Netherlands

Security Portfolio

Cybersecurity | SOC & Defensive Security

Hands-on cybersecurity portfolio focused on SOC monitoring, SIEM/XDR deployment, and incident response. All work is performed in authorized environments. Full personal details are provided on the CV.

SOC monitoring & incident response (phishing, malware investigations)

SIEM/XDR implementation (Wazuh, Microsoft Sentinel, Entra ID integration)

Independent setup of monitoring environments with structured documentation

OSINT & threat analysis fundamentals

Basic penetration testing of endpoint devices

Technical incident reporting with clear remediation guidance

Projects

Case-study style work with clean documentation. All work is performed in authorized lab environments.

Wazuh SIEM & XDR Deployment

Designed and implemented a Wazuh-based SIEM/XDR environment, including integration with a customer portal and structured monitoring workflows.

WazuhSIEMXDRLog AnalysisIncident Detection
  • Configured log ingestion and alerting pipelines
  • Implemented structured monitoring for security events
  • Documented setup and operational procedures for maintainability

SOC Monitoring & Incident Investigations

Performed SOC monitoring and handled incident investigations involving phishing attachments and malware-related alerts using Microsoft Sentinel and Wazuh.

SOCIncident ResponsePhishing AnalysisMalware InvestigationMicrosoft Sentinel
  • Investigated phishing attachments and suspicious activity
  • Produced structured incident reports with clear findings
  • Maintained monitoring coverage and alert triage workflows

Palo Alto NGFW Policy Configuration & Monitoring

Worked with a Palo Alto Next-Generation Firewall to design and implement custom security rules, monitor traffic, and improve visibility into network activity.

Palo Alto NGFWFirewall RulesNetwork SecurityTraffic Monitoring
  • Configured custom security policies based on network segmentation requirements
  • Monitored firewall logs to detect suspicious or anomalous traffic patterns
  • Validated rule effectiveness and minimized unnecessary exposure
  • Documented firewall changes and monitoring procedures for operational clarity

Endpoint Device Security Assessments

Conducted controlled penetration testing on endpoint devices within an authorized environment and documented technical findings and remediation recommendations.

Penetration TestingEndpoint SecurityVulnerability AssessmentReporting
  • Identified security weaknesses in device configurations
  • Documented vulnerabilities and practical mitigation steps
  • Delivered clear, actionable technical recommendations

Skills

Grouped for quick scanning by recruiters and technical interviewers.

Cybersecurity & Operations

  • SOC monitoring
  • Incident response (phishing, malware)
  • SIEM/XDR configuration
  • Threat analysis (OSINT fundamentals)
  • Incident documentation & reporting

Platforms & Systems

  • Windows
  • Linux (Debian, Ubuntu, Kali)

Security Tools

  • Wazuh
  • Microsoft Sentinel
  • Microsoft Entra ID

Scripting & Web

  • Python (fundamentals)
  • HTML / CSS (fundamentals)
  • PHP (fundamentals)

Certifications

In progress items are listed; verification links are added upon completion.

CCNA (In Progress)

CiscoExpected 2026

No public verify link

CompTIA Security+ (In Progress)

CompTIAExpected Q1 2027

No public verify link

HTB CPTS Path (In Progress)

Hack The BoxOngoing

No public verify link

HTB / CTF

Progress highlights without disclosing sensitive solutions or active machine spoilers.

Current

  • Hack The Box: CPTS PathIn progress

Recent

  • Hack The Box: Labs & challengesPracticing enumeration, privilege escalation, and reporting discipline.

Recruiter Pack

This portfolio intentionally does not publish personal contact details. Full details are available on the CV provided with the application.

Contact Details

Contact information is shared directly with recruiters during the application process.

Verification

Certification verification links are added upon completion.

Scope & Ethics

All work shown here was performed in authorized labs or with explicit permission.