Open to full-time cybersecurity roles

Security Operations · Incident Response · Identity Security

Radman
Tahsildoust

Security Analyst with hands-on SOC experience investigating phishing, suspicious sign-ins, endpoint detections, and identity threats using Microsoft Defender XDR, Red Canary, and Entra ID.

Professional headshot of Radman Tahsildoust
Based inTexas
Current focusSOC Operations
Core toolsDefender XDR · Red Canary · Entra ID
SOCSecurity operations focus
4Core portfolio projects
10+Security & cloud tools
1Security operations internship
2027Expected M.S. graduation

About

From healthcare discipline to cybersecurity operations.

I am a Security Analyst with hands-on experience supporting Security Operations Center investigations across email, identity, and endpoint security. I use Microsoft Defender XDR, Microsoft Defender for Office 365, Red Canary, Microsoft Entra ID, and KQL to analyze telemetry, validate alerts, and support containment and remediation.

My background in healthcare operations strengthened my attention to privacy, regulated data, and operational accuracy. I bring that discipline to phishing investigations, suspicious sign-in analysis, endpoint remediation, threat validation, and incident documentation while continuing to deepen my skills in incident response, detection engineering, and cloud security.

Professional Experience

Hands-on security operations and incident investigation experience.

2021—Present

Walmart

Pharmacy Technician

Support high-volume pharmacy operations, resolve insurance issues, maintain accurate records, and protect sensitive patient information under HIPAA requirements.

2017—2021

Walgreens

Pharmacy Technician

Processed prescriptions, supported pharmacists, handled insurance billing, and maintained strict patient confidentiality.

2019—2020

Fossil Group

Sales Associate

Exceeded sales goals and earned Employee of the Month recognition twice.

SECURITY OPERATIONS EXPERIENCE

Real-World SOC Investigations

These case studies are based on real security investigations completed during my Security Operations Center internship. They demonstrate my approach to incident triage, threat analysis, investigation, containment, and remediation using Microsoft Defender XDR, Red Canary, and Microsoft Entra ID. Client-specific information has been removed or anonymized.

Case 01Email Security

Phishing Campaign Investigation

Investigated a campaign affecting multiple mailboxes to determine delivery scope, user interaction, potential account impact, and required containment.

Defender XDRDefender for Office 365Entra IDKQL
Case 02Identity Security

Suspicious Sign-in Investigation

Analyzed unusual geographic and authentication activity to distinguish possible account compromise from legitimate travel, VPN egress, or failed access attempts.

Microsoft Entra IDDefender XDRSign-in LogsMFA
Case 03Endpoint Security

Potentially Unwanted Application Remediation

Investigated recurring software-updater and browser detections, traced associated endpoint activity, and supported complete removal and validation.

Defender XDRRed CanaryKQLWindows
Case 04Threat Validation

Credential-Access Detection Analysis

Reviewed recurring credential-access detections to determine whether they represented malicious behavior or approved administrative and migration activity.

Red CanaryDefender XDRProcess AnalysisThreat Validation

Technical toolkit

Security operations supported by cloud, systems, and data skills.

01

Security Operations

Microsoft Defender XDR, Microsoft Defender for Office 365, Red Canary, alert triage, phishing analysis, incident response, threat validation, and MITRE ATT&CK.

02

Identity & Response

Microsoft Entra ID, sign-in logs, MFA analysis, suspicious-location validation, session revocation, credential remediation, and account recovery workflows.

03

Linux & Systems

Linux dual boot, command line, SSH, Windows troubleshooting, PowerShell, endpoint timelines, process analysis, isolation, scanning, and remediation.

04

Cloud & Networking

AWS EC2 and IAM, GCP, firewalls, load balancers, health checks, multi-zone deployment, and cloud networking.

05

Programming & Data

Kusto Query Language (KQL), Python, Pandas, Matplotlib, JavaScript, SQL, PostgreSQL, pgAdmin, and data visualization.

06

Database Design

ER diagrams, normalization, primary and foreign keys, joins, aggregations, subqueries, and relational schema design.

Selected projects

Academic and personal work built around practical problem-solving.

Data AnalysisPython

Library catalog analysis

Used object-oriented Python, Pandas, Matplotlib, and Google Colab to analyze a structured dataset and create multiple visualizations.

Database DesignPostgreSQL

Relational schema and SQL

Designed normalized schemas and ER diagrams and wrote advanced PostgreSQL queries using joins, aggregations, and subqueries.

Security ResearchSIEM

SIEM platform evaluation

Compared security platforms by cost, scalability, detection capabilities, operational fit, and suitability for a growing SOC.

Cyber Lab

Hands-on practice beyond the classroom.

radman@lab:~

$ whoami

Security analyst building deeper skills across Linux, cloud, and defensive operations.

$ ls labs/

hack-the-box  linux-dual-boot  powershell  cloud-networking

$ status

Continuous learning active.

Hack The Box

Enumeration, Linux navigation, vulnerability analysis, privilege-escalation concepts, and security problem-solving.

Linux Dual Boot

Configured and used a Windows/Linux dual-boot environment for command-line practice and system troubleshooting.

PowerShell Practice

Used PowerShell and endpoint tools to investigate files, support remediation, and improve Windows administration skills.

Career journey

A deliberate move from healthcare operations into cybersecurity.

01Healthcare operations

Privacy, accuracy, and regulated workflows.

02B.A. Biology

Scientific reasoning and analytical discipline.

03M.S. ITM

Cybersecurity, cloud, databases, and Python.

04Hands-on labs

Linux dual boot, Hack The Box, and PowerShell.

05Security Analyst

Threat triage, identity response, and endpoint investigation.

Education

Academic foundation in technology, cybersecurity, and science.

Expected 2027

M.S. Information Technology & Management

University of Texas at Dallas — Cybersecurity focus.

Cybersecurity fundamentals, Python programming, cloud computing, database foundations, and healthcare systems.

2024

B.A. Biology, Minor in Chemistry

University of North Texas.

Contact

Open to full-time cybersecurity opportunities.

I am targeting Security Analyst, SOC Analyst, Incident Response, Identity Security, and cloud-security roles.