In pursuit of greatness
curriculum vitæ

Saïd S.
on my way to the SOC

Three years in IT. Two of them inside the systems and networks of a CAC 40 energy giant. I invested serious hours into CTFs, which gave me the attacker perspective first, then the SOC became the field I chose to build in. Based in Lyon, open to France and the UK first, then the rest of Europe.

Departure
IT support, 2022
Stops so far
4 companies, 1 master's degree in cybersecurity
Experience
3 years in IT
Destination
SOC analyst N1, January 2027
the route
Sep 2022 → Sep 2023
i-Tech
IT technician
First experience. Server administration and maintenance, alongside the security side of the role. Set up and secured firewalls with IPS/IDS and network interface configuration, ran vulnerability scans, access control and system hardening, and delivered cybersecurity awareness lectures in high schools.
firewallsIPS/IDSvulnerability scanshardeningsupport
Sep 2023 → Dec 2023
Mairie de Perpignan
Systems, Networks & Security Admin
A few months in public sector IT. Handled system upgrades from patch deployments to software dependency management, daily backups with retention policies and integrity checks, secured IT profiles and assets, and ran basic intrusion testing on database servers, then addressed what it found. Kept the Bash, PowerShell and Python automation scripts alive and wrote the update reports to go with them.
patchingbackupsintrusion testingBashPowerShellPython
2023 → 2026
Relevant coursesWeb Pentesting · Malware Analysis & Detection · Reverse Engineering · Incident Detection & Response · Digital Forensics · Network Security
EPITECH
Master degree Cybersecurity, GPA 3.8 / 4.0
The degree pursued alongside professional roles. Three years, with cybersecurity as the specialisation and strong academic results.
Master degreecybersecurityGPA 3.8
Jan 2024 → Aug 2024
COULEUR'
Full-stack developer
Eight months building web applications end to end for real clients. Front-end and back-end features primarily in PHP, translating client needs into technical specifications, handling client requests and resolving issues, unit and integration testing, and continuously improving the existing applications.
PHPfront-endback-endtesting
Sep 2024 → Sep 2026
TotalEnergies
Systems, Networks & Security Admin (apprenticeship)
Two years inside the IT of a CAC 40 energy giant. Built and tested IoT systems with a focus on security, ran security assessments and network exposure testing, deployed Zabbix monitoring which improved incident detection by 70 percent, automated tasks in Bash cutting manual workload by 30 percent, led security awareness sessions with simulated phishing, vishing and CEO-fraud exercises, took part in a cyber crisis simulation, and managed users and access rights for sensitive industrial zones. This is where the focus shifted, from offensive curiosity to detection and incident response.
Zabbixsecurity assessmentsIoTBashawarenessaccess rights
Now
In parallel: launching applications and SaaS projects, hackathons and CTFs, organised around the certification schedule.
Current position
Finishing the apprenticeship, focused on certifications and the job search
SOC analyst path in progress. LetsDefend now, BTL1 in the fall, home lab running in Docker, CTFs on weekends. Available from the end of 2026.
LetsDefendhome labavailable
Oct 2026
SC-200
Microsoft Security Operations Analyst
Sentinel and Defender, the stack I want to run in production.
Nov 2026
BTL1
Blue Team Level 1
Hands-on blue team work. Phishing triage, SIEM queries, practical validation.
Jan 2027
Security+
CompTIA Security+
The certification recruiters filter on. In progress.
Jan 2027
SOC Analyst N1
the destination
Full time detection and response. That is the plan.
receipts
Insomni'Hack 2026 venue and scoreboard
22/116
Insomni'Hack 2026, Geneva. First international CTF, top academic team.
3rd
POC CTF 2025, overall. First place in web security, 6000+ students.
950
TOEIC. Fully operational in professional English.
350h+
HackTheBox. The foundation of the offensive skill set.
6th
Cyber 9/12. Strategy and incident response under pressure, team event.
the arsenal

SOC & detection

  • Splunk daily driver
  • Microsoft Sentinel solid
  • Wazuh solid
  • CrowdStrike basics
  • Wireshark solid
  • Volatility basics

Offensive

  • Nmap solid
  • Burp Suite solid
  • Web exploitation CTF level
  • Binary exploitation learning
  • OSINT solid

Ops & systems

  • Windows & AD admin 2 years pro
  • PowerShell admin level
  • Bash / Linux daily
  • Python working knowledge
  • Docker labs & tools
things I built
Looking for an ambitious SOC team, a real stack to master, Splunk or Sentinel. Available from January 2027.

The long version of some of these projects is on the blog.