Defending Enterprise Borders

Automating Defense &
Detection Engineering

Specializing in  

Canadian-trained Cybersecurity Analyst with 4+ years of specialized experience in high-compliance SOC operations, detection engineering, and security automation. Expert at threat hunting, custom SIEM parser design, and scripting Python frameworks to cut analyst triage times by 95%.

Profile Summary

Get to Know Me

Enterprise Security with an Automator's Mindset

Hey! I'm Sohail and I'm a passionate CyberSecurity Enthusiast and Developer. Started in Toronto, Canada, I am currently transitioning back to Hyderabad, India. I served as an IT Security Analyst (SOC Operations) at LifeLabs within a fully remote, high-compliance health-tech security operations team, on a mission to drive proactive defense architectures.

I approach digital security through a software engineering lens. Beyond standard monitoring, I specialize in building active detection capabilities, authoring high-fidelity detection rules, and scripting automated toolsets to drop manual analyst alert triage times by up to 95%.

Download Resume Get in Touch
95%
Triage Overhead Saved
4+ Years
Enterprise Exposure
35%
False Positive Reduction

Developer & Scripting Stack

My core software engineering skills and development frameworks that power my security tooling:

Coding & Languages

HTML5 / CSS3
JavaScript
Python
GoLang
Rust
Node.js
React
Docker
Git
Java
Swift
Kotlin
Objective-C
PHP
C#
Lua
.Net
Bash / Shell
SQL

Human Languages

English (Fluent)
Urdu (Native)
Hindi (Native)
Tactical Competencies

Cybersecurity Capabilities Console

SOHAIL@SEC-OPS: ~ / CAPABILITIES_MATRIX
CrowdStrike (EDR)
Exabeam (SIEM)
LogRhythm (SIEM)
Splunk (Query Language)
Elasticsearch (ELK)
Kibana (ELK)
Logstash (ELK)
Threat Hunting
Threat Intelligence
Incident Response
Qualys (VMDR)
Tenable
Nessus
Kenna
Checkmarx (SAST)
VeraCode (SAST)
Vulnerability Assessment (VA)
Vulnerability Management
Risk Assessment
Threat Modeling
Nmap
Wireshark
Metasploit
Burp Suite
Kali Linux
Remnux (File Analysis)
Network Security
Web Application Security
Mobile Application Security
Cloud Security
Netskope (VPN)
Penetration Testing
Red Teaming
Blue Teaming
Sample Analysis
Cyera (DLP)
Data Loss Prevention (DLP)
Proofpoint (Email Security)
Abnormal AI (Email Security)
Email Security
Encryption
Hashing
Cryptography
Cybersecurity Frameworks
ServiceNow (ITSM)
BMC Helix (ITSM)
Credentials

Industry Standard Certifications

VALID UNTIL APR 2029

GIAC GMON

GIAC Continuous Monitoring Certification (SEC511)

Validates top-tier expertise in continuous monitoring, threat analysis, SOC operations management, and architectural defense structures.

VALID UNTIL JUL 2027

CompTIA Security+

Systems Security & Risk Standard

Demonstrates core global competencies in incident response, endpoint node defense, cryptographic protocols, and organizational risk audits.

VALID UNTIL DEC 2026

ISC2 CC

Certified in Cybersecurity

Establishes rigorous foundational expertise across essential domains of security operations, access controls, and network security.

Professional Experience

Career Milestones & Chronology

Nov 2025 - May 2026

IT Security Analyst (SOC Operations)

LifeLabs • Toronto, ON, Canada

Developed 5+ custom SIEM parsers for DLP, UBA, and WAF sources to expand detection coverage by 30%. Scripted an automated CrowdStrike CSV log parsing framework in Python, dropping analyst alert triage overheads by 95%. Automated multi-stage threat intelligence Lookups (VT/OTX APIs) and spearheaded Forescout NAC system refreshes.

Feb 2024 - Nov 2025

IT Security Analyst

LifeLabs • Toronto, ON, Canada

Orchestrated weekly Qualys VMDR vulnerability scans on core infrastructure and network nodes. Led risk assessments on 50+ software apps and 40+ production server rollouts. Built Selenium-powered Python reporting pipelines to aggregate CrowdStrike analytics (cutting triage overhead by 40%). Led evidence compliance for SOC 2 Type II audits.

May 2023 - Feb 2024

General Systems Manager

Buggy, INABUGGY • Toronto, ON, Canada

Built robust system monitoring solutions using Python and Bash, lowering server downtimes through proactive alarms. Remediated 12+ severe mobile application API security flaws and conducted robust inventory system migrations.

May 2022 - Aug 2022

IT TVM Analyst (Co-op Student)

LifeLabs • Toronto, ON, Canada

Led comprehensive vulnerability scans across 4,000+ endpoints, yielding a 20% total exposure reduction. Completed forensic investigations on suspicious system binaries and supported Incident Response workflows.

Exhibitions

Automated Security Tooling & Scripts

CrowdStrike Threat Hunt Analyzer Mockup
EDR & Threat Hunt

Threat Hunt Analyzer

A scalable Python script to automate Living off the Land (LotL) and process impersonation threat hunting across extensive CrowdStrike logs.

Python CrowdStrike EDR VirusTotal API OTX API
IOC-Scanner Web Application Mockup
APIs & Web Systems

IOC-Scanner

Full-stack web application for scanning and analyzing Indicators of Compromise (IOCs) with real-time threat intelligence.

Full-Stack React.js Cloudflare Pages & Workers
WAF Log Forwarder Dashboard Mockup
Log Pipelines

WAF Log Downloader

An automated, multithreaded Python script that aggregates Imperva WAF event streams and structures them into SIEM-ready indices.

Python Imperva WAF SIEM Ingestion Multithreading
Threat Enrich CLI Terminal Mockup
Log Pipelines

Threat Enrich CLI

A CLI tool to enrich IOCs (IPs, domains, hashes) using VirusTotal, AbuseIPDB, and AlienVault OTX APIs.

Python VirusTotal API AbuseIPDB API AlienVault OTX API CLI Tool
VulScan Product Search Dashboard Mockup
APIs & Web Systems

VulScan Product Search

Lightweight WebApp to search for applications and view their known vulnerabilities. Uses the custom VulScan API.

HTML/CSS/JS PWA Cloudflare Pages
VulScan API Endpoint Mockup
APIs & Web Systems

VulScan API

A free API providing vulnerability data enriched with CISA Known Exploited Vulnerability status, EPSS, and CVSS scores.

Cloudflare Workers RESTful Web Service
PocketWiki Android App Mockup
EDR & Threat Hunt

PocketWiki

Android app to search and save Wikipedia articles. Built with Java and Android SDK using Wikipedia API.

Java Android SDK Android Studio
Not-so-Simple Quizzard Security Game Mockup
APIs & Web Systems

Not-so-Simple Quizzard

A no-auth, no-session, no-cookie security-focused quiz app. Built with PHP and MySQL.

PHP MySQL
Quizzard Android Mobile Mockup
EDR & Threat Hunt

Quizzard Android

Android version of the Quizzard app, focusing on secure mobile development practices.

Java Android Android Studio
Practical Sandbox

Threat Research & Adversary Simulation Labs

Detection Engineering Lab

Designed and built a complex virtualized sandbox utilizing HELK (Hunting ELK) and Sysmon. Used to simulate sophisticated adversary TTPs (Tactics, Techniques, and Procedures) and develop robust, high-fidelity custom Sigma rules to capture evasive threat signals.

Cloud Security & Reputation

Active deployment of serverless security tools across Cloudflare and Azure edge infrastructure. Automated real-time, low-latency IOC scanning, threat ingestion, and dynamic reputation scoring pipelines to minimize external API dependencies.

Defensive CTFs & Research

Active developer of defensive security pipelines and direct threat intelligence shares. High participation on platforms like TryHackMe and HackTheBox, maintaining sharp hands-on specialization across defensive Blue-Teaming and incident mitigation paths.

Contact Form

Get in Touch

Contact Details

Looking for a dedicated SOC L3 Analyst, Detection Engineer, or Security Automation Specialist in Hyderabad? Reach out directly through the form or my primary contact details below.

Phone Number(s)

+91 8801235561 Primary
+1 (437) 987-6561 Secondary

LOCATION FOCUS

Hyderabad (Onsite / Hybrid / Remote)
India (Remote)
UAE & Saudi Arabia (Onsite / Hybrid / Remote)
CONTACT_FORM.EXE [ ACTIVE ]

Message sent!

Thank you for your message!

Expect a response shortly.