• File

Артем

Фахівець з інформаційної безпеки

Considering positions:
Фахівець з інформаційної безпеки, Аналітик, Cyber security specialist
Age:
22 years
City of residence:
Romny
Ready to work:
Remote

Contact information

The job seeker has entered a phone number .

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

ARTEM KRYVTSUN

SOC Analyst | Blue Team | SIEM | Incident Investigation | Python
Žilina, Slovakia / Remote | Email: [open contact info](look above in the "contact info" section) | GitHub Portfolio: https://github.com/jesuskaya/CSecurity | Telegram: @jesuskaya
PROFESSIONAL SUMMARY
Cybersecurity master's student and aspiring SOC Analyst with practical experience gained through independent projects, university cyber laboratories, TryHackMe training and a personal virtual lab. Hands-on exposure to Splunk, Elastic Stack, Wireshark, Nmap, Windows and Linux investigation, EDR/SOAR concepts, MITRE ATT&CK mapping and Python-based security tooling. Built an ML-powered anti-phishing mini-tool with a trainable classification model and developed a network anomaly-detection project. Seeking a Junior SOC Analyst / Security Monitoring position where I can contribute to security monitoring, incident investigation and continuous improvement of detection capabilities.
WORK EXPERIENCE
SOC Analyst L1 | Genesis
February 2026 – July 2026
• Monitored and triaged security alerts across SIEM and EDR platforms, performing initial incident analysis and escalation for Tier 2/3 response.
• Investigated potential security incidents, analyzing malicious indicators of compromise (IoCs), network traffic anomalies, and endpoint telemetry.
• Contributed to the maintenance and tuning of detection rules and security monitoring dashboards to reduce false positives and improve alert fidelity.
• Collaborated with cross-functional IT and infrastructure teams to remediate identified vulnerabilities and contain active security threats.
• Documented incident response procedures, investigation findings, and ticket resolutions in accordance with internal SOC operational metrics and frameworks.
CYBERSECURITY PROJECTS
ML-Powered Anti-Phishing Mini-Tool | Python, Machine Learning
• Designed and developed a security-focused application for analysing suspicious messages and identifyingphishing indicators.
• Implemented a trainable machine-learning classification model and data-processing workflow for phishingdetection.
• Structured the project as a reusable mini-tool with clear input, analysis and result-generation stages.
• Published the project on GitHub with supporting code and documentation.
Network Traffic Anomaly Detection | Python, Isolation Forest
• Built a Python application to detect anomalous network traffic using an Isolation Forest model.
• Prepared and processed numeric and categorical traffic features with Pandas and scikit-learn.
• Added anomaly scoring and visualisation using Matplotlib; tested the tool with network-traffic datasets.
SIEM Investigation Labs | Splunk and Elastic Stack
• Imported and investigated VPN logs in Splunk; parsed JSON with spath and created SPL searches usingfiltering, stats, count and values.
• Used Kibana Discover and KQL to investigate authentication activity, filter events by time and identifysuspicious patterns.
• Created visualisations and an interactive VPN dashboard for failed-login analysis.
Network and Incident Investigation | Wireshark, Nmap, MITRE ATT&CK;
• Analysed PCAP traffic, DNS activity, TCP sessions and suspicious external IP addresses in laboratory scenarios.
• Performed network discovery and service enumeration in a controlled home-lab environment with Nmap.
• Mapped phishing and intrusion scenarios to MITRE ATT&CK; and Cyber Kill Chain stages; documented findings,IOCs and recommended actions.
CYBERSECURITY LABORATORY EXPERIENCE
• FlareVM malware-analysis environment: used a dedicated Windows-based analysis VM and security utilities for controlled investigation practice.
• Windows laboratories: practised system administration, Event Viewer and Windows event analysis, processes, network connections, persistence/autostart review and endpoint-investigation fundamentals.
• Linux and Ubuntu laboratories: practised command-line navigation, users and permissions, processes, networking, logs and basic administration in virtual machines.
• Virtual home lab: configured VMware/VirtualBox environments for Windows, Linux and Ubuntu; performed network scanning, packet capture, tool testing and security exercises.
CORE SKILLS
Security Operations
SIEM, alert triage, log analysis, incident investigation, IOC/TTP analysis, phishing analysis, detection engineering fundamentals
Frameworks & Concepts
MITRE ATT&CK;, Cyber Kill Chain, EDR, SOAR, Incident Response, threat detection, basic malware-analysis workflow
Tools & Platforms
Splunk, Elastic Stack/Kibana, Wireshark, Nmap, FlareVM,
Autoruns, VMware, VirtualBox, Git, GitHub
Systems & Networking
Windows, Linux, Ubuntu, Windows Event Logs, TCP/IP,
DNS, HTTP/HTTPS, DHCP, ICMP, ARP, basic Active
Directory and Azure concepts
Programming & Data
Python, Pandas, scikit-learn, Matplotlib, basic Bash, JSON log parsing, SPL and KQL fundamentals
Professional-soft Skills
Analytical thinking, attention to detail, documentation, structured escalation, continuous learning

TRAINING & CERTIFICATIONS
• CYBRIX Academy – Practical SOC & Cybersecurity Training covering networking, threats, SOC concepts, incident analysis and security tools.
• Hillel Python Basic – Full Course of study (Certificate)
• Hillel Python Professional – Full Course of study (Certificate)
• TryHackMe: SIEM, Splunk Basics, Elastic Stack: The Basics, Introduction to EDR, SOAR, Detection Engineering(Introduction) and other SOC-oriented labs.
• Additional study: MITRE ATT&CK;, Cyber Kill Chain, Windows/Linux fundamentals, networking protocols, phishing, malware, ransomware and Active Directory basics.
• ISC2 Certified in Cybersecurity (CC) - in progress.
EDUCATION
National Technical University "Kharkiv Polytechnic Institute" (NTU "KhPI")
Master's Degree in Cybersecurity – In Progress
5th-year university student; Bachelor's Degree in Cybersecurity completed.
LANGUAGES
Ukrainian: Native | Russian: Native | English: B2 (working proficiency, actively improving)

More resumes of this candidate

Similar candidates

All similar candidates


Compare your requirements and salary with other companies' jobs: