Curriculum Vitae

Muhammad Fezzan

SOC Analyst

Available for opportunities
SentinelDefenderEntraKQLMITRE ATT&CK

Experience

CloudGuard AI

CloudGuard AI

SOC Analyst

June 2025 – Present
  • Managing the end-to-end investigation of security incidents within Microsoft Sentinel, from initial triage and evidence gathering to closure and remediation.
  • Developing and refining KQL analytics rules to improve alert fidelity and minimize false positives across multi-tenant environments.
  • Assisting in threat hunting exercises by utilizing EDR telemetry (Defender for Endpoint) and OSINT to identify indicators of compromise (IOCs).
  • Authoring technical incident summaries and operational reports, translating forensic findings into actionable steps for stakeholders.
  • Tuning and managing security policies for Entra ID and Defender for Endpoint based on technical audits and operational requirements.
TriageIncident ResponseThreat HuntingTuning
SystemOps

SystemOps

Lead R&D & Security Analyst

Aug 2024 – June 2025
  • Spearhead and manage e-commerce security initiatives ensuring secure, efficient execution
  • Partner with development teams to embed security protocols from project inception
  • Conduct ongoing code reviews to detect and resolve security vulnerabilities
  • Organise and lead workshops on secure coding practices for team-wide security awareness
  • Implement real-time threat detection tooling to reinforce system integrity
Threat DetectionCode ReviewAppSec
bITo Ltd

bITo Ltd

Student Worker

Feb 2022
  • Designed and produced a proof of concept addressing the Speed vs Urgency problem
  • Worked collaboratively across different team roles
  • Communicated and presented project outcomes to a panel at bITo Ltd
R&DPresentation

Education

Manchester Metropolitan University

Manchester Metropolitan University

Sep 2023 – Present

BSc Cyber Security

Oldham College

Oldham College

Sep 2021 – Jun 2023

Level 3 Hardware & Networking

DistinctionMeritMerit

Skills & Stack

SIEM & Analytics

  • Microsoft Sentinel
  • KQL Engineering
  • Analytics Rules
  • Watchlists
  • UEBA Analysis

Endpoint & Defense

  • Defender for Endpoint
  • Live Response
  • ASR Rules
  • Incident Forensics
  • Device Discovery

Identity & Cloud

  • Entra ID (Azure AD)
  • Conditional Access
  • App Governance
  • Identity Protection
  • MFA

Intelligence & Frameworks

  • MITRE ATT&CK Mapping
  • Indicator Lifecycle
  • TTP Attribution
  • Phishing Analysis
  • Evidence Custody

Automation & Logic

  • Python
  • Logic Apps (SOAR)
  • PowerShell
  • SQL
  • Microsoft Graph API

Certifications

Projects