SOCLIFE
SOCLIFE

Evidence-led security analysis

Published knowledge

Search SOC//LIFE

Professional profile

Denis Iana

Security Analyst focused on Detection Engineering and Threat Hunting.

I investigate security activity across identity, endpoint, email, cloud and network environments, and build detections that turn noisy signals into useful investigation paths.

My work focuses on understanding what happened, deciding what matters, and turning that reasoning into detections, hunts and repeatable validation.

Focus

What I do

  • Incident Investigation

    Follow the evidence across identity, endpoint, email, cloud and network data to understand what actually happened.

    Evidence: CASE-001

  • Detection Engineering

    Build and tune detection logic with attention to legitimate lookalikes, investigation value and validation.

    Evidence: DET-001

  • Threat Hunting

    Start from a clear hypothesis, test it against available telemetry and stop when the evidence or data no longer supports the hunt.

    Evidence: HUNT-001

  • Threat-Informed Analysis

    Turn current attacker behavior and public research into practical questions for detection and hunting.

    Evidence: THREAT-001

Portfolio

Selected work

Roles

Experience

  1. L2 Cyber Security Analyst

    Smarttech247

    Security operations across SIEM, XDR, identity, endpoint, email, cloud and network telemetry, with a focus on investigation, detection engineering and threat hunting.

    • Investigate and correlate security activity across multiple telemetry sources.
    • Build, tune and review detection logic and investigation workflows.
    • Support deeper incident analysis, threat hunting and escalation decisions.
  2. Quality Assurance

    EA Games

    Tested software behavior, reproduced issues and documented findings clearly for development teams.

    • Reproduced and documented software issues.
    • Worked with structured testing and repeatable validation.
    • Built an early foundation in analytical troubleshooting and attention to detail.

Platforms

Tools

  • SIEM & Query

    • Splunk Enterprise Security
    • IBM QRadar
    • Microsoft Sentinel
  • Endpoint & XDR

    • Microsoft Defender XDR
    • Cortex XDR
    • CrowdStrike
    • SentinelOne
  • Network, Cloud & Security

    • Palo Alto
    • Fortinet
    • Microsoft Entra ID
    • AWS
    • Azure
    • Mimecast

Development

Learning

  • Microsoft Applied Skills

    Get started with identities and access using Microsoft Entra

    Status
    Completed
    Issuer
    Microsoft
    Completed
    August 2026

Contact

Want to talk about SOC, Detection Engineering or Threat Hunting?

CV available on request.
Connect on LinkedIn (opens in a new tab)