Threat Detection & Intelligence

Ibrahim
Abdl-Razik

Senior SOC Consultant & Detection Engineer
Riyadh, Saudi Arabia

Current: SIDF — Saudi Industrial Development Fund Clearance background: Egyptian Army, Electronic Warfare Labs: CyberDefenders · TryHackMe (DashTX)
5+ Years in Cybersecurity
4 Countries & Sectors
Tier 3 SOC Depth

Detection engineering
grounded in intelligence tradecraft

I build detection systems that actually catch things. With over five years across banking, financial services, and critical infrastructure in Egypt, the UAE, and Saudi Arabia, my work centers on one question: what would an adversary do next, and are we positioned to see it?

My path through the Egyptian Army's Electronic Warfare corps shaped how I think — signals analysis, direction-finding, and pattern recognition under operational pressure. That tradecraft carries directly into how I approach threat hunting and detection engineering today.

At SIDF I lead 24/7 SOC operations for critical financial infrastructure, engineering custom detections, executing APT hunts, and advising on security posture improvements against Saudi NCA and SAMA compliance frameworks. I work at the intersection of adversary behavior, telemetry gaps, and detection logic — turning threat intelligence into durable coverage.

Core Focus
  • Detection Engineering (Sigma, YARA)
  • Threat Hunting (hypothesis-driven)
  • MITRE ATT&CK mapping & coverage analysis
  • SOC maturity & governance
  • Digital Forensics & Incident Response
Frameworks & Compliance
  • MITRE ATT&CK & D3FEND
  • Saudi NCA (ECC-1:2018, CSCC-1:2019)
  • SAMA Cyber Security Framework
  • ISO 27001 · NIST · CIS Controls
  • Cyber Kill Chain · Diamond Model
Languages
  • Arabic — Native
  • English — Highly proficient

A record built
across live environments

Oct 2024 — Present Riyadh, Saudi Arabia

SOC Consultant

Saudi Industrial Development Fund (SIDF)

  • Direct 24/7 Security Operations Center monitoring and incident response for critical financial infrastructure.
  • Engineer custom detection logic and provide Tier-3+ support for deep-dive investigations, root cause analysis, and post-mortem reviews.
  • Map IOCs and adversary TTPs to MITRE ATT&CK to strengthen detection coverage; identify gaps and onboard new data sources.
  • Execute proactive threat-hunting missions targeting APTs across Windows and network telemetry.
  • Develop SOC playbooks, SOPs, and IR workflows; lead SOC maturity assessments aligned to Saudi NCA (ECC-1:2018, CSCC-1:2019).
  • Guide SOAR automation initiatives and communicate security posture to C-level stakeholders.
Feb 2023 — Oct 2024 Saudi Arabia

L3 SOC Analyst — Team Lead

Securenass

  • Led team-lead function overseeing analysis of network traffic, system logs, and security telemetry across the monitored estate.
  • Engineered and fine-tuned SIEM correlation rules and behavioral detections to eliminate false positives and broaden coverage.
  • Managed end-to-end incident lifecycle — coordination, escalation, resolution — aligned to client SLAs.
  • Relayed actionable advisories from the Central Bank of Egypt (CBE) to stakeholders; synthesized packet inspection findings into executive security-posture reports.
  • Designed and documented standard work processes within the SOC environment.
Dec 2021 — Feb 2023 UAE

Senior SOC Analyst

Coordinates Middle East by GBM

  • Investigated complex security incidents using integrated SIEM, EDR, and NDR solutions.
  • Monitored real-time alerts and traffic for high-value assets: database servers, email infrastructure, security devices.
  • Recommended and implemented detection use cases, reducing noise while enhancing coverage.
  • Used packet inspection and log correlation for forensic-quality incident tracking.
Jan 2021 — Nov 2021 Egypt

L1 SOC Analyst

Banque du Caire (BDC)

  • Performed technical analysis of network flows and intrusion alerts for critical banking infrastructure.
  • Maintained 24/7 monitoring for email, database, web servers, and Domain Controllers.
  • Developed Python automation scripts to streamline investigative workflows and reduce analyst overhead.
  • Contributed to playbook development and use-case engineering for investigation processes.
Nov 2017 — Apr 2020 Egypt

Electronic Warfare First Lieutenant

Egyptian Army

  • Commanded signal-analysis and direction-finding operations to detect and locate electronic signal sources.
  • Conducted technical analysis of intercepted data to identify, classify, and extract actionable intelligence.
  • Produced technical intelligence reports supporting strategic decision-making under operational pressure.

What I build
and how I operate

01 — Primary Discipline

Threat Detection & Detection Engineering

High-fidelity correlation rules, behavioral detections, use-case engineering, detection gap analysis, and detection-as-code workflows. False-positive reduction and detection testing at scale.

Sigma YARA KQL SPL MITRE ATT&CK
02 — Intelligence

Cyber Threat Intelligence

IOC/IOA development, OSINT and threat-feed analysis, adversary profiling, and Kill Chain / Diamond Model analysis. STIX/TAXII integration and intelligence operationalization.

IOC/IOA OSINT STIX/TAXII Adversary Profiling
03 — Hunting

Proactive Threat Hunting

Hypothesis-driven and proactive hunting across Windows telemetry and network data. APT identification across the full kill chain, translating hunt results into permanent detections.

APT Detection Windows Telemetry Network Hunting TTP Analysis
04 — Response

Incident Response & Digital Forensics

Full incident lifecycle management, root cause analysis, malware triage, memory forensics, and post-mortem documentation. CHFI-certified investigative methodology.

Memory Forensics Malware Triage RCA CHFI
05 — Platform Engineering

SIEM / XDR Engineering

Architecture, optimization, and integration of SIEM and XDR platforms. Log ingestion pipeline design — parsing, normalization, enrichment — and SOAR automation across the SOC stack.

QRadar Splunk ELK Wazuh SOAR
06 — Governance

SOC Strategy & Compliance

SOC maturity assessments, gap analysis, 24/7 monitoring design, playbook & SOP development. Deep familiarity with Saudi NCA, SAMA CSF, ISO 27001, NIST, and CIS Controls.

NCA ECC-1 SAMA CSF ISO 27001 NIST

Platform & tool coverage

IBM QRadarSIEM
FortiSIEMSIEM
SplunkSIEM
Elastic StackSIEM
LogRhythmSIEM
WazuhSIEM / XDR
MDEEDR / XDR
CrowdStrikeEDR / XDR
Carbon BlackEDR
Cisco AMPEDR
SuricataNDR / IDS
WiresharkNetwork
NessusVulnerability
MetasploitOffensive
Burp SuiteWeb
PythonAutomation
PowerShellScripting
BashScripting
AWSCloud
AzureCloud

Certifications &
professional development

GIAC GIAC Foundational Cybersecurity Technologies (GFACT) 2023
MITRE ATT&CK Defender (MAD) — Fundamentals, SOC Assessments, CTI, Threat Hunting Active
EC-Council Certified Ethical Hacker (CEH) 2020
EC-Council Certified Incident Handler (ECIH) 2020
EC-Council Computer Hacking Forensic Investigator (CHFI) 2020
AWS AWS Certified Cloud Practitioner Essentials Active
IBM IBM Resilient SOAR Foundations Active
Training TCM Security: Practical Malware Analysis & Triage · Practical Ethical Hacking
SpecterOps Tradecraft Analysis 2022 2022
SANS FOR508 / FOR608 — Advanced Digital Forensics & Incident Response Training
Education B.Sc. Computer Science — Mansoura University (Excellent) 2017

Open to
the right
conversation.