Skip to main content
Istanbul, TürkiyeOpen to Fully Remote Opportunities

Cybersecurity Professional

Irfan Alkan

SOC Team Lead | Senior SOC Analyst | Incident Response | Security Operations

Cybersecurity professional with 4+ years of progressive Security Operations Center experience across incident investigation, SIEM/EDR analysis, detection improvement, and analyst mentoring.

Core Tooling & Operations

Hands-on experience with IBM QRadar, Splunk, CrowdStrike Falcon, Wireshark, Active Directory, Sysmon, Windows/Linux security telemetry, and incident response workflows.

Irfan Alkan - SOC Team Lead & Senior SOC Analyst

Profile Overview

About Me

Professional cybersecurity background combining deep hands-on investigative rigor with analyst training and technical leadership.

I am a cybersecurity professional with more than four years of progressive Security Operations Center experience, advancing from SOC Analyst Intern to SOC Analyst L1, SOC Analyst L2, and SOC Team Lead / Cybersecurity Instructor.

My work focuses on security monitoring, incident investigation, SIEM and EDR analysis, detection improvement, escalation support, technical reporting, and analyst mentoring.

I have investigated approximately 300 security alerts and incidents involving web attacks, malware, phishing, suspicious PowerShell activity, authentication attacks, ransomware, network scanning, privilege escalation, endpoint threats, and account compromise.

I combine hands-on technical Security Operations experience with leadership, training, investigation review, and workflow improvement.

I am particularly interested in fully remote SOC, Security Operations, Incident Response, Detection, and MDR opportunities open to candidates based in Türkiye.

Target Roles

SOC Team LeadSenior SOC AnalystSOC Analyst L2Security Operations AnalystIncident Response AnalystSecurity Operations EngineerDetection AnalystMDR Analyst
Work Model PreferenceFully Remote (Eligible for candidates based in Türkiye)
Location & TimezoneIstanbul, Türkiye (UTC+3)

Operational Scope

SOC Experience Metrics

Verifiable hands-on investigative volume, tool utilization, and mentoring experience across four years of Security Operations Center activities.

SOC Operations
300+

Security Alerts & Incidents Investigated

Triage, scope determination, and escalation across diverse attack vectors

SIEM Analysis
~200

IBM QRadar Offenses Investigated

AQL queries, offense triage, correlation tuning, and false-positive reduction

SIEM Analysis
~100

Splunk SPL Searches & Detection Queries

Event correlation, field extractions, log analysis, and custom dashboards

EDR / Endpoint
~70

CrowdStrike Falcon Detection Investigations

IOC investigation, endpoint containment support, and alert triage

EDR / Endpoint
~80

CrowdStrike Process-Tree Analyses

Deep execution lineage, parent-child process tracking, and anomaly detection

Network Security
~20

PCAP Packet Investigations

Wireshark packet-level analysis, protocol decoding, and flow inspection

Technical Leadership
~200

Cybersecurity Students & Analysts Trained / Mentored

Hands-on instruction in SOC procedures, SIEM/EDR, and investigation quality

Technical Leadership
~20

Training Cohorts Guided

Structured curriculum delivery in security monitoring and incident response

* Metrics reflect approximate non-additive investigation counts and hands-on operational activity. Symbols (~ and +) indicate conservative estimates.

Career Progression

Professional Experience

Progressive four-year Security Operations Center tenure advancing through foundational alert triage, advanced L2 incident escalations, and technical team leadership.

CYDEO

Contract

Istanbul, Türkiye / Remote

TenureMarch 2022 – Present

SOC Team Lead | Cybersecurity Instructor

Current Role

CYDEO • July 2025 – Present

  • Lead SOC investigation reviews and provide escalation support across active security incidents.
  • Guide analysts through rigorous alert triage, investigation, technical documentation, and escalation procedures.
  • Improve SOC workflows, ticket standard operating procedures, and overall investigation quality.
  • Train cybersecurity students and junior analysts in SOC operations, incident response, SIEM, EDR, network analysis, and technical reporting.
  • Develop and deliver hands-on training modules utilizing IBM QRadar, Splunk, CrowdStrike Falcon, Wireshark, Active Directory, Sysmon, and related security technologies.
Tools & Focus:IBM QRadarSplunkCrowdStrike FalconWiresharkSysmonActive DirectoryIncident Response

SOC Analyst L2 | Team Lead

CYDEO • July 2024 – June 2025

  • Performed advanced SOC investigations and handled L2 escalations for complex security alerts.
  • Investigated high-severity IBM QRadar offenses and Splunk alerts using targeted AQL and SPL queries.
  • Conducted correlation-rule tuning, false-positive analysis, custom dashboard creation, and log-source troubleshooting.
  • Investigated CrowdStrike Falcon endpoint detections via detailed process-tree and indicator of compromise (IOC) analysis.
  • Supported endpoint containment workflows and remediation coordination.
  • Guided junior analysts, provided technical escalation review, and maintained investigation quality standards.
Tools & Focus:IBM QRadar (AQL)Splunk (SPL)CrowdStrike FalconProcess TreesDetection TuningRemediation

SOC Analyst L1 | Cybersecurity Mentor

CYDEO • July 2022 – June 2024

  • Conducted initial alert triage and security-event investigations across multi-tenant environments.
  • Investigated web application attacks, malware infections, phishing campaigns, authentication anomalies, suspicious PowerShell execution, and suspicious network traffic.
  • Determined alert severity, impact scope, and formal escalation requirements.
  • Refined SOC ticketing workflows and standardized investigation documentation templates.
  • Mentored cybersecurity students and incoming junior analysts in foundational monitoring practices.
Tools & Focus:Alert TriagePhishing AnalysisPowerShell AnalysisMalware TriageSIEM MonitoringTicketing

SOC Analyst Intern

CYDEO • March 2022 – June 2022

  • Supported continuous SOC monitoring and incident-investigation support workflows.
  • Analyzed security alerts, Windows/Linux event logs, and baseline network telemetry.
  • Developed solid practical familiarity with core SOC processes, SIEM investigation steps, and professional technical documentation.
Tools & Focus:Log AnalysisNetwork BaselinesSIEM InvestigationDocumentationSecurity Operations

Core Competencies

Technical Skills & Tooling

Categorized operational competencies across SIEM systems, endpoint telemetry, incident investigation, and network analysis.

SIEM Platforms & Analysis

Core security information & event management with hands-on enterprise telemetry analysis.

IBM QRadar~200 offenses investigated
Splunk~100 SPL searches & queries
AQL (Ariel Query Language)
SPL (Search Processing Language)
Correlation Rules Tuning
Detection Tuning
Custom SOC Dashboards
Alert Investigation
Log Analysis
False-Positive Analysis
Log-Source Troubleshooting
11 competenciesOperational

EDR & Endpoint Security

Host-level telemetry, execution lineage tracking, and containment coordination.

CrowdStrike Falcon~70 detections investigated
Process-Tree Analysis~80 lineage reviews
IOC Investigation
Endpoint Containment Support
Remediation Support
Sysmon Telemetry
Windows Security Event Logs
7 competenciesOperational

Incident Response & Operations

End-to-end incident lifecycle from initial detection to closure reporting.

Alert Triage (~300 investigated)
Incident Investigation
Escalation Management
IOC Analysis
Threat Investigation
Root-Cause Analysis Support
Investigation Reporting
SOC Ticket Documentation
8 competenciesOperational

Network Security & Packet Analysis

Deep packet inspection, network telemetry decoding, and perimeter logging.

WiresharkStrong hands-on (~20 PCAPs)
PCAP Packet Analysis
TCP/IP Protocol Suite
DNS & HTTP/HTTPS Traffic
Nmap (Lab & Practical Exposure)
pfSense Firewall
Suricata (Log Analysis Exposure)
7 competenciesOperational

Systems & Infrastructure

Enterprise operating environments, directory services, and virtualization.

Microsoft Windows
Linux Administration
Active Directory
Kali Linux
Windows Server
VirtualBox
6 competenciesOperational

Detection & Threat Analysis

Behavioral analysis across common enterprise attack vectors and tactics.

MITRE ATT&CK (Practical Familiarity / Investigation Context)
Detection Engineering Concepts
Threat Hunting Concepts
Web Attack Analysis (~200 investigated)
Malware Triage (~40 investigated)
Phishing Analysis (~20 investigated)
Suspicious PowerShell Analysis (~20 investigated)
Authentication Attack Analysis (~10 investigated)
8 competenciesOperational

Security Framework Familiarity

Conceptual alignment with leading cybersecurity standards and control architectures.

NIST Cybersecurity Framework (Familiarity)
ISO/IEC 27001 (Familiarity)
2 competenciesOperational

Practical Implementations

Hands-On Projects & Labs

Hands-on detection environments, security instrumentation, and purpose-built study tools demonstrating practical operational capability.

Featured Lab Environment

SOC Home Lab

Designed and built a virtual Security Operations Center environment for attack simulation, telemetry collection, detection development, and incident investigation. This lab mirrors modern enterprise telemetry pipelines: adversarial simulations conducted from Kali Linux traverse a segmented pfSense firewall into a Windows Server Active Directory domain. Host and authentication activities are captured via fine-grained Sysmon configurations and ingested into Splunk for detection creation, SPL queries, and investigative triage.

Lab Telemetry & Attack Architecture Flow
Kali LinuxAttacker / Threat Emulation
pfSenseNetwork Boundary & Segmentation
Windows Server / ADTarget Domain & Host Activity
Sysmon AgentHigh-Fidelity Telemetry Logging
Splunk Universal ForwarderSIEM Ingestion & Indexing
Detection & InvestigationSPL Rules, Triage & Incident Analysis

Key Engineering Activities & Investigations

Adversarial attack simulation across network and endpoint boundaries
Windows Server and Active Directory enterprise telemetry generation
Custom Sysmon XML configuration for high-fidelity process and network logging
Splunk data ingestion, source typing, and index architecture
Development of custom SPL detection rules and correlation queries
Alert validation, false-positive elimination, and threshold tuning
Full incident triage, root-cause investigation, and documentation
Deep packet inspection and protocol analysis using Wireshark
Tech Stack:SplunkSysmonActive DirectoryWindows ServerpfSenseKali LinuxWiresharkVirtualBox
Production Study Application

Security+ Test Engine

An independent cybersecurity study application designed to provide structured exam practice and domain testing. Designed, engineered, and deployed independently across platforms, delivering intuitive question randomized quizzes, timed review modes, and detailed domain explanations.

Engineered with Flutter for high performance multi-platform consistency
Deployed on Firebase Hosting with fast global CDN distribution
Comprehensive database of ~1,107 structured practice questions
Engineered and deployed independently from architecture to release

Key Engineering Activities & Investigations

Engineered cross-platform interactive exam interface with randomized testing modes
Implemented domain-based performance tracking and score analytics
Automated build and continuous deployment to Firebase Hosting
Designed mobile-first responsive layout tailored for efficient technical revision
Tech Stack:FlutterFirebase HostingDartMulti-Platform (Web/Mobile)State Management
Independent Security+ study application. CompTIA and Security+ are trademarks of CompTIA. This project is an independent study tool and is not affiliated with or endorsed by CompTIA.

Instruction & Mentorship

Technical Leadership & Analyst Mentoring

Guiding analysts through real-world incident lifecycles, rigorous investigation methodologies, and practical SIEM/EDR workflows.

~200
Students & Analysts Mentored
~20
Training Cohorts Guided
4+
Years of Hands-on Operations

SOC Investigation Review & Quality Assurance

Reviewing analyst case files, alert triage quality, and technical investigation notes to maintain consistency and depth across alert lifecycles.

  • Structured alert triage and escalation evaluation
  • Evidence validation and root-cause analysis guidance
  • Standardizing technical reporting and ticket handoffs
  • Providing actionable feedback on investigation methodology

Hands-on Technical Instruction

Delivering practical, lab-based technical curriculum focused on modern SOC instrumentation and defensive tactics.

  • IBM QRadar offense triage and AQL queries
  • Splunk SPL event searches and correlation query building
  • CrowdStrike Falcon process-tree analysis and host triage
  • Wireshark packet capture and protocol anomaly identification
  • Web attack analysis (SQLi, XSS, Path Traversal, Brute Force)

L2 Escalation & Incident Mentoring

Directing analysts during critical escalation scenarios, bridging knowledge gaps from initial event detection to containment coordination.

  • Assisting junior analysts through complex multi-stage alerts
  • PowerShell obfuscation and authentication anomaly triage
  • Independent Security+ foundational knowledge mentoring
  • Incident documentation standards for executive and client reviews

Credentials & Validation

Certifications & Continuous Learning

Active credentials, validated simulation badges, and ongoing technical development in cybersecurity analysis.

Active CertificationRangeForce

Security Engineer 1 Elite

Issued Feb 2026 • Valid through Feb 2030

Hands-on, simulation-based technical credential validating advanced offensive-defensive skills, SIEM triage, malware analysis, network defense, and SOC incident resolution in realistic enterprise scenarios.

Hands-on SOC DefenseSIEM InvestigationMalware AnalysisNetwork Triage
Issued: February 2026 | Expires: February 2030
Historical Certification — Expired June 2025CompTIA

CompTIA Security+

Earned 2022 • Expired June 2025

Foundational baseline security certification covering network security principles, threat mitigation, identity access management, risk assessment, and operational security.

Core Security PrinciplesThreat IdentificationNetwork DefenseCryptography Baselines
Earned: 2022 | Expired: June 2025
In ProgressCompTIA

CompTIA CySA+

Currently In Preparation

Currently undertaking advanced study targeting behavioral cybersecurity analysis, vulnerability assessment, threat intelligence utilization, and continuous security monitoring.

Threat IntelligenceVulnerability ManagementBehavioral AnalysisIncident Response
Status: In Progress (Curriculum Study & Lab Practice)

Academic Background

Education

Foundational engineering and graduate analytical education supporting technical rigor and strategic problem-solving.

Master of Arts in International Relations

University of Oklahoma

Advanced graduate study emphasizing analytical methodology, geopolitical risk analysis, and strategic communication.

Bachelor's Degree in Electronics Engineering

Turkish Air Force Academy

Rigorous engineering foundation in signal processing, electronic systems, telecommunications, and digital logic.

Initiate Contact

Let's Connect

I am open to SOC, Security Operations, Incident Response, Detection, and MDR opportunities, with a strong preference for fully remote positions open to candidates based in Türkiye.

Direct Email

Reach out for role inquiries, technical interviews, or team discussions.

Curriculum Vitae

Download a comprehensive PDF copy of my technical cybersecurity resume.