Submitting more applications increases your chances of landing a job.

Here’s how busy the average job seeker was last month:

Opportunities viewed

Applications submitted

Keep exploring and applying to maximize your chances!

Looking for employers with a proven track record of hiring women?

Click here to explore opportunities now!
We Value Your Feedback

You are invited to participate in a survey designed to help researchers understand how best to match workers to the types of jobs they are searching for

Would You Be Likely to Participate?

If selected, we will contact you via email with further instructions and details about your participation.

You will receive a $7 payout for answering the survey.


User unblocked successfully
Hamza Aslam, Network & Security Engineer (GRC)

Hamza Aslam

Network & Security Engineer (GRC)·Kloud 7

Saudi Arabia

Bachelor's degree, Information Technology

Work experience

Total years of experience: 2 years, 7 months

Network & Security Engineer (GRC)

August 2024 - January 2026

Kloud 7

Alabama, United States Remote

August 2024 - January 2026

• Assisted in developing security governance documentation, including Acceptable Use, Password, and Access Control policies across
multiple client environments, supporting consistent policy enforcement.
• Supported incident response documentation aligned with NIST SP 800-61r3, helping define structured response procedures and
improving incident response readiness.
• Performed risk assessments across client environments, identifying security gaps and documenting risks in risk registers with risk matrix
evaluation and mitigation tracking.
• Conducted NIST CSF 2.0 gap analysis to assess security controls, supporting remediation recommendations and documenting findings to
improve compliance posture.
• Supported ISO/IEC 27001 compliance and audit activities, assisting in control validation for regulatory audit requirements in alignment with
British Council IELTS compliance for MCG Technologies.
• Assisted in implementing endpoint security controls such as removable media restrictions and access control enforcement, contributing to
up to 20% reduction in policy violations and improved compliance adherence.
• Supported Business Continuity Plan (BCP) documentation by contributing to recovery procedures and continuity planning activities,
including defined recovery objectives (RTO: 15 minutes).
• Delivered 6+ security awareness training sessions to 40+ employees on phishing, password hygiene, physical security, and acceptable use
policies, improving user security awareness and compliance behavior.
• Remediated 20, 000+ vulnerabilities through patching, system hardening, and configuration management, reducing organizational risk
exposure and ensuring alignment with security baseline requirements.

Company industry:
IT Services

SOC Analyst | Network & Security Engineer

January 2024 - January 2026

Kloud 7

Alabaster, United States

January 2024 - January 2026

• Remediated 20, 000+ vulnerabilities across multiple client environments, reducing attack surface and improving overall security posture.
• Implemented patch management and system hardening in collaboration with cross-functional teams, consistently meeting SLA targets.
• Triaged 10-30 daily alerts using Splunk SIEM and SentinelOne EDR in a 24/7 SOC environment.
• Reduced false positives by 25% through SIEM tuning and improved alert analysis.
• Developed and tuned Splunk queries (SPL) to detect phishing, DDoS and brute-force attacks.
• Investigated 25+ confirmed security incidents with SOC L2 team, performing containment and root cause analysis.
• Mapped threats to MITRE ATT&CK framework to enhance detection accuracy and alert context.
• Supported end-to-end incident response, including detection, investigation, containment, and reporting.
• Analyzed system logs and network traffic to identify threats and vulnerabilities across multiple environments.
• Developed and improved incident response playbooks aligned with NIST CSF 2.0 and SP 800-61.
• Strengthened security controls in alignment with NIST and ISO 27001 standards.
• Documented incidents and vulnerabilities to support audits, compliance, and continuous improvement.

Company industry:
IT Services

Cybersecurity Intern

June 2023 - November 2023

Cyber Reconnaissance and Combat Center

Islamabad, Pakistan Hybrid

June 2023 - November 2023

Security product development, security services, and training lab
• Applied Python for automation, including web scraping and data collection to support security research and analysis tasks.
• Developed understanding of the cyber kill chain and how adversaries exploit system and network weaknesses.

Company industry:
Cyber & Network Security

Education

Bahria University

December 2024

December 2024

Bachelor's degree, Information Technology

Pakistan

Bahria University

December 2024

December 2024

High school or equivalent, InformationTechnology

Pakistan

GPA (point): 4 out of 5

GPA (point): 4 out of 5

OPF Boys College Islamabad

September 2020

September 2020

High school or equivalent, Computer Science

Pakistan

Pakistan International School Jeddah

July 2018

July 2018

High school or equivalent, Matriculation

Saudi Arabia

Pakistan International School Jeddah - PISJ AZIZIA

March 2018

March 2018

High school or equivalent, Matriculation

Saudi Arabia

Skills

OPERATIONS
Intermediate
OPERATIONS
Intermediate
PATCH MANAGEMENT
Intermediate
PATCH MANAGEMENT
Intermediate
PROACTIVITY
Intermediate
PROACTIVITY
Intermediate
RECONNAISSANCE
Intermediate
RECONNAISSANCE
Intermediate
ROOT CAUSE ANALYSIS
Intermediate
ROOT CAUSE ANALYSIS
Intermediate
SYSTEMS ENGINEERING
Intermediate
SYSTEMS ENGINEERING
Intermediate
Threat Detection & Analysis
Intermediate
Threat Detection & Analysis
Intermediate
Security Incident Triage
Intermediate
Security Incident Triage
Intermediate
Risk Management
Intermediate
Risk Management
Intermediate
GOVERNANCE
Intermediate
GOVERNANCE
Intermediate
AUDITING
Intermediate
AUDITING
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
GOVERNANCE RISK MANAGEMENT AND COMPLIANCE
Intermediate
INTERNAL AUDITING
Intermediate
INTERNAL AUDITING
Intermediate
ISO IEC 27001
Intermediate
ISO IEC 27001
Intermediate
PREPAREDNESS
Intermediate
PREPAREDNESS
Intermediate
RISK ANALYSIS
Intermediate
RISK ANALYSIS
Intermediate
RISK MANAGEMENT
Intermediate
RISK MANAGEMENT
Intermediate
SECURITY CONTROLS
Intermediate
SECURITY CONTROLS
Intermediate
VULNERABILITY MANAGEMENT
Intermediate
VULNERABILITY MANAGEMENT
Intermediate
INCIDENT RESPONSE
Intermediate
INCIDENT RESPONSE
Intermediate
LOG ANALYSIS
Intermediate
LOG ANALYSIS
Intermediate
MITRE ATT&CK FRAMEWORK
Intermediate
MITRE ATT&CK FRAMEWORK
Intermediate
NETWORK SECURITY
Intermediate
NETWORK SECURITY
Intermediate
PHYSICAL SECURITY OPERATIONS
Intermediate
PHYSICAL SECURITY OPERATIONS
Intermediate
RISK ANALYSIS
Intermediate
RISK ANALYSIS
Intermediate
SECURITY INVESTIGATIONS
Intermediate
SECURITY INVESTIGATIONS
Intermediate
SPLUNK
Intermediate
SPLUNK
Intermediate
THREAT ASSESSMENT
Intermediate
THREAT ASSESSMENT
Intermediate
VULNERABILITY MANAGEMENT
Intermediate
VULNERABILITY MANAGEMENT
Intermediate

Languages

English
Expert
Arabic
Intermediate

Training and Certifications

Certifications
CompTIA Security+ SY0-701 CompTIA Google Cybersecurity Professional Certificate (Risk Management)
CompTIA Security+ SY0-701 CompTIA Google Cybersecurity Professional (Risk Management)
Google Cybersecurity Professional Certificate (Risk Management)
CompTIA Security+ SY0-701
CompTIA
Oct 2025 - Oct 2028
Show credentials