SECURITY OPERATIONS ENGINEER

Be Obsessed
or Be Normal.

Blue-team operations, threat detection and incident response across enterprise environments. I design and operationalise the controls that keep critical infrastructure defensible — and hold up when someone actually tries.

Yousef Fallaha
LOCATION
Aleppo · UTC+3
FOCUS
SOC operations & IR
STACK
Microsoft E5 / Azure
STATUS
Open to work
01PROOF3 ROLES · 10 CERTIFICATIONS
4+
YEARS BLUE TEAM
30++
TOOLS OPERATED
10
CERTIFICATIONS

From frontline SOC analyst to leading a multi-tenant SOC — incident response, security engineering, and the data-protection controls underneath both. The discipline predates the career: national-level triathlon, still officiating.

Feb 2023 — Feb 2026
3 YRS
Cyber Security Analyst
DefendLab
Remote · UAE
Feb 2026 — May 2026
4 MOS
Security Operations Engineer
VCG Markets
Remote · UAE
May 2026 — Present
5 MOS
SOC Lead
Omarino IT Services
Remote · Germany
CERTIFICATIONSVERIFY ALL →
02SELECTED WORKALL ENGAGEMENTS →
001
LEADERSHIP
Running A Multi-Tenant SOC

SOC operations and security engineering across a multi-tenant MSSP portfolio — setting the strategy and running the execution behind threat detection, cyber defence and incident response.

Microsoft SentinelDefender XDRJiraConfluence
002
ENGINEERING
Security Architecture & Engineering

End-to-end deployment and configuration of the Microsoft E5 Security Stack across Azure — endpoints, identities, cloud and email brought under one coverage model.

Defender for EndpointDefender for IdentityDefender for Cloud AppsAzure
003
GOVERNANCE
Data Protection, Risk & Reporting

DLP policies and Insider Risk workflows that stop unauthorised exfiltration across cloud and endpoint channels — and the ISO 27001 risk register, audit-readiness documentation and executive reporting that sit above them.

Purview DLPInsider RiskISO 27001
004
RESPONSE
Incident Response Lifecycle

Initial alert triage through containment, eradication and post-incident documentation, run across Sentinel and Defender XDR.

Microsoft SentinelDefender XDR
03WRITINGNOTHING PUBLISHED
ARCHIVE
Nothing published yet

Notes on SOC operations and incident response, in English and Arabic. The first pieces are being written — the archive opens when there is something in it worth reading.

Tell me when it’s live
04CONTACTALEPPO · UTC+3

Currently leading a SOC.
Open to the next hard problem.

Hiring for a blue-team role, weighing an MSSP, or stuck on a detection that will not stop firing — all three are worth an email.

ELSEWHERE
OPEN TO ROLES
contact@yousef-fallaha.com
Write to me
WORKINGRemote · Aleppo
NOWSOC Lead, Omarino IT Services