Skip to main content

Overview

Introduction

Hello! I'm Muhammad Rafay Ali, a Cyber Security Engineer with 2+ years of hands-on experience in SOC operations, SIEM engineering, threat detection, incident response, and security hardening. Deployed and tuned security platforms across multi-server enterprise environments, cutting undetected threat windows by 35% and false positive rates by 45%.

I specialize in SOC Operations, SIEM Engineering, and Threat Detection & Response, with expertise in ISO 27001, NCA-ECC, CIS Benchmarks, and MITRE ATT&CK frameworks.

Actively sharpening offensive and defensive skills through TryHackMe and continuous lab-based research, translating attack techniques into practical detection and response strategies. Certified in ISO/IEC 27001 Lead Auditor, ISC2 CC, SOC Foundations, and Google Cybersecurity Professional programs. Seeking to deliver managed security excellence in SOC/MSSP environments.

"Let's collaborate to bring your secure infrastructure to life!"

Work Experience

Cyber Security Engineer

Encbit

Jul 2025 - Present Lahore | Hybrid
  • Managed Wazuh SIEM deployments across 5+ client environments, authoring 15+ custom detection rules and decoders that improved log ingestion accuracy by 30% across 50+ monitored assets.
  • Conducted OSINT-driven attack surface analysis using Google Dorking, WHOIS, and Shodan identifying and coordinating remediation for 10+ exposed assets while triaging 200+ daily security events.
  • Maintained continuous offensive/defensive research through TryHackMe labs and MITRE ATT&CK-grounded techniques, directly informing real-world detection engineering decisions.

Cyber Security Analyst

Cyber Silo

Feb 2025 - Jul 2025 Islamabad | Hybrid
  • Engineered custom SIEM detection rules and log parsers on Wazuh and Threat Hawk, increasing detection fidelity by 40% while resolving agent misconfigurations to restore 99% log integrity.
  • Automated compliance mapping workflows by correlating ISO 27001, NCA-ECC, and SAMA controls via Python scripting, cutting manual alignment effort by 60% and building CIS hardening templates for FortiGate, Cisco, and pfSense firewalls.
  • Validated threat detection coverage by simulating 20+ MITRE ATT&CK scenarios via Atomic Red Team, verifying rule accuracy and identifying critical coverage gaps across monitored infrastructure.

SOC Analyst

Cyber Silo (Client: Allama Iqbal Open University)

Feb 2024 - Feb 2025 Islamabad | Hybrid
  • Spearheaded SIEM deployment across 30+ servers and endpoints, managing Wazuh EDR with MITRE ATT&CK-mapped rules to close 35% of previously unmonitored attack surfaces.
  • Reduced false positives by 45% through systematic rule optimization and threat intelligence alignment, while performing real-time IOC analysis, log correlation, and root cause analysis across all telemetry sources.
  • Designed incident response playbooks for containment, remediation, and escalation workflows cutting MTTR from 30+ minutes to under 10 minutes across the monitored environment.

Academic Background

Hamdard University

BS Computer Science

2019 - 2023
Hamdard University Islamabad
Merit Scholarship Recipient for maintaining a top-tier GPA across consecutive semesters
Top 3 finish in multiple university CTF competitions
Co-founded the cybersecurity awareness society, ran workshops for 100+ students

Key Courses

Cyber & Information Security
Network Security
Artificial Intelligence
Machine Learning
Mobile App Development
Software Engineering
Database Management Systems
Data Structures & Algorithms

Technical Skills

SIEM & SOC

Threat Detection & Response

Wazuh
Wazuh
IBM QRadar
IBM QRadar
Threat Hawk
Threat Hawk
Microsoft Sentinel
Microsoft Sentinel
Threat Intelligence
Threat Intelligence
IOCs
IOC Analysis
Hunting
Threat Hunting

Offensive Security

VAPT & Exploitation

Kali Linux
Kali Linux
Burp Suite
Burp Suite
Metasploit
Metasploit
MITRE ATT&CK
MITRE ATT&CK
OSINT
OSINT
Nmap
Nmap

OS & Cloud

Infrastructure & Hardening

Windows
Windows Security
Linux
Linux Hardening
Azure
Azure Cloud
Active Directory
Active Directory
VMware
VMware

Governance

GRC & Standards

ISO 27001
ISO 27001
NCA-ECC
NCA-ECC
SAMA CSF
SAMA
ADHICS
ADHICS

Security Ops

IR & Engineering

Incident Response
Incident Response
Incident Documentation
Incident Documentation
Rule Parsing
Rule Parsing
Alert Tuning
Alert Tuning
API Integration
API Integration

Automation

Scripting & DevOps

Python
Python
Bash
Bash
PowerShell
PowerShell
Docker
Docker
GitHub
GitHub
Node.js
Node.js
Vercel
Vercel

Featured Projects

Scroll to explore

Active Directory Attack Simulation & Hardening

security

Emulated post-exploitation techniques in a Windows AD lab using Atomic Red Team, Mimikatz, and PowerShell. Integrated Wazuh SIEM to detect 20+ MITRE-mapped TTPs and performed CIS-based hardening, achieving 80% compliance improvement.

#Active Directory#Kali Linux#Wazuh#Mimikatz#Atomic Red Team+2

ThreatHawk SIEM Deployment & Custom Detection Engineering

security

Deployed ThreatHawk and Wazuh SIEM across multi-vendor enterprise environments. Built 30+ custom detection rules and log parsers for Huawei routers, WatchGuard firewalls, TrendMicro EDR, CrowdStrike, and spyware/grayware events. Reduced false positives by 45% through systematic rule tuning.

#ThreatHawk#Wazuh#Huawei#WatchGuard#TrendMicro EDR+3
Work in Progress

GCC Compliance Mapping Automation

security

Built a compliance mapping framework with Python scripts that cross-reference ISO 27001 controls against NCA ECC, SAMA CSF, ADHICS, PDPL, UAE IA, and Bahrain NCSC. Scripts auto-detect existing ISO controls in rules and append matched regional framework controls from a master spreadsheet, cutting manual mapping effort by 60%.

#ISO 27001#NCA ECC#SAMA CSF#ADHICS#PDPL+4
Work in Progress

NoxShield SIEM

security

Full-featured security operations dashboard with live Wazuh API integration, geolocation attack maps, MITRE ATT&CK visualization, and compliance tracking (PCI-DSS, HIPAA, NIST). Backed by SQLite with auto-refreshing data pipelines.

#Next.js#TypeScript#Wazuh API#Recharts#SQLite+2

Rafu Portfolio

development

A cybersecurity-themed portfolio featuring GSAP animations, 3D skills globe, interactive hacking terminal, and custom target cursor. Built with Next.js and deployed on Vercel with optimized OG previews.

#Next.js#TypeScript#GSAP#Tailwind CSS#Three.js+1

Multi-Sensor Intrusion Detection IoT

development

IoT security solution using ESP32, motion/gas/fire sensors, and ESP32-CAM. Engineered a Flutter + Firebase mobile app for real-time alerts, improving response time by 60%.

#IoT#ESP32#ESP32-CAM#Flutter#Dart+2

Impact Insights

Numbers from real SOC deployments and security engineering work

45%
False Positive Reduction
Systematic rule tuning across SIEM platforms
35%
Threat Coverage Gained
Closed unmonitored attack surfaces with custom rules
30+
Custom Detection Rules
Built for Wazuh, ThreatHawk, and QRadar
<10 min
Incident MTTR
Down from 30+ min with structured playbooks
60%
Faster Compliance Mapping
Automated ISO 27001 to NCA/SAMA correlation
200+
Daily Events Triaged
Real-time monitoring across enterprise environments

Password Auditor

Strength ScoreWeak (0%)

Password analysis checks against Have I Been Pwned database (11+ billion breached passwords).

Security Checklist

At least 12 characters
Contains Uppercase
Contains Number
Contains Special Char
Not in breach database

Interactive Terminal

Try commands like help, whoami, or skills

guest@rafay-portfolio:~
Welcome to Rafay's Portfolio Terminal. Type 'help' to begin.
guest@rafay-portfolio:~$

Get In Touch

Let's Connect

I'm open to discussing SOC operations, SIEM engineering opportunities, and security consultation.

GitHubLinkedInInstagram

© 2026 Muhammad Rafay Ali. All rights reserved.