Сервіс пошуку роботи №1 в Україні
Артем
Фахівець з інформаційної безпеки
- Розглядає посади:
- Фахівець з інформаційної безпеки, аналітик, Cyber security specialist
- Вік:
- 22 роки
- Місто проживання:
- Ромни
- Готовий працювати:
- Дистанційно
Контактна інформація
Шукач вказав: Телефон
Прізвище, контакти та світлина доступні тільки для зареєстрованих роботодавців. Щоб отримати доступ до особистих даних кандидатів, увійдіть як роботодавець або зареєструйтеся.
Отримати контакти цього кандидата можна на сторінці https://www.work.ua/resumes/19446375/
Завантажений файл
Версія для швидкого
перегляду
Це резюме розміщено у вигляді файлу. Ця версія для швидкого перегляду може бути гіршою за оригінал резюме.
ARTEM KRYVTSUN
SOC Analyst | Blue Team | SIEM | Incident Investigation | Python
Žilina, Slovakia / Remote | Email: [відкрити контакти ](див. вище в блоці «контактна інформація») | GitHub Portfolio: https://github.com/jesuskaya/CSecurity | Telegram: @jesuskaya
PROFESSIONAL SUMMARY
Cybersecurity master's student and aspiring SOC Analyst with practical experience gained through independent projects, university cyber laboratories, TryHackMe training and a personal virtual lab. Hands-on exposure to Splunk, Elastic Stack, Wireshark, Nmap, Windows and Linux investigation, EDR/SOAR concepts, MITRE ATT&CK mapping and Python-based security tooling. Built an ML-powered anti-phishing mini-tool with a trainable classification model and developed a network anomaly-detection project. Seeking a Junior SOC Analyst / Security Monitoring position where I can contribute to security monitoring, incident investigation and continuous improvement of detection capabilities.
WORK EXPERIENCE
Cybersecurity Intern (University Internship)
Cyber Police Department
April 2025 – June 2025
• Assisted in the analysis of cybersecurity incidents and digital evidence.
• Reviewed Windows event logs and basic network traffic during investigations.
• Collected and documented technical information related to cybercrime cases.
• Performed open-source intelligence (OSINT) and information gathering.
• Assisted in identifying phishing websites, malicious domains, and suspicious IP addresses.
• Prepared technical documentation and incident reports.
• Worked under the supervision of senior cybercrime investigators.
SOC Analyst L1 | Genesis
February 2026 – July 2026
• Monitored and triaged security alerts across SIEM and EDR platforms, performing initial incident analysis and escalation for Tier 2/3 response.
• Investigated potential security incidents, analyzing malicious indicators of compromise (IoCs), network traffic anomalies, and endpoint telemetry.
• Contributed to the maintenance and tuning of detection rules and security monitoring dashboards to reduce false positives and improve alert fidelity.
• Collaborated with cross-functional IT and infrastructure teams to remediate identified vulnerabilities and contain active security threats.
• Documented incident response procedures, investigation findings, and ticket resolutions in accordance with internal SOC operational metrics and frameworks.
CYBERSECURITY PROJECTS
ML-Powered Anti-Phishing Mini-Tool | Python, Machine Learning
• Designed and developed a security-focused application for analysing suspicious messages and identifyingphishing indicators.
• Implemented a trainable machine-learning classification model and data-processing workflow for phishingdetection.
• Structured the project as a reusable mini-tool with clear input, analysis and result-generation stages.
• Published the project on GitHub with supporting code and documentation.
Network Traffic Anomaly Detection | Python, Isolation Forest
• Built a Python application to detect anomalous network traffic using an Isolation Forest model.
• Prepared and processed numeric and categorical traffic features with Pandas and scikit-learn.
• Added anomaly scoring and visualisation using Matplotlib; tested the tool with network-traffic datasets.
SIEM Investigation Labs | Splunk and Elastic Stack
• Imported and investigated VPN logs in Splunk; parsed JSON with spath and created SPL searches usingfiltering, stats, count and values.
• Used Kibana Discover and KQL to investigate authentication activity, filter events by time and identifysuspicious patterns.
• Created visualisations and an interactive VPN dashboard for failed-login analysis.
Network and Incident Investigation | Wireshark, Nmap, MITRE ATT&CK;
• Analysed PCAP traffic, DNS activity, TCP sessions and suspicious external IP addresses in laboratory scenarios.
• Performed network discovery and service enumeration in a controlled home-lab environment with Nmap.
• Mapped phishing and intrusion scenarios to MITRE ATT&CK; and Cyber Kill Chain stages; documented findings,IOCs and recommended actions.
CYBERSECURITY LABORATORY EXPERIENCE
• FlareVM malware-analysis environment: used a dedicated Windows-based analysis VM and security utilities for controlled investigation practice.
• Windows laboratories: practised system administration, Event Viewer and Windows event analysis, processes, network connections, persistence/autostart review and endpoint-investigation fundamentals.
• Linux and Ubuntu laboratories: practised command-line navigation, users and permissions, processes, networking, logs and basic administration in virtual machines.
• Virtual home lab: configured VMware/VirtualBox environments for Windows, Linux and Ubuntu; performed network scanning, packet capture, tool testing and security exercises.
CORE SKILLS
Security Operations
SIEM, alert triage, log analysis, incident investigation, IOC/TTP analysis, phishing analysis, detection engineering fundamentals
Frameworks & Concepts
MITRE ATT&CK;, Cyber Kill Chain, EDR, SOAR, Incident Response, threat detection, basic malware-analysis workflow
Tools & Platforms
Splunk, Elastic Stack/Kibana, Wireshark, Nmap, FlareVM,
Autoruns, VMware, VirtualBox, Git, GitHub
Systems & Networking
Windows, Linux, Ubuntu, Windows Event Logs, TCP/IP,
DNS, HTTP/HTTPS, DHCP, ICMP, ARP, basic Active
Directory and Azure concepts
Programming & Data
Python, Pandas, scikit-learn, Matplotlib, basic Bash, JSON log parsing, SPL and KQL fundamentals
Professional-soft Skills
Analytical thinking, attention to detail, documentation, structured escalation, continuous learning
TRAINING & CERTIFICATIONS
• CYBRIX Academy – Practical SOC & Cybersecurity Training covering networking, threats, SOC concepts, incident analysis and security tools.
• Hillel Python Basic – Full Course of study (Certificate)
• Hillel Python Professional – Full Course of study (Certificate)
• TryHackMe: SIEM, Splunk Basics, Elastic Stack: The Basics, Introduction to EDR, SOAR, Detection Engineering(Introduction) and other SOC-oriented labs.
• Additional study: MITRE ATT&CK;, Cyber Kill Chain, Windows/Linux fundamentals, networking protocols, phishing, malware, ransomware and Active Directory basics.
• ISC2 Certified in Cybersecurity (CC) - in progress.
EDUCATION
National Technical University "Kharkiv Polytechnic Institute" (NTU "KhPI")
Master's Degree in Cybersecurity – In Progress
5th-year university student; Bachelor's Degree in Cybersecurity completed.
LANGUAGES
Ukrainian: Native | Russian: Native | English: B2 (working proficiency, actively improving)
SOC Analyst | Blue Team | SIEM | Incident Investigation | Python
Žilina, Slovakia / Remote | Email: [
PROFESSIONAL SUMMARY
Cybersecurity master's student and aspiring SOC Analyst with practical experience gained through independent projects, university cyber laboratories, TryHackMe training and a personal virtual lab. Hands-on exposure to Splunk, Elastic Stack, Wireshark, Nmap, Windows and Linux investigation, EDR/SOAR concepts, MITRE ATT&CK mapping and Python-based security tooling. Built an ML-powered anti-phishing mini-tool with a trainable classification model and developed a network anomaly-detection project. Seeking a Junior SOC Analyst / Security Monitoring position where I can contribute to security monitoring, incident investigation and continuous improvement of detection capabilities.
WORK EXPERIENCE
Cybersecurity Intern (University Internship)
Cyber Police Department
April 2025 – June 2025
• Assisted in the analysis of cybersecurity incidents and digital evidence.
• Reviewed Windows event logs and basic network traffic during investigations.
• Collected and documented technical information related to cybercrime cases.
• Performed open-source intelligence (OSINT) and information gathering.
• Assisted in identifying phishing websites, malicious domains, and suspicious IP addresses.
• Prepared technical documentation and incident reports.
• Worked under the supervision of senior cybercrime investigators.
SOC Analyst L1 | Genesis
February 2026 – July 2026
• Monitored and triaged security alerts across SIEM and EDR platforms, performing initial incident analysis and escalation for Tier 2/3 response.
• Investigated potential security incidents, analyzing malicious indicators of compromise (IoCs), network traffic anomalies, and endpoint telemetry.
• Contributed to the maintenance and tuning of detection rules and security monitoring dashboards to reduce false positives and improve alert fidelity.
• Collaborated with cross-functional IT and infrastructure teams to remediate identified vulnerabilities and contain active security threats.
• Documented incident response procedures, investigation findings, and ticket resolutions in accordance with internal SOC operational metrics and frameworks.
CYBERSECURITY PROJECTS
ML-Powered Anti-Phishing Mini-Tool | Python, Machine Learning
• Designed and developed a security-focused application for analysing suspicious messages and identifyingphishing indicators.
• Implemented a trainable machine-learning classification model and data-processing workflow for phishingdetection.
• Structured the project as a reusable mini-tool with clear input, analysis and result-generation stages.
• Published the project on GitHub with supporting code and documentation.
Network Traffic Anomaly Detection | Python, Isolation Forest
• Built a Python application to detect anomalous network traffic using an Isolation Forest model.
• Prepared and processed numeric and categorical traffic features with Pandas and scikit-learn.
• Added anomaly scoring and visualisation using Matplotlib; tested the tool with network-traffic datasets.
SIEM Investigation Labs | Splunk and Elastic Stack
• Imported and investigated VPN logs in Splunk; parsed JSON with spath and created SPL searches usingfiltering, stats, count and values.
• Used Kibana Discover and KQL to investigate authentication activity, filter events by time and identifysuspicious patterns.
• Created visualisations and an interactive VPN dashboard for failed-login analysis.
Network and Incident Investigation | Wireshark, Nmap, MITRE ATT&CK;
• Analysed PCAP traffic, DNS activity, TCP sessions and suspicious external IP addresses in laboratory scenarios.
• Performed network discovery and service enumeration in a controlled home-lab environment with Nmap.
• Mapped phishing and intrusion scenarios to MITRE ATT&CK; and Cyber Kill Chain stages; documented findings,IOCs and recommended actions.
CYBERSECURITY LABORATORY EXPERIENCE
• FlareVM malware-analysis environment: used a dedicated Windows-based analysis VM and security utilities for controlled investigation practice.
• Windows laboratories: practised system administration, Event Viewer and Windows event analysis, processes, network connections, persistence/autostart review and endpoint-investigation fundamentals.
• Linux and Ubuntu laboratories: practised command-line navigation, users and permissions, processes, networking, logs and basic administration in virtual machines.
• Virtual home lab: configured VMware/VirtualBox environments for Windows, Linux and Ubuntu; performed network scanning, packet capture, tool testing and security exercises.
CORE SKILLS
Security Operations
SIEM, alert triage, log analysis, incident investigation, IOC/TTP analysis, phishing analysis, detection engineering fundamentals
Frameworks & Concepts
MITRE ATT&CK;, Cyber Kill Chain, EDR, SOAR, Incident Response, threat detection, basic malware-analysis workflow
Tools & Platforms
Splunk, Elastic Stack/Kibana, Wireshark, Nmap, FlareVM,
Autoruns, VMware, VirtualBox, Git, GitHub
Systems & Networking
Windows, Linux, Ubuntu, Windows Event Logs, TCP/IP,
DNS, HTTP/HTTPS, DHCP, ICMP, ARP, basic Active
Directory and Azure concepts
Programming & Data
Python, Pandas, scikit-learn, Matplotlib, basic Bash, JSON log parsing, SPL and KQL fundamentals
Professional-soft Skills
Analytical thinking, attention to detail, documentation, structured escalation, continuous learning
TRAINING & CERTIFICATIONS
• CYBRIX Academy – Practical SOC & Cybersecurity Training covering networking, threats, SOC concepts, incident analysis and security tools.
• Hillel Python Basic – Full Course of study (Certificate)
• Hillel Python Professional – Full Course of study (Certificate)
• TryHackMe: SIEM, Splunk Basics, Elastic Stack: The Basics, Introduction to EDR, SOAR, Detection Engineering(Introduction) and other SOC-oriented labs.
• Additional study: MITRE ATT&CK;, Cyber Kill Chain, Windows/Linux fundamentals, networking protocols, phishing, malware, ransomware and Active Directory basics.
• ISC2 Certified in Cybersecurity (CC) - in progress.
EDUCATION
National Technical University "Kharkiv Polytechnic Institute" (NTU "KhPI")
Master's Degree in Cybersecurity – In Progress
5th-year university student; Bachelor's Degree in Cybersecurity completed.
LANGUAGES
Ukrainian: Native | Russian: Native | English: B2 (working proficiency, actively improving)
Інші резюме цього кандидата
Схожі кандидати
-
Фахівець з інформаційної безпеки
Дистанційно, Київ, Одеса -
Фахівець з інформаційної безпеки
25000 грн, Дистанційно -
Спеціаліст з інформаційної безпеки
Дистанційно, Одеса, Інші країни -
Фахівець з інформаційної безпеки
Дистанційно, Київ -
Information security analyst
Дистанційно, Київ, Біла Церква -
Фахівець з інформаційної безпеки
Дистанційно, Київ , ще 2 міста