Security Operations · Incident Response · Identity Security
Radman
Tahsildoust
Security Analyst with hands-on SOC experience investigating phishing, suspicious sign-ins, endpoint detections, and identity threats using Microsoft Defender XDR, Red Canary, and Entra ID.
About
From healthcare discipline to cybersecurity operations.
I am a Security Analyst with hands-on experience supporting Security Operations Center investigations across email, identity, and endpoint security. I use Microsoft Defender XDR, Microsoft Defender for Office 365, Red Canary, Microsoft Entra ID, and KQL to analyze telemetry, validate alerts, and support containment and remediation.
My background in healthcare operations strengthened my attention to privacy, regulated data, and operational accuracy. I bring that discipline to phishing investigations, suspicious sign-in analysis, endpoint remediation, threat validation, and incident documentation while continuing to deepen my skills in incident response, detection engineering, and cloud security.
Professional Experience
Hands-on security operations and incident investigation experience.
Libra Solutions Group
Security Analyst Intern
Support Security Operations Center activities by investigating security alerts, analyzing endpoint and identity telemetry, and assisting with incident response across multiple client environments.
- Investigate phishing, endpoint, and identity-related security alerts.
- Analyze Microsoft Entra ID authentication logs to validate suspicious sign-ins and identity-based threats.
- Triage endpoint detections using Microsoft Defender XDR and Red Canary.
- Use Kusto Query Language in Microsoft Defender XDR to investigate alerts, correlate security events, and validate findings.
- Support containment through session revocation, password-reset coordination, and endpoint remediation.
- Differentiate legitimate administrative activity from potentially malicious behavior through log analysis and threat validation.
- Document investigation findings and communicate remediation recommendations to internal teams.
Walmart
Pharmacy Technician
Support high-volume pharmacy operations, resolve insurance issues, maintain accurate records, and protect sensitive patient information under HIPAA requirements.
Walgreens
Pharmacy Technician
Processed prescriptions, supported pharmacists, handled insurance billing, and maintained strict patient confidentiality.
Fossil Group
Sales Associate
Exceeded sales goals and earned Employee of the Month recognition twice.
SECURITY OPERATIONS EXPERIENCE
Real-World SOC Investigations
These case studies are based on real security investigations completed during my Security Operations Center internship. They demonstrate my approach to incident triage, threat analysis, investigation, containment, and remediation using Microsoft Defender XDR, Red Canary, and Microsoft Entra ID. Client-specific information has been removed or anonymized.
Phishing Campaign Investigation
Investigated a campaign affecting multiple mailboxes to determine delivery scope, user interaction, potential account impact, and required containment.
Investigation
Reviewed email telemetry, correlated related alerts, validated whether links or attachments were accessed, and checked identity activity for suspicious authentication following delivery.
Response
Supported malicious-message removal, session revocation, credential remediation, and verification of completed actions before closure.
Skills demonstrated
Email security, scope analysis, identity validation, incident response, evidence-based closure.
Suspicious Sign-in Investigation
Analyzed unusual geographic and authentication activity to distinguish possible account compromise from legitimate travel, VPN egress, or failed access attempts.
Investigation
Reviewed sign-in location, device, authentication status, MFA results, session context, and surrounding activity to assess whether the event represented malicious access.
Response
Supported session revocation and password-reset workflows when risk could not be safely excluded, then coordinated account restoration after remediation.
Skills demonstrated
Identity telemetry analysis, false-positive validation, account containment, risk-based decision-making.
Potentially Unwanted Application Remediation
Investigated recurring software-updater and browser detections, traced associated endpoint activity, and supported complete removal and validation.
Investigation
Reviewed endpoint timelines, process relationships, persistence indicators, installed software, scheduled tasks, and registry evidence to establish scope.
Response
Supported application removal, endpoint restriction and isolation workflows, artifact cleanup, malware scanning, and post-remediation verification.
Skills demonstrated
Endpoint triage, process analysis, remediation coordination, persistence review, validation.
Credential-Access Detection Analysis
Reviewed recurring credential-access detections to determine whether they represented malicious behavior or approved administrative and migration activity.
Investigation
Examined alert context, affected endpoint activity, process lineage, related administrative actions, and available internal validation to determine intent.
Response
Documented the supporting evidence and closed detections as validated legitimate activity only after confirmation and review found no additional threat indicators.
Skills demonstrated
Alert triage, contextual analysis, false-positive determination, documentation, escalation judgment.
Technical toolkit
Security operations supported by cloud, systems, and data skills.
Security Operations
Microsoft Defender XDR, Microsoft Defender for Office 365, Red Canary, alert triage, phishing analysis, incident response, threat validation, and MITRE ATT&CK.
Identity & Response
Microsoft Entra ID, sign-in logs, MFA analysis, suspicious-location validation, session revocation, credential remediation, and account recovery workflows.
Linux & Systems
Linux dual boot, command line, SSH, Windows troubleshooting, PowerShell, endpoint timelines, process analysis, isolation, scanning, and remediation.
Cloud & Networking
AWS EC2 and IAM, GCP, firewalls, load balancers, health checks, multi-zone deployment, and cloud networking.
Programming & Data
Kusto Query Language (KQL), Python, Pandas, Matplotlib, JavaScript, SQL, PostgreSQL, pgAdmin, and data visualization.
Database Design
ER diagrams, normalization, primary and foreign keys, joins, aggregations, subqueries, and relational schema design.
Selected projects
Academic and personal work built around practical problem-solving.
Multi-zone cloud deployment
Built and troubleshot a team cloud environment using virtual machines, IAM, SSH, firewall rules, health checks, load balancing, and multi-zone routing.
Library catalog analysis
Used object-oriented Python, Pandas, Matplotlib, and Google Colab to analyze a structured dataset and create multiple visualizations.
Relational schema and SQL
Designed normalized schemas and ER diagrams and wrote advanced PostgreSQL queries using joins, aggregations, and subqueries.
SIEM platform evaluation
Compared security platforms by cost, scalability, detection capabilities, operational fit, and suitability for a growing SOC.
Cyber Lab
Hands-on practice beyond the classroom.
$ whoami
Security analyst building deeper skills across Linux, cloud, and defensive operations.
$ ls labs/
hack-the-box linux-dual-boot powershell cloud-networking
$ status
Continuous learning active.
Hack The Box
Enumeration, Linux navigation, vulnerability analysis, privilege-escalation concepts, and security problem-solving.
Linux Dual Boot
Configured and used a Windows/Linux dual-boot environment for command-line practice and system troubleshooting.
PowerShell Practice
Used PowerShell and endpoint tools to investigate files, support remediation, and improve Windows administration skills.
Career journey
A deliberate move from healthcare operations into cybersecurity.
Privacy, accuracy, and regulated workflows.
Scientific reasoning and analytical discipline.
Cybersecurity, cloud, databases, and Python.
Linux dual boot, Hack The Box, and PowerShell.
Threat triage, identity response, and endpoint investigation.
Education
Academic foundation in technology, cybersecurity, and science.
M.S. Information Technology & Management
University of Texas at Dallas — Cybersecurity focus.
Cybersecurity fundamentals, Python programming, cloud computing, database foundations, and healthcare systems.
B.A. Biology, Minor in Chemistry
University of North Texas.
Contact
Open to full-time cybersecurity opportunities.
I am targeting Security Analyst, SOC Analyst, Incident Response, Identity Security, and cloud-security roles.