• File

Ростислав

SOC L1-L2, Cyber Security Analyst, NOC, System Administrator

City:
Kyiv

Contact information

The job seeker has entered a phone number .

Name, contacts and photo are only available to registered employers. To access the candidates' personal information, log in as an employer or sign up.

Uploaded file

Quick view version

This resume is posted as a file. The quick view option may be worse than the original resume.

Rostyslav Bereshchuk
📧 [open contact info](look above in the "contact info" section)
📞 [open contact info](look above in the "contact info" section)
Kyiv, Ukraine | Full-time/Part-time | On-site/Hybrid/Remote
Positions: SOC L1-L2, Cyber Security Analyst, SysAdmin

EDUCATION TECHNICAL SKILLS & TOOLS

National Technical University of Malware Analysis
Ukraine “Igor Sikorsky Kyiv – Static and basic dynamic analysis (IDA, Ghidra, JADX, PE-bear, Frida, local
Polytechnic Institute” and cloud Sandboxes)
Specialty: 125 - Cybersecurity – Classification and practical application of the MITRE ATT&CK framework
Degree: Bachelor’s (Enterprise, Mobile) and the Cyber Kill Chain.
2022 - 2026 Scripting & Automation
– Python, Bash
GPA: 91 / 100
Network Security & Vulnerability Assessment
Additional Education:
– Nmap, Masscan, Burp Suite, mitmproxy, Nessus, OpenVAS,OWASP TOP 10
TryHackMe, Coursera, Cisco
Networking Academy, EY Cyber DFIR
Bootcamp – Endpoint monitoring (Autoruns, Procmon, Sysmon, Syslog, Elastic Defend
logs, Honeypot logs)
LANGUAGES – Forensics (Volatility, Autopsy)
Ukrainian: Native – IoC processing (WHOIS, Maltego, Shodan, MISP, development YARA rules)
English: Technical (B1) Other
– Data Analysis (preprocessing, statistical analysis, visualization)
NETWORK PROTOCOLS
OPERATING SYSTEMS OFFICE TOOLS
TCP, UDP, ICMP, IPsec, TLS,
DTLS, DNS, HTTP/S, SSH, NTP Linux | Windows Microsoft Office | Google Workspace

EXPERIENCE
“ISSP SERVICE” LLC - Diploma Project March - May, 2026
Network Steganography in the NTP
– Researched NTP protocol versions, specifications, use cases, and field behavior, focusing on their purpose and
interrelationships.
– Analyzed traffic from existing PoCs with a limited number of NTP-based covert communication techniques and
identified limitations of existing anomaly detection solutions/tools, including Suricata, Zeek, and Fortinet signatures.
– Implemented 16 covert communication techniques using 12 NTP fields for C2, data exfiltration, and low-bandwidth
fallback communication.
– Designed and implemented a detection approach combining behavioral analysis (e.g., one-way traffic, timestamp
consistency, version switching, and comparison of selected field values against legitimate .pcap data), statistical analysis
(Shannon entropy, min/max, mean, etc.), and protocol compliance analysis (RFC 5905, RFC 8915, RFC 9109).
Environment: 3 local VMs: PDC Emulator - Windows Server 2022, domain-joined client - Windows 10 (NT5DS),
Ubuntu 20.04 - gateway.
Technologies & Tools: Wireshark, Zeek, Snort/Suricata, Python, VPN; Docker Compose deployment: ELK Stack,
Malcolm (AWS/GCP).
Ростислав Берещук
📧 [open contact info](look above in the "contact info" section)
📞 [open contact info](look above in the "contact info" section)
Київ, Україна | Full-time/Part-time | On-site/Hybrid/Remote
Посади: SOC L1-L2, Cyber Security Analyst, SysAdmin

ОСВІТА ТЕХНІЧНІ НАВИЧКИ ТА ДОСВІД З ІНСТРУМЕНТАМИ

КПІ ім. Ігоря Malware Analysis
Сікорського – Статичний та базовий динамічний аналіз (IDA, Ghidra, JADX, PE-bear, Frida,
Спеціальність: 125 - локальні та хмарні пісочниці)
Кібербезпека – Класифікація загроз і практичне застосування фреймворків MITRE ATT&CK
Ступінь: Бакалавр (Enterprise, Mobile) та Cyber Kill Chain
2022 – 2026 Scripting & Automation
Середній бал: 91 / 100 – Python, Bash
Додаткова освіта: Network Security & Vulnerability Assessment
– Nmap, Masscan, Burp Suite, mitmproxy, Nessus, OpenVAS, OWASP TOP 10
TryHackMe, Coursera,
Cisco, EY Cyber Bootcamp DFIR
– Моніторинг кінцевих пристроїв (Autoruns, Procmon, Sysmon, Syslog, журнали
МОВИ Elastic Defend, журнали Honeypot)
Ukrainian: Native – Цифрова криміналістика (Volatility, Autopsy)
English: Technical (B1) – Обробка індикаторів компрометації (WHOIS, Maltego, Shodan, MISP, розробка
YARA-правил)
ЗНАННЯ ПРОТОКОЛІВ Інше
TCP, UDP, ICMP, IPsec, – Аналіз даних (попередня обробка, статистичний аналіз, візуалізація)
TLS, DTLS, DNS, HTTP/S,
ОПЕРАЦІЙНІ СИСТЕМИ ОФІСНІ ІНСТРУМЕНТИ
SSH, NTP
Linux | Windows Microsoft Office | Google Workspace

ДОСВІД
ТОВ «ІССП СЕРВІС» - дипломний проєкт березень - травень 2026 р
Мережева стеганографія в протоколі NTP
– Дослідив версії протоколу NTP, його специфікації, застосування та поведінку полів, зосередившись на їх
призначенні та взаємозв'язках.
– Проаналізував трафік існуючих PoC з обмеженою кількістю технік прихованої комунікації за допомогою NTP
та визначив недоліки існуючих рішень/інструментів для виявлення аномалій: Suricata, Zeek, сигнатури від Fortinet.
– Реалізував 16 технік прихованої комунікації з використанням 12 полів NTP для C2, ексфільтрації даних і
резервного каналу зв'язку з низькою пропускною здатністю.
– Розробив і реалізував підхід до виявлення, що поєднує поведінковий (наприклад, односторонній трафік,
узгодженість часових міток, перемикання версій, порівняння значень деяких полів з легітимних .pcap),
статистичний (Shannon entropy, min/max, mean…) та протокольний (RFC 5905, RFC 8915, RFC 9109) аналіз.
Середовище: 3 local VMs: PDC Emulator - Windows Server 2022, domain-joined client - Windows 10 (NT5DS),
Ubuntu 20.04 - gateway.
Технології та інструменти: Wireshark, Zeek, Snort/Suricata, Python, VPN; Docker Compose deployment: ELK Stack,
Malcolm (AWS/GCP).

Similar candidates

All similar candidates

Candidates by city


Compare your requirements and salary with other companies' jobs: