resume

Alexandru Hera


Experience

  1. Security Operations Center Manager

    BeyondJul 2025 — Present

    • Lead the SOC service and set its strategic and operational direction.
    • Oversee SOC operations across log collection, threat detection, incident triage and response, reporting, quality assurance, and customer engagement.
    • Write and maintain the SOC's security policies, standards, and governance frameworks.
    • Mentor analysts and set development plans that grow the team's skills.
  2. Information Security Consultant

    MassMutual RomaniaAug 2020 — Jul 2025

    • Responded to incidents using digital forensics and incident response (DFIR) principles and tooling such as EDR, SIEM, PAM, DLP, and cloud services.
    • Documented and followed security operations processes, ran quality assurance, and mentored junior analysts.
    • Automated response actions and built workflows and playbooks to improve SOC capabilities.
    • Ran purple team exercises on the blue team alongside CrowdStrike, SpecterOps, and the internal offensive operations team.
    • Maintained technical relationships with partner teams such as Endpoint Engineering, IAM, Cloud Security, and Fraud.
  3. Senior SOC Analyst

    SecureWorksFeb 2019 — Jul 2020

    • Investigated low to medium-severity incidents from multiple sources, such as AV/EDR, network, and email.
    • Used indicators of compromise (IOCs) from internally produced cyber threat intelligence (CTI) reports to sweep the customer's environment.
    • Recommended improvements to playbooks and procedures.
  4. Monitoring Analyst

    BRD Groupe Société GénéraleJul 2017 — Feb 2019

    • Monitored the bank's critical infrastructure, responding to process warnings and escalating high to critical alerts.
    • Provided operational support to bank employees.

Certifications

hover a certification to see what it covers

Management

GSOMGIAC Security Operations Manager
SOC strategy & designTeam leadership & developmentDetection program managementThreat-intel integrationSOC metrics & KPIsSOC maturity assessmentMITRE ATT&CK alignment

Forensics & Incident Response

GCFAGIAC Certified Forensic Analyst
Enterprise incident responseThreat huntingWindows forensicsMemory forensicsTimeline & super-timelineAnti-forensics detectionVolatilityKAPEPlaso
GCFRGIAC Cloud Forensics Responder
Cloud incident responseMicrosoft 365 forensicsAzure / Entra IDAWS & GCP log analysisUnified Audit LogOAuth & identity abuseCloudTrail

Offensive Security

GRTPGIAC Red Team Professional
Red-team engagement planningAdversary emulationActive Directory attacksC2 infrastructureLateral movement & persistenceDefense evasionCobalt StrikeBloodHound

Foundations

AWSAWS Certified Cloud Practitioner
Cloud fundamentalsAWS core servicesShared-responsibility modelCost & billing
SEC+CompTIA Security+
Network securityThreats & attacksCryptographyIdentity & accessRisk & compliance
CCNACCNA Routing and Switching
Routing & switchingNetwork fundamentalsIP addressingNetwork security

Achievements

  • Google Cloud Security MSSP of the Year (EMEA)2026 Google Cloud Partner Award for Beyond's Google-centric agentic SOC.
  • GIAC Advisory BoardInvited membership for top-percentile performance across GIAC exams.

Education

Computing and IT (BSc)University of Derby · 2022
Network Engineering (AP)Danish Academy of Business and Technology · 2016

Training

SANS LDR551Building and Leading Security Operations Centers
SANS SEC565Red Team Operations and Adversary Emulation

Skills

ManagementSOC strategy & design · Team leadership & development · Detection program management · Threat-intel integration · SOC metrics & KPIs · SOC maturity assessment · MITRE ATT&CK alignment

Forensics & Incident ResponseEnterprise incident response · Threat hunting · Windows forensics · Memory forensics · Timeline & super-timeline · Anti-forensics detection · Volatility · KAPE · Plaso · Cloud incident response · Microsoft 365 forensics · Azure / Entra ID · AWS & GCP log analysis · Unified Audit Log · OAuth & identity abuse · CloudTrail

Offensive SecurityRed-team engagement planning · Adversary emulation · Active Directory attacks · C2 infrastructure · Lateral movement & persistence · Defense evasion · Cobalt Strike · BloodHound

FoundationsCloud fundamentals · AWS core services · Shared-responsibility model · Cost & billing · Network security · Threats & attacks · Cryptography · Identity & access · Risk & compliance · Routing & switching · Network fundamentals · IP addressing