Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Thank you. Your report has been submitted and will be reviewed shortly.
Faisal Alshamrani, Cybersecurity Specialist

Faisal Alshamrani

Cybersecurity Specialist·RMG

Saudi Arabia

Bachelor's degree, Computer Science

Work experience

Total years of experience: 2 years, 0 months

Cybersecurity Specialist

July 2025 - Present

RMG

Arar, Saudi Arabia

July 2025 - Present

• Worked in a shift-based 24x7 SOC environment; closed over 900 SIEM alerts daily.
• Performed daily malware scans across the entire network using Kaspersky Endpoint Security.
• Investigated Kerberoasting alerts using PowerShell, SPN enumeration, and event log analysis.
• Blocked malicious IPs through F5 WAF iRules and enforced perimeter defences.
• Detected and responded to host compromises involving DLL injection, persistence, and beaconing.
• Created YARA rules and carried out endpoint containment including isolation, credential resets, and system wipes.
• Performed forensic analysis of compromised hosts, including memory dump analysis Volatility, and Windows artifact
correlation (Prefetch, Amcache, SRUM, Shimcache, JumpLists, registry hives) to validate execution timelines and
persistence.
• Implemented SIEM use cases to detect PowerShell activity.

Company industry:
Cyber & Network Security
Job role:
Information Technology

Cybersecurity Analyst Trainee

July 2024 - December 2024

SAMA

Riyadh, Saudi Arabia

July 2024 - December 2024

• Detected unauthorized persistence by auditing registry run keys, startup folders, and Winlogon settings with PowerShell,
revealing suspicious entries linked to malicious startup behaviour.
• Analysed a memory dump with Volatility to detect .NET-based malware infection on a suspected endpoint; extracted
malware artifacts and confirmed in-memory execution behaviour.
• Investigated APT activity across an enterprise Splunk SIEM by analysing multiple indexes and threat intel; mapped attacker
movement across the kill chain and identified compromise indicators including initial access, lateral movement, and
persistence.
• Hunted for specific MITRE ATT&CK techniques (T1099, T1055, T1021, etc.) using ELK stack, including timestomping,
Meterpreter migration, and credential harvesting; successfully identified multiple TTPs and correlated them with attacker
activity timelines.
• Validated sender authenticity by reviewing HTTP and email headers (SPF, DKIM, DMARC), and inspected user-agent, host,
referrer, and URI paths in HTTP traffic, resulting in the detection of phishing attempts, unauthorized access, and data
exfiltration over DNS and HTTP(S).
• Investigated web-based malware delivery using EnCase and browser artifact parsers, traced Quasar RAT infection to
Chrome browsing activity, and confirmed payload download via HTTP.
• Analysed suspicious executables with EnCase, inspecting metadata, compile times, and hash values to identify malware
disguised as legitimate binaries (e.g., client-built.exe).
• Mapped execution of manually deployed malware using WinPrefetchView and EnCase, confirmed METSVC.EXE execution
by the user, and verified its persistence via scheduled tasks.
• Investigated anomalies involving TCP/IP traffic, DNS tunnelling, and unauthorized port scanning attempts.

Company industry:
Banking

Cybersecurity SOC Officer

January 2024 - July 2024

SIJIL

Riyadh, Saudi Arabia

January 2024 - July 2024

• Worked in a shift-based SOC environment with 24x7 alert monitoring responsibilities.
• Utilised ECC, DCC, and SAMA CSF controls to verify compliance, including vulnerability patching, user management, and
overall cyber security posture.
• Blocked over 15 instances of external scanning on the perimeter firewall.
• Investigated and triaged 50+ security incidents by analysing EDR alerts, Windows Event Logs, DNS records, and firewall
logs; escalated valid threats to seniors per playbook.
• Prioritised vulnerability scans using Qualys VMDR, resulting in the monthly remediation of over 10 critical vulnerabilities.
• Designed and delivered the 2024/25 cyber security awareness programme for the entire organisation, including awareness
emails, posters, quizzes, and phishing simulations to assess effectiveness.
• Developed, deployed, and demonstrated threat intelligence platforms (OpenCTI and MISP) to address a gap identified in
the GRC assessment.
• Independently verified and responded to SAMA threat intelligence reports by scanning the environment for artefacts and
correlating findings with OSINT sources.
• Maintained incident records using Jira; documented alert context, actions taken, and escalation notes in compliance with
SOC operating procedures.

Company industry:
Financial Services
Job role:
Information Technology

Education

Brunel University London

April 2023

April 2023

Bachelor's degree, Computer Science

United Kingdom

GPA (point): 3.50 out of 4

GPA (point): 3.50 out of 4

Skills

Threat Hunting

Expert

Governance

Expert

Cyber Security

Expert

Computer Forensics

Expert

Incident Analysis

Expert

ARTIFICIAL INTELLIGENCE

Intermediate

COMPUTER SCIENCE

Intermediate

CYBER SECURITY

Intermediate

CYBER THREAT HUNTING

Intermediate

ENDPOINT DETECTION AND RESPONSE

Intermediate

GOVERNANCE RISK MANAGEMENT AND COMPLIANCE

Intermediate

INTERNAL INVESTIGATIONS

Intermediate

QUALYS

Intermediate

SECURITY INFORMATION AND EVENT MANAGEMENT SIEM

Intermediate

WIRESHARK

Intermediate

Information Security

Intermediate

IT Security

Intermediate

ISO 27001

Expert

Network Security

Intermediate

Information Security Management

Intermediate

Vulnerability Assessment

Intermediate

Languages

Arabic

Native Speaker

English

Native Speaker

Training and Certifications

Certifications
GCTI
Dec 2024 - Dec 2028
GSOC
Nov 2024 - Nov 2028
Security+
Nov 2024 - Nov 2027
CEH
Nov 2024 - Dec 2026
eCTHP
Feb 2025