Thanks to visit codestin.com
Credit goes to github.com

Skip to content
View sksahabuj's full-sized avatar

Block or report sksahabuj

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sksahabuj/readme.md

SK Sahabuj Zaman | Security Operations β†’ Cloud Security Engineering

Profile Views LinkedIn Email

9+ Years Security Operations | Transforming to Cloud Security Architecture


🎯 Current Mission

Transitioning from SOC Operations Leadership to Cloud Security Engineering through hands-on AWS security projects, automation, and modern detection engineering.

Current Focus:

  • ☁️ AWS Security Architecture (CloudTrail, GuardDuty, Security Hub, IAM)
  • 🐍 Security Automation with Python
  • πŸ” Detection Engineering & Threat Hunting
  • πŸ“Š SOAR & Security Orchestration
  • πŸ›‘οΈ Cloud Security Posture Management (CSPM)

πŸ’Ό Professional Background

Security Operations Expert @ Nokia (May 2023 - Present)

  • Leading 12-member SOC team across L1/L2/L3 operations
  • 9+ years experience in SIEM (Splunk ES, McAfee ESM)
  • Incident Response, Threat Hunting (MITRE ATT&CK-aligned)
  • Use-case development, custom dashboards, and MDR operations

Previous Experience:

  • Senior Specialist @ HCL Technologies
  • Associate SME Security @ MicroLand
  • Security Consultant @ Aujas Cybersecurity
  • Security Service Specialist @ IBM

Now Building: Cloud-native security engineering capabilities to architect secure cloud infrastructure at scale.


πŸš€ Active Projects

Building production-grade AWS security monitoring with CloudTrail, GuardDuty, and automated response workflows. Python-based automation for security posture management.

Collection of Python scripts for AWS security automation - IAM auditing, misconfiguration detection, compliance checking, and automated remediation.

High-fidelity detection rules in Sigma format for cloud environments. Covering AWS attack techniques, privilege escalation, and lateral movement detection.

Documenting my transition from traditional SOC to Cloud Security Engineering. Labs, lessons learned, and technical deep-dives for security professionals making the same journey.

Automated IR playbooks for cloud security incidents. Python-based orchestration for containment, investigation, and recovery in AWS environments.

πŸ› οΈ cloud-security-tools

Testing and documenting open-source cloud security tools. Practical guides for CSPM, CNAPP, and security automation platforms.


πŸ“œ Certifications

Current:

  • ISC2 Certified in Cybersecurity (CC)
  • Splunk Enterprise Certified Admin
  • Splunk Power User

πŸŽ“ Pursuing (2026):

  • AWS Certified Security - Specialty (Target: Q2 2026)
  • CISSP - Certified Information Systems Security Professional (Target: Q4 2026)

πŸ› οΈ Technical Stack

Cloud Platforms: AWS (Primary Focus), Azure (Learning)
SIEM & Security Tools: Splunk Enterprise Security, McAfee ESM, Darktrace, EDR platforms
Languages: Python (Security Automation - Learning), Bash, PowerShell
Frameworks: MITRE ATT&CK, CIS Benchmarks, NIST CSF
Cloud Security: CloudTrail, GuardDuty, Security Hub (Hands-on Labs)
Detection: Sigma Rules, SPL (Splunk), Use-case Development
Network Security: FortiGate UTM, Layer 3 Switching, McAfee EPO


πŸ“Š GitHub Activity

GitHub Stats

GitHub Streak

Top Languages


πŸ“ Recent Technical Writing

Coming Soon: Technical blog covering cloud security architecture, detection engineering, and lessons from the SOC to cloud security transition.


🎯 2026 Transformation Goals

  • πŸ”„ Build 6+ production-quality cloud security projects
  • πŸ”„ Earn AWS Security Specialty & CISSP certifications
  • πŸ”„ Launch technical blog with 20+ security engineering articles
  • πŸ”„ Master Python for security automation
  • πŸ”„ Transition to Cloud Security Architect/Engineering role (β‚Ή40-50 LPA)

πŸ† Professional Achievements

  • Customer Appreciation: Developed custom Splunk dashboard enabling timely audit completion and sustained 2 years of MDR operations with consistent SLA adherence
  • Zero Escalations: Maintained MDR operations with zero customer escalations, recognized by Nokia management
  • Team Leadership: Successfully led 12-member SOC team, improving MTTR through streamlined workflows
  • False Positive Reduction: Reduced alert noise by 40% through McAfee ESM fine-tuning at Apollo Munich

πŸ“« Let's Connect

I'm always interested in connecting with security professionals, especially those working in cloud security architecture and detection engineering.

  • πŸ’Ό LinkedIn: SK Sahabuj Zaman
  • πŸ“§ Email: [email protected]
  • 🌍 Location: Noida, India
  • πŸ’¬ Open to: Cloud Security roles, Security Engineering positions, Technical collaboration

"From SOC Operations to Cloud Security Engineering - Building in public, learning constantly, shipping daily."

Last Updated: February 2026

Pinned Loading

  1. aws-security-lab aws-security-lab Public

    1

  2. soc-to-cloud-security soc-to-cloud-security Public

    1

  3. security-automation-scripts security-automation-scripts Public

    1

  4. incident-response-playbooks incident-response-playbooks Public

    1

  5. threat-detection-rules threat-detection-rules Public

    1

  6. cloud-security-tools cloud-security-tools Public

    1