About

Ciaran Byrne

I am a SOC Analyst Level 3 with a background in offensive security, digital forensics, networking, software development, and security infrastructure. This site documents the work behind that experience: what I built or investigated, how I approached it, what the evidence showed, and where the work stopped.

Background

From networking and ethical hacking into security operations

I first became interested in cyber security through networking classes and home labs in Glasgow. I completed an HNC in Cyber Security and Networking at City of Glasgow College before studying Ethical Hacking at Abertay University. During my degree, I also spent two semesters at Champlain College in the United States, studying digital forensics, system administration, threat hunting, and application security.

My work has never stayed within one part of security. I have built networks, written C++ and Python tooling, analysed malware and forensic evidence, assessed applications, and developed a complete cyber-range environment for my honours project. I now use that wider technical background in security operations, where an alert has to become an investigation, a decision, a containment action, or an escalation.

Progression

Education and technical development

  1. SOC Analyst Level 3, NatWest Group

    Enterprise incident investigation and threat hunting using Splunk, Microsoft Defender for Endpoint, Carbon Black, and supporting security platforms. The role includes complex escalations, endpoint analysis, containment, and helping L1 and L2 analysts progress investigations they cannot resolve.

  2. Study Abroad, Champlain College

    Two semesters covering digital forensics, network forensics, threat hunting, system administration, information assurance, and web application security.

  3. BSc (Hons) Ethical Hacking, Abertay University

    Offensive and defensive security, malware analysis, digital forensics, secure programming, IoT development, networking, and an individual honours project focused on competitive cyber-security training.

  4. HNC Cyber Security and Networking, City of Glasgow College

    The networking, systems administration, and security foundations that I later built on throughout university and professional work.

Approach

Attack, defence, and the system around them

I tend to think about security in terms of strategy: what each side can see, what each side can reach, and how one move changes the options available to the other. A defensive control changes how an attacker has to move, while an offensive technique exposes where the design, visibility, or assumptions have failed.

I do not see attack and defence as separate areas. They are different parts of the same system. That is why my work moves between offensive security, incident investigation, forensics, networking, and engineering. I want to understand what is being protected, how it could be reached, what evidence an action would leave behind, and which change would actually make the system harder to compromise.