Experience

I started as an assistant and worked my way up to SOC team lead and L3 engineering.

I work on incident response, threat hunting and security operations. I’m experienced across EDR, NDR, XDR, SIEM and SOAR, with a background in SOC leadership, detection engineering and DevSecOps.

Work experience

  1. Senior Cyber Security Engineer

    Barikat Cyber Security

    Present
    • Perform alarm investigation, triage and incident response across customers’ EDR, NDR, XDR, SIEM and SOAR platforms.
    • Lead proactive threat hunting engagements and conduct root cause analysis for security incidents.
    • Develop and tune detection rules and correlation use-cases to reduce false positives and improve coverage.
    • Provide L3-level support and technical guidance to SOC teams during critical investigations.
    Tools
    SentinelOneCortex XDRVectra NDRCortex XSOARQRadar SIEMSplunkDefender XDR
  2. Senior Cyber Security Engineer

    Kariyer.net — Kariyer Group

    1 yr 6 mo
    • Cyber incident response, threat hunting and vulnerability management.
    • Conducted POC processes on security products.
    • Built security environments and actively contributed to DevSecOps processes using Semgrep and SonarQube.
    • Authored and integrated up-to-date detection rules for SIEM, EDR and DLP products.
    Tools
    CrowdStrike (XDR, SOAR, SIEM, DLP)Microsoft SentinelHumanMicrosoft AzureSemgrepSonarQube
  3. Senior Cyber Security Analyst

    Destel Bilişim Çözümleri A.Ş.

    2 yr 2 mo
    • Started as a Level 2 (L2) analyst, then progressed to Level 3 (L3) analyst and Team Lead within the SOC.
    • Improved customers’ security posture and led regular threat hunting engagements.
    • Performed incident analysis and root cause analysis for cyber incidents.
    Tools
    SplunkQRadarSpyCloudFortiSOARCisco ESACrowdStrike
  4. MDR Analyst

    ADEO Cyber Security Solutions

    1 yr 2 mo
    • Reviewed and prioritized alarms generated by EDR tools.
    • Analyzed current threat reports, created new EDR detection rules and ran threat hunting processes.
    Tools
    CrowdStrike FalconCarbon Black EDRXSOARCortex XDRMicrosoft Defender ATP
  5. Blue Team Assistant Specialist

    Sparta Bilişim

    6 mo
    • Managed Blue Team operations using open-source SIEM, EDR, IDS/IPS and Honeypot solutions.
    Tools
    Open-source SIEMEDRIDS/IPSHoneypot

Education

  • Digital Forensics — MSc

    Fırat Üniversitesi

  • Digital Forensics — BSc

    Fırat Üniversitesi

  • Computer Engineering — Minor

    Fırat Üniversitesi

  • Computer Science — Erasmus

    South East European University

Skills

EDRNDRXDRSIEMSOARDLPThreat HuntingIncident ResponseDetection EngineeringDFIRDevSecOpsVulnerability MgmtBlue Team

Certifications

19

SOC Prime

  • Discovery Detection Master
  • Threat Bounty Program — Trusted Contributor
  • Threat Bounty Program — Recognized Author of Detection Rules

Splunk

  • Splunk 7.x Fundamentals
  • Splunk User Behavior Analytics
  • Splunk Infrastructure Overview

Kaspersky

  • Industrial CyberSecurity — Certified Professional
  • Threat Intelligence Presales

CrowdStrike

  • Sales & Product Training
  • Spotlight App Fundamentals

Basis Technology

  • Intro to DFIR
  • Autopsy Basics & Hands-on

ADEO

  • Windows Forensic Certificate

AND

  • Investigation Theory

Fortinet

  • NSE 1 & 2 — Network Security Associate

Cybrary

  • Creating a World Class SOC

UITSEC

  • Web Application Security Camp

Türk Telekom

  • Cyber Security Summer Camp

Turkish Cyber Security Cluster

  • SIEM-SOC Summer Camp