Senior SOC Consultant & Detection Engineer
Riyadh, Saudi Arabia
I build detection systems that actually catch things. With over five years across banking, financial services, and critical infrastructure in Egypt, the UAE, and Saudi Arabia, my work centers on one question: what would an adversary do next, and are we positioned to see it?
My path through the Egyptian Army's Electronic Warfare corps shaped how I think — signals analysis, direction-finding, and pattern recognition under operational pressure. That tradecraft carries directly into how I approach threat hunting and detection engineering today.
At SIDF I lead 24/7 SOC operations for critical financial infrastructure, engineering custom detections, executing APT hunts, and advising on security posture improvements against Saudi NCA and SAMA compliance frameworks. I work at the intersection of adversary behavior, telemetry gaps, and detection logic — turning threat intelligence into durable coverage.
Saudi Industrial Development Fund (SIDF)
Securenass
Coordinates Middle East by GBM
Banque du Caire (BDC)
Egyptian Army
High-fidelity correlation rules, behavioral detections, use-case engineering, detection gap analysis, and detection-as-code workflows. False-positive reduction and detection testing at scale.
IOC/IOA development, OSINT and threat-feed analysis, adversary profiling, and Kill Chain / Diamond Model analysis. STIX/TAXII integration and intelligence operationalization.
Hypothesis-driven and proactive hunting across Windows telemetry and network data. APT identification across the full kill chain, translating hunt results into permanent detections.
Full incident lifecycle management, root cause analysis, malware triage, memory forensics, and post-mortem documentation. CHFI-certified investigative methodology.
Architecture, optimization, and integration of SIEM and XDR platforms. Log ingestion pipeline design — parsing, normalization, enrichment — and SOAR automation across the SOC stack.
SOC maturity assessments, gap analysis, 24/7 monitoring design, playbook & SOP development. Deep familiarity with Saudi NCA, SAMA CSF, ISO 27001, NIST, and CIS Controls.