resume Alexandru HeraExperience
Certificationshover a certification to see what it covers Management GSOMGIAC Security Operations Manager SOC strategy & designTeam leadership & developmentDetection program managementThreat-intel integrationSOC metrics & KPIsSOC maturity assessmentMITRE ATT&CK alignment Forensics & Incident Response GCFAGIAC Certified Forensic Analyst Enterprise incident responseThreat huntingWindows forensicsMemory forensicsTimeline & super-timelineAnti-forensics detectionVolatilityKAPEPlaso GCFRGIAC Cloud Forensics Responder Cloud incident responseMicrosoft 365 forensicsAzure / Entra IDAWS & GCP log analysisUnified Audit LogOAuth & identity abuseCloudTrail Offensive Security GRTPGIAC Red Team Professional Red-team engagement planningAdversary emulationActive Directory attacksC2 infrastructureLateral movement & persistenceDefense evasionCobalt StrikeBloodHound Foundations AWSAWS Certified Cloud Practitioner Cloud fundamentalsAWS core servicesShared-responsibility modelCost & billing SEC+CompTIA Security+ Network securityThreats & attacksCryptographyIdentity & accessRisk & compliance CCNACCNA Routing and Switching Routing & switchingNetwork fundamentalsIP addressingNetwork security Achievements
EducationComputing and IT (BSc)University of Derby · 2022 Network Engineering (AP)Danish Academy of Business and Technology · 2016 TrainingSANS LDR551Building and Leading Security Operations Centers SANS SEC565Red Team Operations and Adversary Emulation SkillsManagementSOC strategy & design · Team leadership & development · Detection program management · Threat-intel integration · SOC metrics & KPIs · SOC maturity assessment · MITRE ATT&CK alignment Forensics & Incident ResponseEnterprise incident response · Threat hunting · Windows forensics · Memory forensics · Timeline & super-timeline · Anti-forensics detection · Volatility · KAPE · Plaso · Cloud incident response · Microsoft 365 forensics · Azure / Entra ID · AWS & GCP log analysis · Unified Audit Log · OAuth & identity abuse · CloudTrail Offensive SecurityRed-team engagement planning · Adversary emulation · Active Directory attacks · C2 infrastructure · Lateral movement & persistence · Defense evasion · Cobalt Strike · BloodHound FoundationsCloud fundamentals · AWS core services · Shared-responsibility model · Cost & billing · Network security · Threats & attacks · Cryptography · Identity & access · Risk & compliance · Routing & switching · Network fundamentals · IP addressing |