improve. I try to pay that forward by documenting what I learn.

Off the clock

Away from work I build lab setups from whatever hardware I can get my hands on, and I am into PC performance and gaming. Same root cause, really: I like knowing how the machine actually behaves.

Education

BS Computer Science
University of Karachi (UBIT), 2022 – 2026

Certifications

  • Certified in Cybersecurity (CC), ISC2 (January 2026)
  • IBM & ISC2 Cybersecurity Professional Certificate, IBM & ISC2 (June 2025)
  • Google Cybersecurity Professional Certificate, Google (May 2025)
  • Palo Alto Networks Cybersecurity Professional Certificate, Palo Alto Networks (May 2025)

Want the short version?

The résumé has everything on one page, with a PDF you can download.

Search the site