Open to SOC roles · Salé, Morocco · On-site, hybrid or remote

Mohamed
Lachgar

Seven years on the console of a 24/7 government-sector Security Operations Centre. I triage what the SIEM surfaces, run the incidents that turn out to be real, and write the detections that catch the next one earlier.

7+
Years in a 24/7 SOC
24/7
Monitoring coverage
8
Tools in daily use

01 / About

Seven years of watching what everyone else scrolls past

How I work, and what I bring to a security operations team.

I'm a SOC analyst at a Moroccan government agency, working inside a 24/7 Security Operations Centre. Since 2019 I've sat on the side of security where the alerts actually land — monitoring and analysing what the SIEM surfaces, and deciding, shift after shift, which of it matters.

Most of that work is unglamorous on purpose. A phishing campaign reported by a user, a suspicious binary that needs pulling apart, a burst of traffic that looks wrong for the hour. I run those to ground: malware analysis, phishing investigation and incident response from first alert through to containment and write-up.

The part I care most about is what happens afterwards. Every incident is a detection that could have fired sooner, so I spend my time on threat hunting and building new detection rules — turning something we found by hand this week into something the platform catches by itself next week.

Security

  • Threat detection
  • Incident response
  • Threat hunting
  • Malware analysis
  • Phishing analysis
  • Cyber threat intelligence
  • Detection engineering

Tooling

  • Elastic Stack (ELK)
  • Kibana
  • TheHive
  • Cortex
  • MISP
  • Snort IDPS
  • Sysmon
  • Fleet agent

Platforms & frameworks

  • Linux
  • Windows
  • Networking
  • MITRE ATT&CK

02 / Experience

Experience & education

Where I've worked and what I was responsible for.

Aug 2019 — Present

SOC Analyst

Government agency · Rabat, Morocco · Full-time, on-site

Security analyst in a 24/7 Security Operations Centre at a government agency. The employer is not named publicly.

  • Monitor and analyse security alerts from SIEM tooling across a round-the-clock shift rotation.
  • Respond to cybersecurity incidents end to end, including malware analysis and phishing campaigns.
  • Contribute to threat hunting and to the development of new security detection rules.
Elastic Stack (ELK)KibanaSnort IDPSCortexTheHiveMISPSysmonFleet agent

Education

Cisco Networking Academy

Cisco · with the Agence de Développement du Digital

Networking and cybersecurity coursework, taken alongside full-time SOC work. The certifications below came out of this programme.

03 / What I do

The four things I'm hired for

Day-to-day work from inside a live SOC — not a lab, not a course project.

Monitoring

Alert triage & SIEM monitoring

Working the queue in a 24/7 rotation: reading what the Elastic Stack surfaces, separating the noise from the handful of alerts that deserve a human, and escalating with enough context that the next analyst doesn't have to start over.

Elastic StackKibanaSysmonFleet agent
Response

Incident response

Taking confirmed incidents from first alert to containment and write-up — including malware analysis and phishing campaigns aimed at staff. Cases are tracked in TheHive and enriched through Cortex so the timeline survives the handover.

TheHiveCortexMalware analysisPhishing
Hunting

Threat hunting

Going looking rather than waiting. Hypothesis-driven sweeps across host and network telemetry for the activity no rule has fired on yet, mapped against MITRE ATT&CK so the gaps we find are gaps we can name.

MITRE ATT&CKKibanaSysmonNetwork telemetry
Engineering

Detection engineering & CTI

Writing the new detection rules and Snort signatures that come out of each incident and each hunt, fed by threat intelligence curated in MISP. The goal is simple: what we caught by hand this month should fire on its own next month.

Snort IDPSMISPDetection rulesThreat intel

04 / Certifications

Credentials

Earned through the Cisco Networking Academy and verifiable on Credly. Anything still in progress is marked as such.

Introduction to Cybersecurity

Cisco Networking Academy

2026

Introduction to Modern AI

Cisco Networking Academy

2026

Apply AI: Update Your Resume

Cisco Networking Academy

2026

Digital Awareness

Cisco Networking Academy

2026

Cybersecurity Career Path

Cisco Networking Academy

In progress

Elastic Certified Analyst

Elastic

In progress

05 / Contact

Let's talk

Hiring for a SOC or detection role, or need a second pair of eyes on your setup? The inbox is the fastest route.

I reply to everything that isn't a bulk mailshot — usually within a day. Open to on-site, hybrid and remote.