Open to Work — UK SOC Analyst Roles

Poorna
Sujampathi

Cyber Security Analyst · Threat Intelligence · SOC Analyst

Performance-driven SOC Analyst with 2.5+ years across Tier 1 & Tier 2 operations in Banking, Aviation & Telecom.
NCSC Certified MSc · Hatfield, UK · Graduate Route Visa

Microsoft Sentinel CrowdStrike Falcon IBM QRadar NetScout DDoS Splunk Python Automation
2.5+ Years SOC Experience Tier 1 & Tier 2
1K+ Daily Alerts Triaged 100% SLA Maintained
30% Efficiency Gain Python Automation
3 Industry Sectors Banking · Aviation · Telecom
MSc Cyber Security NCSC Certified

A security professional
with a passion for defence.

Performance-driven Security Operations Centre (SOC) Analyst with over 2.5+ years of international experience across Tier 1 and Tier 2 operations in the Banking, Aviation, and Telecommunications sectors.

Proven track record in orchestrating real-time DDoS mitigation for critical infrastructure and automating alert triage using Python to improve operational efficiency by 30%.

Currently completing an NCSC Certified MSc in Cyber Security at the University of Hertfordshire, with a research focus on AI-augmented incident response and advanced digital forensics. Seeking SOC Analyst and Threat Intelligence roles in the UK.

Total Experience
2.5+ Years (Tier 1 & Tier 2)
Alert Triage & SLA
1,000+ Daily Alerts (100% SLA)
Education
MSc Cyber Security (NCSC Certified)
Location & Eligibility
Hatfield, UK · Graduate Route Visa

Technical expertise across
the security stack.

Security Operations (SIEM/EDR)

  • Microsoft Sentinel
  • IBM QRadar
  • McAfee SIEM
  • CrowdStrike Falcon
  • Microsoft Defender for Endpoint
  • Cortex XDR

Threat Detection & Analysis

  • Threat Intelligence Analysis
  • IOC Investigation
  • Threat Hunting
  • Behavioral Anomaly Detection
  • Malware Analysis

Frameworks & Compliance

  • MITRE ATT&CK Mapping
  • NIST CSF
  • ISO 27001
  • GDPR Compliance

Infrastructure & Tools

  • WAF Monitoring
  • CyberArk (PAM)
  • Forcepoint DLP
  • NetScout Arbor
  • Python for Security Automation
  • SOAR Playbook Development

Beyond security —
creative expertise.

Graphic Design

Visual Design & Branding

Creating compelling visual identities, social media graphics, marketing materials, and brand assets that communicate clearly and leave a lasting impression.

Adobe Photoshop Adobe Illustrator Canva Pro Figma Adobe InDesign
Video Editing

Video Production & Post

Producing professional video content including cinematic edits, motion graphics, colour grading, and audio mixing for YouTube, social media, and corporate use.

Adobe Premiere Pro After Effects DaVinci Resolve CapCut Adobe Audition
Web Design

UI/UX & Web Development

Designing and building clean, modern, responsive websites and landing pages with a focus on user experience, accessibility, and performance optimisation.

HTML / CSS JavaScript Figma WordPress Responsive Design

Where I've worked
and what I've achieved.

2023 – 2024 Air Arabia

Associate Infrastructure Analyst (SOC Tier 2)

★ Best Performance Award 2023
  • Orchestrated real-time triage for 1,000+ daily security alerts using Azure Sentinel, maintaining 100% adherence to critical incident Service Level Agreements (SLAs).
  • Engineered custom automation scripts in Python to enrich alert context, reducing the mean time to investigate (MTTI) by 30% and optimizing Tier 1 analyst bandwidth.
  • Spearheaded threat detection initiatives using Microsoft Defender, identifying and neutralizing stealthy lateral movement attempts within the aviation network.
  • Collaborated with cross-functional NOC teams to resolve high-severity infrastructure incidents, ensuring continuous business availability for global flight operations.
  • Awarded Best Performance Award (2023) for excellence in incident remediation and proactive tool tuning.
2022 – 2023 Nations Trust Bank

Information Security Analyst

  • Led the mitigation of a large-scale live DDoS attack on core banking systems, safeguarding financial assets for 1M+ customers and preventing service disruption.
  • Monitored and analysed critical security events using McAfee SIEM and CrowdStrike, performing deep-dive forensic investigations into confirmed Indicators of Compromise (IOCs).
  • Enhanced the SOC Knowledge Base by developing 5+ new incident response playbooks, standardizing recovery procedures for ransomware and phishing scenarios.
  • Supported Data Loss Prevention (DLP) initiatives using Forcepoint, identifying and mitigating unauthorized data exfiltration risks across the enterprise.
2022 SLT-Mobitel

Information Security Analyst Intern

  • Configured 15+ custom correlation rules in IBM QRadar, reducing false-positive alert noise by 30% and improving overall detection accuracy.
  • Monitored high-volume web traffic via WAF and managed privileged access through CyberArk to ensure stringent identity and access management (IAM).
  • Assisted in the containment of multiple network-based intrusion attempts, working alongside senior analysts to document root cause analysis (RCA) findings.

Notable projects
with real-world impact.

ZERO_TRUST_BYOD // ENFORCER.PY
AUTH_CIPHER: AES-128 GCM + UUID Validation ANOMALY_MODEL: ISOLATION_FOREST (0.02 Risk Threshold) BIOMETRIC_CNN: VERIFIED (Facial Liveness Passed)

Advanced BYOD Security Framework

2024–25

Scenario: Unmanaged personal devices in corporate environments introduce severe access risks.

Goal: Design an access control system to securely authenticate and isolate BYOD endpoints.

Actions: Developed a framework using AES-128 encryption and UUID-based authentication. Integrated ML and CNN-based facial recognition to detect anomalies.

Outcome: Created a zero-trust model prototype that prevents unauthorized network access from compromised personal devices.

BYOD Security AES-128 Machine Learning Zero-Trust
DARKWEB_SCANNER // IP_ENRICHMENT.PY
VIRUSTOTAL_API: MALICIOUS (42/70 Detections) ABUSEIPDB_SCORE: 98% CONFIDENCE HIGH RISK DARKWEB_OSINT: C2 BOTNET HOST IDENTIFIED

Dark Web IP Scanner

2023

Scenario: Threat hunting requires checking numerous external IP reputation lists, consuming valuable triage time.

Goal: Automate IP enrichment to quickly determine the severity of a suspicious IP.

Actions: Developed a Python script integrating APIs (VirusTotal, AbuseIPDB, AlienVault OTX) and dark-web OSINT.

Outcome: Automatically generated hashes, geolocation, and severity scoring into an analyst-ready threat summary.

Python Dark Web OSINT VirusTotal API AbuseIPDB
SIEM_PARSER // REGEX_AUTOMATION.PY
LOG_INGEST: 25,000 EVENTS / SEC MTTI_REDUCTION: 30% FASTER TRIAGE NOISE_FILTER: 15+ CUSTOM CORRELATION RULES

SIEM Log Processing Automation

2023

Scenario: Manual triage of noisy, unparsed SIEM alerts leads to alert fatigue and high MTTR.

Goal: Automate log parsing to extract actionable indicators from raw logs.

Actions: Wrote Python scripts to parse log formats and highlight critical fields.

Outcome: Integrated the pipeline with the SIEM, reducing manual triage time by 30% and improving SOC efficiency.

Python Log Analysis SIEM Automation
PHISHING_AI // IMAP_FORENSICS.PY
HEADER_CHECKS: SPF: PASS | DKIM: PASS | DMARC: FAIL GEMINI_AI_ANALYSIS: SPOOFED DISPLAY NAME DETECTED QUARANTINE_ACTION: AUTOMATED ISOLATION SUCCESS

AI-Augmented Phishing & CTI Engine

2022

Scenario: Standard email security filters often miss sophisticated, targeted phishing attacks and zero-day malicious URLs.

Goal: Develop an automated email analysis engine to proactively detect, score, and quarantine complex phishing attempts.

Actions: Built a Python application fetching real-time IMAP emails, validating SPF/DKIM/DMARC headers, and querying CTI feeds + Gemini AI API.

Outcome: Created a robust pipeline that automatically flags spoofing and quarantines malicious messages with high accuracy.

Python Email Forensics Threat Intel Gemini AI
KALI_CLI // PENTEST_RECON.SH
NMAP_STEALTH: PORTS 22, 80, 443 OPEN NIKTO_WEB_SCAN: CVE-2023-XXXX DETECTED HTML_REPORT_GEN: SUCCESS (/tmp/recon_report.html)

Kali Linux CLI Pentesting Scanner

2024

Scenario: Routine vulnerability assessments involve running fragmented tools manually, causing reporting delays.

Goal: Create a lightweight, unified scanning tool to streamline basic reconnaissance.

Actions: Built a Bash CLI tool on Kali Linux orchestrating Nmap, Nikto, and Metasploit auxiliary modules.

Outcome: Consolidated scan outputs into structured HTML reports, doubling assessment speed and repeatability.

Kali Linux Bash Nmap Metasploit

Certifications & Awards

What I'm working on
right now.

In Progress

SOC 200 Certification

Preparing for SOC 200 certification with a focus on advanced SOC operations, security monitoring, incident handling, threat detection, and real-world SIEM workflows.

Timeline: Q2 2026 Priority: High
In Progress

TryHackMe – SOC Learning Path

Actively following the TryHackMe SOC Learning Path with daily hands-on practical labs, focusing on SIEM alert analysis, log investigation, threat detection, and incident response in real-world SOC scenarios.

Timeline: Ongoing Priority: High
Upcoming

Wazuh Policy Implementation

Implementing and testing Wazuh security policies using Kali Linux, including log analysis, rule tuning, agent configuration, and threat detection use cases.

Timeline: Q1 2026 Priority: Medium
Upcoming

Custom SOC Lab Environment

Designing and building a custom SOC lab environment on Kali Linux, integrating SIEM, endpoint monitoring, threat simulation, and incident response workflows for hands-on SOC practice.

Timeline: Q3 2026 Priority: Medium

Academic
Background.

University of Hertfordshire Logo

MSc Cyber Security

University of Hertfordshire, UK

NCSC Certified MSc

2024 – 2025  ·  NCSC Certified Master's Degree

  • Currently completing an NCSC Certified MSc in Cyber Security with a research focus on AI-augmented incident response and advanced digital forensics
  • Covered distributed systems security, information security management & compliance, digital forensics, penetration testing, and cyber operations
  • Critically evaluated vulnerabilities and threats — conducting comprehensive risk assessments in complex enterprise environments
SLIIT Logo

BSc(Hons) Information Technology
Specialized in Cyber Security

Sri Lanka Institute of Information Technology (SLIIT)

Completed

2020 – 2024  ·  Specialization in Cyber Security

  • Core studies in networking, information security, software engineering, and database systems
  • Specialization in Cyber Security — covering threat detection, network defence, and security operations
  • Final year project focused on BYOD Security using machine learning (Enhanced Security In a BYOD Environment)

Let's build something
secure together.

I'm actively looking for SOC Analyst opportunities in the UK. Whether you're a recruiter, a hiring manager, or a fellow security professional — feel free to reach out!

Phone / WhatsApp +44 7768 875587
Location & Eligibility

Hatfield, UK · Graduate Route Visa (Full-time work eligible)