SOC & Incident Analysis
Security event and log analysis, initial incident triage, MITRE ATT&CK, and Cyber Kill Chain fundamentals.
Cybersecurity portfolio
Junior SOC Analyst L1
Information Security graduate from Ural Federal University, focused on SOC operations, security event and log analysis, web security, and DFIR. Building practical experience through security projects, labs, and competitions.
About
I am an Information Security graduate from Ural Federal University with a focus on SOC operations, security event and log analysis, initial incident triage, web security, and digital forensics.
My practical experience includes web application security assessment using the OWASP Testing Guide, vulnerability classification with OWASP / CWE, Burp Suite work, and analysis of security events and logs in laboratory environments.
I also developed TRACE as my graduation project: a DFIR workstation for collecting, importing, and analyzing Windows digital artifacts, with integrity verification, case management, audit logging, and report generation.
Skills
Focused on the technologies and security practices reflected in my current CV and practical work.
Security event and log analysis, initial incident triage, MITRE ATT&CK, and Cyber Kill Chain fundamentals.
Wazuh and ELK Stack for event search, parsing, normalization, and security monitoring; basic IDS/IPS concepts.
OWASP Testing Guide, OWASP / CWE, Burp Suite, web vulnerability analysis, and controlled security testing.
Collection and analysis of Windows digital artifacts, SHA-256 integrity checks, case management, and audit logging.
Python for automation and data/log processing.
Linux environments including Kali, Ubuntu, Astra, and CentOS, with practical work using Nessus, Cowrie, and Git.
Experience
Practical training completed
Assessed a training web application using the OWASP Testing Guide, documented vulnerabilities, classified findings using OWASP / CWE, and prepared remediation recommendations.
Developed and tested an AES Traffic Decryptor extension for Burp Suite in Java to analyze protected API traffic using AES-CBC.
Implemented a Python tool for automated collection and structuring of open data using Playwright and APScheduler.
Analyzed a controlled injection CTF scenario, documented the investigation process and technical findings, and developed practical documentation for security work.
Projects
Projects that demonstrate practical work with incident investigation, digital artifacts, monitoring, and security tooling.
Graduation project for incident investigation: collection, import, and analysis of Windows digital artifacts, integrity verification, case management, audit logging, and HTML/PDF reporting.
Worked with an isolated Cowrie honeypot environment to monitor attacker traffic, review logs and suspicious activity indicators, and perform initial event triage.
Competitions
Participation in cybersecurity competitions, hackathons, and professional information security events.
Participation in a practical cybersecurity CTF environment focused on solving security challenges.
Participation in cybersecurity challenges requiring analysis, practical problem-solving, and teamwork.
Participation in a cybersecurity competition and related technical challenges.
Participation in a national CTF competition in a team environment.
Participation in a cybersecurity-focused hackathon and web security challenge.
Volunteer at the KOD IB information security conference in Yekaterinburg and participant in UrFU cybersecurity training activities.
Ural Federal University, Institute of Radioelectronics and Information Technologies.
Education
Bachelor's degree in Information Security (10.03.01), 2022–2026.
Graduated from the Information Security program at Ural Federal University. My graduation thesis focused on an automated workstation for information security incident investigations.
Thesis: “Automated workstation for conducting information security incident investigations” — development of the TRACE prototype for collecting and analyzing Windows digital artifacts in DFIR tasks.
Languages
Native language.
B2 — working proficiency.
B1 — working proficiency.
Activities
Mentor supporting international students with university procedures, communication, and initial adaptation.
Volunteer at an information security conference in Yekaterinburg and active participant in cybersecurity events.
Contact
For portfolio questions, project discussion, or professional opportunities, email is the most reliable contact method.