SBR shams.dev
02 / Capabilities

What I can actually do

Grouped by domain rather than listed as a wall of keywords. Search to check for something specific — matching terms highlight as you type. The header switch changes which domains are in view.

SIEM

Security Monitoring & SIEM

Standing up the pipeline, then actually reading what comes out of it.

SIEM deployment & operation (Wazuh)Security monitoringLog & event analysisIdentifying suspicious activityFile Integrity MonitoringThreat-intel enrichment (VirusTotal)SOC reporting & documentation
IR

Incident Detection & Response

Triage, escalate, and follow the thread back to root cause.

Incident identification, triage & escalationMalware, phishing & intrusion-attempt handlingIndicators of Compromise (IoCs)Root-cause investigationMITRE ATT&CK mapping
VA

Vulnerability & Ethical Hacking

Finding the gap before somebody else finds it for you.

Vulnerability detection & CVE analysisCIS-benchmark configuration assessmentEthical hacking & web app testing (WebGoat/OWASP)Burp SuiteTryHackMe practiceSelf-built Wazuh/Kali cyber lab
GRC

Security Fundamentals & Governance

The half of security that has to survive an audit.

CIA TriadRisk managementThreats & vulnerabilitiesSecurity best practicesISO 27001 & PCI DSS concepts (MSc coursework)Security policy & risk-register awareness
NET

Network Engineering

Designing the paths, then making sure only the right traffic takes them.

LAN/WAN designNetwork segmentation & VLANsTCP/IP, DNSRouting & switching (Cisco, MikroTik)Firewalls (MikroTik, Cisco Meraki, UFW)VPN
SYS

Systems & Server Administration

Directory, policy and mail — the plumbing nobody notices until it stops.

Windows Server 2016Active DirectoryGroup PolicyRole-based access controlMicrosoft 365 administrationMail serverLinuxBash scripting
OPS

IT Infrastructure & Support

Endpoints, storage, backup, cameras, procurement — the whole estate.

Workstation deployment & troubleshooting (180+ endpoints)NAS storage & backup (QNAP, TrueNAS, rsync/cron)Enterprise cloud backup (Box)Virtualization (VMware, Hyper-V, VirtualBox)CCTV/IP cameras, DVR/NVR & access controlIT procurement & software-license compliance
IAM

Identity, Access & Audit

Who can reach what — and the evidence trail that proves it.

Active DirectoryGroup PolicyRole-based access controlPassword & account-lockout policyAudit-driven log collectionEvidence support for compliance reviews
EP

Network & Endpoint Security

Hardening the edge of the estate, on both sides of the job title.

Network segmentation & VLANsTCP/IP, DNSFirewalls (MikroTik, Cisco Meraki, UFW)VPNEndpoint security (Microsoft Endpoint Manager, Ivanti)DLPEmail & system hardeningCIS hardeningZero Trust principles
DEV

Platforms & Programming

Enough code to automate the boring parts and read someone else's script.

Programming fundamentals (C++, Python)Bash scriptingBasic web programmingGit/GitHubHypervisors (VMware, Hyper-V, VirtualBox)Windows Server 2016Linux
Proof, not adjectives

Where these show up

A skills list is only worth as much as the work behind it. Each of these areas is exercised somewhere in my experience or in a documented lab.

Let's talk about the hard part.

Open to SOC Analyst, Security Analyst and Blue Team roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.

Open to IT Engineer, Network Engineer and Systems Infrastructure roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.