Curriculum vitae

Ciaran Byrne

SOC Analyst Level 3

SOC Analyst Level 3 with experience across enterprise incident investigation, threat hunting, DFIR support, malware-analysis workflows, and security-event triage. My main experience is with endpoint and SIEM telemetry, Microsoft Defender, Splunk, Carbon Black, digital forensics, reverse engineering, evidence-led reporting, and containment. My offensive background includes controlled malware development, exploit validation, network pivoting, web application assessment, Active Directory attack paths, and cyber-range design.

Experience

SOC Analyst Level 3

NatWest Group

  • Led the investigation of user-reported suspicious endpoint activity, identifying unrecognised archive downloads and Microsoft Defender telemetry that had not surfaced through the standard SOC alert queue.
  • Contained the potential compromise through endpoint isolation, account disablement, and credential-reset actions. I extracted hashes, IP addresses, and domains for estate-wide scoping, briefed First Response, and produced the evidence handover supporting a device rebuild.
  • Worked with threat intelligence teams, peer financial institutions, and national cyber-security partners to monitor geopolitical threats and hostile-state activity targeting the UK financial sector, translating intelligence into hunting and monitoring priorities.
  • Responded to a large-scale Layer 7 DDoS and SMS-pumping campaign, correlating application, network, geographic, and telecommunications indicators to identify malicious infrastructure and abuse patterns.
  • Supported targeted IP blocking, geoblocking, and telephone-number controls during the campaign while investigating associated account activity and potential insider involvement.
  • Conducted proactive threat hunts following bug-bounty disclosures, translating web-application findings into searches for exploitation indicators, suspicious requests, and post-compromise behaviour.
  • Trained and supported L1 and L2 analysts across endpoint analysis, telemetry correlation, containment, case progression, and response-team handover.

Call Handler

NHS 24

  • Coordinated urgent responses across patients, nurses, specialist clinicians, GP out-of-hours services, and the Scottish Ambulance Service for complex and potentially life-threatening presentations.
  • Used adaptive communication and rapid problem-solving to assess patients with severe communication difficulties, establish their identity and location, and provide accurate information for emergency dispatch.
  • Managed highly distressed patients and families through traumatic and end-of-life situations, balancing emotional support, clinical requirements, patient dignity, and timely escalation.
  • Supported service continuity during a national clinical-system outage, conducting technical checks, escalating the failure, and agreeing an emergency referral process with senior nursing staff and ambulance dispatch.
  • Produced clear case records and clinical handovers, allowing multiple healthcare teams to continue care without unnecessary delay or repeated assessment.

Security Technician

The Leahy Center for Digital Investigation

  • Performed purple-team-style detection validation with SOC analysts, testing whether security rules reliably identified the adversary TTPs they were designed to detect.
  • Created exploit proofs of concept and controlled malware samples to detonate against SIEM and endpoint controls, measuring alert coverage and investigative visibility.
  • Identified false negatives and detection gaps, then worked with analysts to refine rule logic, telemetry sources, alert context, and triage effectiveness.
  • Built and deployed Elastic Stack SIEM environments for security monitoring, adversary simulation, detection engineering, and investigation.

Selected work

Education

BSc (Hons) Ethical Hacking

Abertay University

Classification: 2:1. The degree covered penetration testing, red teaming, exploit development, malware analysis, digital forensics, secure programming, networking, IoT security, and system internals.

Dissertation: King of the Forest - Cybersecurity Training Environment.

Exchange Year in Cyber Security

Champlain College

Digital forensics, operating-system forensics, network forensics, threat hunting, system administration, information assurance, and web application security.

GPA: 4.08/4.50.

HNC Cyber Security and Networking

City of Glasgow College

Networking, operating systems, systems administration, and the technical foundations I later built on throughout university and professional work.

Professional development

Certifications

Offensive Security Certified Professional
In progress
Hack The Box Certified Penetration Testing Specialist
In progress

Additional experience

  • Securi-Tay speaker: Delivered a technical talk on command-and-control frameworks and attacker tradecraft.
  • NECCDC: Achieved second place defending enterprise-style infrastructure against a professional red team.
  • TryHackMe contributor: Created and supported the development of cyber-security challenge rooms.

Technical profile

Offensive security and adversary simulation
Internal network assessment, routed pivoting, web application testing, exploit proofs of concept, Windows payload development, process injection, Metasploit, Burp Suite, Chisel, sshuttle, and Nmap.
Security operations and incident response
Splunk, Microsoft Defender XDR, Microsoft Defender for Endpoint, Carbon Black, ServiceNow, FireEye, security-event triage, incident investigation, endpoint containment, and response handover.
Digital forensics
Wireshark, Zeek/Bro, CyberChef, FTK Imager, Volatility, Elastic Stack, evidence handling, PCAP analysis, and endpoint and network artefact analysis.
Malware analysis and reverse engineering
Ghidra, IDA, x64dbg, REMnux, PEStudio, CAPA, executable analysis, decompilation, suspicious execution behaviour, and payload obfuscation.
Threat hunting and intelligence
KQL, Sigma, MITRE ATT&CK, IOC and TTP enrichment, infrastructure analysis, alert investigation, proactive hunting, and detection refinement.
Cloud and infrastructure
AWS, CloudTrail, GuardDuty, Docker, Linux, Windows, Active Directory, networking, and containerised environments.
Programming and tooling
Python, C++, C#, Java, Flask, SQLAlchemy, SQLite, scripting, automation, and backend service development.
Frameworks and security principles
OWASP, NIST, ISO 27001 principles, CWE, secure coding, evidence-led reporting, and technical remediation.