Experience
Kuveyt Türk Participation Bank
2022 – PresentRegulated bank, 10,000+ endpoints
- Senior Cybersecurity AnalystJun 2024 – Present
- Cybersecurity AnalystJun 2022 – Jun 2024
- Investigated memory, disk and network artefacts to uncover activity and misconfigurations missed by existing detections, coordinating remediation with security and system-owner teams
- Managed threat intelligence and attack surface management from vendor evaluation to daily operations, completing 4 proof-of-concept cycles across these areas and digital forensics
- Designed and facilitated 4 incident response tabletop exercises in 2025–2026, including a macOS scenario for subsidiary IT teams, documenting detection gaps and procedural improvements
- Triaged 800–1,750 assigned alerts monthly and investigated high-severity incidents through closure
- Mentored new analysts to independently triage and investigate alerts using response playbooks
Logsign
2020 – 2022SIEM/SOAR vendor and managed SOC
- SOC Tier 2 AnalystJun 2021 – May 2022
- SOC Tier 1 Analyst and Shift Team LeaderJan 2021 – Jun 2021
- SOC Tier 1 AnalystFeb 2020 – Jan 2021
- Co-led detection tuning that cut daily alerts by approximately 90% (60,000 to 5,000–6,000) for an enterprise customer through duplicate suppression and correlation threshold refinement, maintaining detection coverage
- Led 3–4 analysts and handled L2 escalations for 4 round-the-clock shift teams serving approximately 20 enterprise tenants, managing schedules, workloads and analysis quality
- Built response playbooks by alert type and standardised customer notification templates across the SOC
Publications and open source
Reconstructed 129 days of on-chain command-and-control rotation history for a macOS campaign, and documented an unreported delivery vector using compromised legitimate sites and 3 unpublished indicators.
etherhiding-tools
Sep 2026
Scripts for reading C2 addresses and rotation history out of EtherHiding smart contracts.
Certifications
Skills
Security
- Incident response
- Threat hunting
- Detection engineering
- MITRE ATT&CK
Tools
- Splunk
- Cortex XSOAR
- Cortex XDR
- Carbon Black EDR
- Vectra NDR
- PowerShell
Forensics
- Volatility
- Autopsy
- FTK
- Wireshark
- REMnux
- Windows internals
- macOS incident analysis
Education
Namık Kemal University · B.Sc. in Electronics and Communication Engineering
2015 – 2019
Languages
- Turkish Native
- English Professional working proficiency (TOEFL iBT 89/120)
- Spanish B1