• Файл

Олександр

Cybersecurity Analyst

Вік:
19 років
Місто проживання:
Харків
Готовий працювати:
Київ

Контактна інформація

Шукач вказав: ТелефонЕл. пошту

Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.

Завантажений файл

Версія для швидкого перегляду

Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.

Oleksandr 01 // EXPERIENCE

Synolyts SOC L1 Analyst — IT Specialist Apr 2026 — Jul 2026

CYBERSECURITY ANALYST Continuous monitoring and analysis of information security events within a managed
// Pentest · OSINT · AI Security SOC environment. Detection and triage of anomalies in network traffic, system and
Research application logs. Incident intake, classification, and escalation in accordance with
established playbooks; responding to low- and medium-complexity incidents. Conducting
initial threat analysis and preparing findings for Tier 2/3 escalation. IoC extraction,
TEL [відкрити контакти](див. вище в блоці «контактна інформація») enrichment, and sharing via MISP; cross-referencing threat intelligence feeds to identify
MAIL [відкрити контакти](див. вище в блоці «контактна інформація») known malicious indicators in network and endpoint telemetry.
LI LinkedIn
HTB Hack The Box Prepared and delivered daily shift handover notes, weekly threat summaries, and
monthly security status reports for client-facing and internal stakeholders. Contributed to
LOC Kyiv, Ukraine
quarterly review documentation covering incident trends, SLA compliance, and recurring
// SKILLS anomaly patterns. Maintained up-to-date incident logs, violation registers, and escalation
records in accordance with SOC operational procedures.
WEB & NETWORK

Network Architecture OSI / TCP-IP Stack Participating in the development and update of security documentation, including SOC
instructions and infrastructure diagrams.
Protocol Behaviour
STACK QRadar SIEM · QRadar SOAR · Wazuh · Check Point XDR · CheckPoint NDR ·
CheckPoint SmartConsole 81.10/82 · Imperva WAF · FortiDDoS · Fortiweb · Fidelis Network ·
Port & Service Mapping Traffic Analysis
Fidelis Endpoint · Carbon Black (Broadcom) · CrowdStrike Falcon EDR · Rapid7 InsightVM ·
Microsoft Defender for Endpoint · Radware DefensePro · Zabbix · UptimeRobot · Symantec DLP ·
Packet Inspection Symantec Messaging Gateway · MISP · VMware · VDI · Omnitracker · SharePoint · MS Teams ·
Jira · GitLab
PENETRATION TESTING
Penetration Tester — Commercial & Personal Nov 2025 — Present
Burp Suite Professional Caido
Practice
Kali Linux OWASP WSTG Conducted commercial web application penetration tests across Black Box, Gray Box,
and White Box engagement types following OWASP WSTG methodology. Performed
NIST SP 800-115 PTES OSSTMM
manual vulnerability research and exploitation across the full WSTG test case catalogue.
Findings mapped to MITRE ATT&CK TTPs and scored using CVSS.
Black / Gray / White Box

Completed PortSwigger Web Security Academy — hands-on practical training across all
SOC & THREAT DETECTION
major web vulnerability classes using Burp Suite Professional.
QRadar SIEM QRadar SOAR Wazuh
Active practice on Hack The Box platform; participated in HTB CTF Season 10 "Season
Check Point XDR CheckPoint NDR
of the Underground" (Jan–May 2026), achieving Silver Tier rank (#5190 of 12,294
players).
CheckPoint SmartConsole Imperva WAF

FortiDDoS Fortiweb Produced structured pentest reports with executive summaries, per-finding technical
breakdowns, reproduction steps, impact assessments, and prioritized remediation
Carbon Black (Broadcom) roadmaps for both technical and non-technical audiences.

STACK Burp Suite Professional · Caido · Kali Linux
CrowdStrike Falcon EDR

Microsoft Defender for Endpoint
GRC Assistant — Personal Practice Sep 2025 — Nov 2025

Assisted in conducting information security audits aligned with GDPR and NIS2
Fidelis Network Fidelis Endpoint compliance requirements. Participated in risk identification and assessment processes,
contributing to the development of risk registers and mitigation plans. Supported the
Rapid7 InsightVM Radware DefensePro drafting and review of information security policies, procedures, and control
documentation.
Symantec DLP

Gained practical exposure to audit methodology, gap analysis against regulatory
Symantec Messaging Gateway
frameworks, and the documentation lifecycle for IS management systems (ISMS).
Elasticsearch Kibana Zabbix Assisted in preparing compliance reports and coordinating remediation tracking across
internal teams.
UptimeRobot
Familiar with Ukrainian information security legislation framework (Laws on Information
Protection, Cybersecurity, Personal Data, State Secrecy) and their application in
compliance contexts.

02 // PROJECTS & INDEPENDENT PRACTICE
THREAT INTELLIGENCE

MITRE ATT&CK MISP IOC Analysis
OSINT Analyst — Personal Practice Feb 2022 — Present

Cyber Kill Chain Diamond Model Conducted multi-disciplinary intelligence collection and analysis across OSINT, GEOINT,
SOCMINT, and HUMINT vectors. Tracked and attributed entities, infrastructure, and
VirusTotal AbuseIPDB events through persistent open-source monitoring — with continuous operational
engagement during Russia's full-scale invasion of Ukraine since February 2022.
OSINT & GEOINT
GEOINT: satellite imagery analysis via Sentinel Hub, Google Earth Pro, and Planet Labs;
SpiderFoot Shodan Censys
terrain correlation, damage assessment, and equipment identification from geolocated
Recon-ng theHarvester FOCA media. SOCMINT: deep social network mapping using SpiderFoot and custom graph
analysis; Telegram OSINT via TGStat and Telegago for channel/group monitoring, actor
ExifTool Gephi Sentinel Hub network mapping, and tracking information operations; dark web monitoring via Ahmia
and OnionSearch. HUMINT-adjacent: source credibility assessment, deception detection,
Planet Labs Google Earth Pro and cross-validation of human-reported intelligence against technical indicators.

Wayback Machine Bellingcat Toolkit
Applied structured analytic techniques (SATs) including ACH, link analysis, and timeline
Mitaka IntelTechniques TGStat
reconstruction. Threat actor profiling using MITRE ATT&CK for attribution and TTP
mapping. Applied Bellingcat verification methodology for geolocation confirmation,
Telegago Hunchly Ahmia chronolocation, and open-source evidence validation.

OnionSearch OSINT Framework Produced written intelligence reports summarizing findings, source reliability
assessments, and analytic confidence levels. Documented entity profiles, link analysis
INTEL DISCIPLINES diagrams, and timeline reconstructions in structured formats for further review or handoff.
OSINT GEOINT SOCMINT STACK SpiderFoot · theHarvester · Recon-ng · Shodan · Censys · FOCA · ExifTool · Gephi ·
Sentinel Hub · Google Earth Pro · Wayback Machine · MISP · Hunchly · Mitaka · IntelTechniques ·
HUMINT ACH / SATs Link Analysis OSINT Framework · Bellingcat Toolkit · TGStat · Telegago · Ahmia · OnionSearch

Threat Profiling Bellingcat Verification Qwen3.5-4B-Safety-Thinking 2026
Merlin Research · HuggingFace
COMPLIANCE & GRC Contributed to the development of a 4B-parameter safety-aligned language model with
GDPR NIS2 Risk Management reasoning capabilities. Optimized for structured reasoning quality, instruction adherence,
and robustness against adversarial inputs. Training pipeline leveraged LoRA-based
Security Audits Supervised Fine-Tuning with native <think> reasoning format, using Anthropic's
Bloom&Petri framework for behavioral alignment.
PROGRAMMING
TAGS AI Safety · LLM Fine-tuning · LoRA / SFT · Alignment · Reasoning · Qwen3.5
Python C Java Bash
03 // CERTIFICATIONS
Script-based Automation

PoC Development CS Junior Cybersecurity Analyst Career Path
Cisco · Verify
TOOLS & OFFICE
EH Ethical Hacker
MS Office Google Workspace Cisco · Verify

Excel Analytics VSCode KeePass IC Introduction to Cybersecurity
Cisco · Verify
SharePoint Jira GitLab
OI Open-source Intelligence (OSINT)
Basel Institute on Governance · February 2026
// LANGUAGES

Ukrainian — Native HTB Certified Penetration Testing Specialist IN PROGRESS
Hack The Box
Russian — Fluent

English — B1
04 // EDUCATION
// SOFT SKILLS
B.Sc. Cybersecurity — 3rd Year Student
Critical & Analytical Thinking · Communication ·
V. N. Karazin Kharkiv National University · 2024 — Present · Expected graduation 2028
Emotional Intelligence · Problem Solving · Time
Management · Stress Resistance · Digital
Literacy · Self-learning

Схожі кандидати

Усі схожі кандидати


Порівняйте свої вимоги та зарплату з вакансіями інших підприємств: