Muhammad Zeeshan

Lead Security Engineer

Lead Security Engineer with expertise in SOC operations, threat detection, cloud security, and AI-powered cybersecurity solutions for financial institutions.

0 Threats Detected
0 24/7 SOC Monitoring
0 % Uptime Achieved
zeeshan@security:~$
root@soc:~# |
Muhammad Zeeshan - Lead Security Engineer

SOC Dashboard

Active Threats 0
Blocked IPs 0
System Health 98%
MALWARE BLOCKED
PHISHING DETECTED
INTRUSION BLOCKED

About Me

As a Lead Security Engineer, I orchestrate advanced SOC operations, encompassing the end-to-end design and deployment of internal SOCs leveraging open-source tools like Wazuh, TheHive, and the ELK stack. My expertise extends to proactive threat detection via MITRE ATT&CK-aligned SIEM rules, behavioral analytics, and the proficient utilization of XDR, MXDR, and EDR platforms.

I am proficient in securing diverse cloud environments, conducting incident response workshops for AWS and Cloudflare, and managing security tools across AWS, Azure Sentinel, and Cloudflare. Furthermore, I lead AI-powered cybersecurity solutions for enhanced threat detection and anomaly identification, specifically tailored for financial institutions.

2025
Lead Security Engineer - Merik Solutions
2024
Performer of the Quarterly - Ebryx
2022
Security Engineer - Ebryx
Location: Islamabad, Pakistan
Email: muhammadzeeshan494@gmail.com
Languages: Urdu (Native), English (Bilingual)

Professional Experience

Feb 2025 - Present

Lead Security Engineer

Merik Solutions, Islamabad

Currently leading the internal SOC at Merik Solutions, overseeing technical operations, team development, and strategic direction. SOC initiatives span from open-source tool deployment to AI-powered security use cases for the finance sector.

  • Designed and deployed a full-featured internal SOC using open-source tools including Wazuh, TheHive, and ELK stack
  • Developed comprehensive training roadmap for SOC analysts with hands-on labs and continuous assessments
  • Conducted technical lectures and workshops on Python-based automation for log parsing and SOAR integrations
  • Led incident response tabletop sessions simulating real-world breaches
  • Building analyst rosters and shift rotations to ensure 24/7 SOC coverage
  • Creating, tuning, and maintaining SIEM detection rules with MITRE ATT&CK-aligned use cases
  • Mentoring team members and participating in hiring new SOC analysts
  • Leading development of AI-powered cybersecurity use cases for financial institutions
  • Conducting client meetings to assess security needs and propose tailored SOC solutions
  • Improving SOC operations by aligning practices with SANS, NIST, and MITRE frameworks
June 2022 - Feb 2025

Security Engineer

Ebryx, Lahore

Working as part of SOC Team, actively monitoring, containing, and responding to security threats by collecting TTPs and following effective models like SANS and NIST.

  • Continuously monitored Network/Host in 24/7 SOC environment using SIEM/EDR tools
  • Identification and investigation of Logs/Events and escalation of security incidents
  • Threat hunting, use-case creation, rate limiting, and tuning of SIEM and IDS rules
  • Designed, developed, and maintained Incident Response playbooks
  • Conducted AWS Security and Cloudflare incident response workshops
  • Developed threat detection rules in ELK and Azure Sentinel with Logic Apps automation
  • Performed forensic analysis of artifacts from compromised machines/networks
  • Used MITRE ATT&CK to analyze APT techniques and mapped detections over Azure Sentinel Rules
  • Conducted deep analysis of phishing emails and malware using static and dynamic analysis
  • Developed multiple automation scripts for Slack and Azure Sentinel
  • Set up VS Code Server on EC2 with Nginx for secure remote development
  • Created automated vulnerability scanner for final year project

Professional Skills

Detection Engineering

Gap Assessments Threat Hunting Threat Research Security Hardening Purple Teaming

Cloud Security & Assessments

AWS Azure Sentinel Microsoft Defender Cloudflare EC2 RDS S3 IAM VPC SG CF ES Lambda LB

Intrusion Analysis/SIEM Tools

ELK Stack Crowdstrike Falcon Azure Sentinel Cloudflare Wazuh Microsoft Defender Qradar Lacework VIPRE

TCP/IP Protocols & AWS Security

TCP/IP Protocols Traffic Flow Guard Duty Security Hub AWS Security Hub Amazon CloudTrail

Security Tools

Maltego NMAP Wireshark Metasploit Zscaler Azure DevOps The Hive Jira

Languages and Technologies

Kibana Query Language Kusto Query Language Elastic Search Query Python C++ C Computer Networks Data Structures Object Oriented Programming Information Security Operating System

Education & Certifications

Education

BS-Computer Science

Namal University Mianwali

2018 - 2022

Final Year Project: Automated Network Penetrator

Certifications

Certified AppSec Practitioner (CAP)

The SecOps Group

Certified Network Security Practitioner (CNSP)

The SecOps Group

Professional Trainings

AWS Solution Architect

CloudGuru

Network Plus

CBT Nuggets

Linux Fundamentals

Linux

Rate Limiting/Detection Rules and Playbook Creation

Cloudflare

Website Hacking Penetration Testing & Bug Bounty Hunting

Hacking

Resume

Muhammad Zeeshan - Resume

Lead Security Engineer | Cybersecurity Expert

PDF • Updated January 2025

4+ Years Experience
Multiple Certifications
SOC Leadership

Extracurricular Experience

Leadership Roles at Namal University

President - Cyber Security Awareness Society

Served 6 months leading cybersecurity awareness initiatives

Head Education Wing - Namal Environmental Society

Served 6 months organizing educational programs and workshops

Co-Head Education Wing - Namal Society of Social Impact

Served 6 months coordinating social impact educational initiatives

Youth Leadership Camp

Islamabad

Spent 10 days at a Youth Leadership Camp, participating in workshops on leadership, team building, and personal development.

Awards & Achievements

Performer of the Quarterly

Ebryx Pvt. Ltd.

President

Cyber Security Awareness Society, Namal University

Head & Co-Head of Education Wings

Multiple student bodies, Namal University

Youth Leadership Camp

Leadership training program, Islamabad

Contact Me

Location

Islamabad, Pakistan

Languages

Urdu (Native), English (Bilingual)