Application · Security Analyst · EROAD

Detecting threats,
investigating incidents,
documenting everything.

I'm an Auckland-based security practitioner with hands-on experience in alert triage, log analysis, network forensics, and threat detection - built through 20+ structured SOC investigations, each documented end to end.

Focus
Security Operations
Location
Auckland, NZ
Certifying
CompTIA Security+
Status
Available
01

Why this role

Role alignment

EROAD's Security Analyst position maps directly to the work I've been training for: monitoring and triaging alerts across detection platforms, supporting incident response from investigation through to post-incident review, and maintaining the documentation that underpins compliance. My SOC lab work has been deliberate practice for exactly this.

What I bring

A genuine curiosity for how attacks work and how to stop them, paired with the discipline to document every investigation thoroughly. Behind the security study sits real IT operations experience across Windows, Active Directory, Microsoft 365, and cloud platforms - so I understand the systems I'd be protecting from the inside.

02

Technical capabilities

Detection & Response

  • Security alert monitoring & triage
  • Incident investigation
  • Threat detection & hunting
  • MITRE ATT&CK framework
  • SIEM fundamentals
  • Vulnerability scanning concepts

Forensics & Analysis

  • Wireshark & network forensics
  • Windows Event Log analysis
  • Sysmon analysis
  • Log correlation
  • Malware behaviour analysis
  • Email & payload analysis

Systems & Tooling

  • Windows & Linux
  • Active Directory & IAM
  • Microsoft 365 & Azure
  • PowerShell scripting
  • Python (foundational)
  • Technical documentation
03

Selected lab investigations

Full writeups with methodology, screenshots & findings → github.com/Aryaghaem/tryhackme-scripts-labs

Threat Detection

Command & Control detection

Identified C2 beaconing patterns in network logs, isolating regular callback intervals and anomalous outbound traffic indicative of an active channel.

MITRE ATT&CK · T1071 Application Layer Protocol
Persistence

Registry run keys & startup persistence

Detected malicious registry run-key modifications and startup folder entries used to maintain access across reboots, tracing the full persistence mechanism.

MITRE ATT&CK · T1547 Boot or Logon Autostart
Persistence

Malicious services & scheduled tasks

Investigated attacker-created Windows services and scheduled tasks, distinguishing them from legitimate system activity through event log analysis.

MITRE ATT&CK · T1053 Scheduled Task/Job
Network Forensics

DNS tunnelling detection

Used Wireshark to surface DNS exfiltration - high-entropy subdomains, abnormal query lengths and frequency - and reconstructed the data leakage path.

MITRE ATT&CK · T1048 Exfiltration Over Alternative Protocol
Network Forensics

ARP spoofing & MITM investigation

Detected ARP cache poisoning, traced intercepted credentials through the man-in-the-middle position, and documented the complete attack chain.

MITRE ATT&CK · T1557 Adversary-in-the-Middle
Network Forensics

Log4Shell exploitation detection

Identified Log4j RCE exploitation in network traffic - JNDI lookup strings, outbound callbacks, and post-exploitation indicators of compromise.

MITRE ATT&CK · T1190 Exploit Public-Facing Application
Initial Access

Phishing payload analysis via Sysmon

Traced phishing-delivered malware through Sysmon process creation events, network connections, and file-drop artefacts to map the execution chain.

MITRE ATT&CK · T1566 Phishing
Discovery

Internal reconnaissance detection

Detected post-compromise discovery activity - net commands, whoami, and ipconfig abuse - correlating events to identify the attacker's enumeration phase.

MITRE ATT&CK · T1087 Account Discovery
04

Credentials & study

CompTIA Security+

Exam Booked

Sitting 26 June 2026 · Threats, cryptography, IAM, network security, risk management

TryHackMe SOC Level 1

In Progress

20+ labs completed · SOC operations, threat detection, incident response

Google Cybersecurity Certificate

Completed

Coursera · Dec 2025 · coursera.org/account/accomplishments/specialization/CTLYS2V86SFL

Information Technology - Unitec

Graduating June 2026

Networking, system administration, information security, Windows Server

05

Experience

Feb 2026 - Present
Remote · Part-time

Junior IT Support Technician

Whizz-IT Ltd
  • Monitoring systems and triaging technical incidents across Windows environments
  • Managing Active Directory and Microsoft 365 accounts and access controls
  • Maintaining technical documentation and configuration records
  • Supporting patch installations and updates across client environments
Dec 2025 - Feb 2026
Hybrid · Auckland

IT Apprentice

Pacific Net Ltd · Cloud Services Provider
  • Supported Microsoft 365, Azure-based cloud services, and Intune device management
  • Assisted engineers with system configuration and infrastructure monitoring
  • Logged and documented technical issues and resolutions in an enterprise environment

Let's talk about the role.

I'm applying for the Security Analyst position at EROAD and would welcome the chance to discuss how I can contribute to your team.