Reza N.-Senior IT Security Engineer · Detection & Response · Microsoft Security

Check rate
Experience
Senior IT-Security Expert
Teambank AG
- Completed the integration of log sources into Microsoft Sentinel, including GCP workloads – centralized consolidation of all security-relevant events from Azure and GCP environments for complete end-to-end telemetry and comprehensive compliance evidence
- Developed custom rules and use cases based on the GFG Use-Case Library and the MITRE ATT&CK Matrix to cover company-specific threats and GFG-relevant scenarios with precise, mapped detection rules
- Tuned detection rules to minimize false positives, optimized detection thresholds, and modeled exceptions – enabling the SOC to work with relevant, prioritized alerts while reducing Mean Time to Detect/Respond
- Built SOAR capabilities in Sentinel by developing playbooks to automate recurring response processes such as containment, user and host isolation, and ticketing – shorter response times and 24/7 scalability
- Designed and built a log transformation solution to normalize and enrich incoming raw logs (GeoIP, CMDB, threat intelligence) and convert them into a consistent schema for high-performance KQL queries, use case logic, and correlations
- Managed Azure security through Azure Policies to enforce security and compliance standards, prevent drift, and continuously remediate deviations
- Operated the Defender XDR portal to link endpoint, identity, email, and SaaS signals with Sentinel findings, enable holistic incident triage, and orchestrate measures directly from XDR
Technologies: Microsoft Sentinel, Microsoft Defender XDR, Azure Policy, KQL, GCP, MITRE ATT&CK
Principal IT-Security Engineer
nicos GmbH
- Holistically assessed and coordinated security events and managed incident response processes
- Created and optimized use cases for threat detection in Microsoft Sentinel and SentinelOne
- Administered and functionally expanded the central security infrastructure with a focus on Microsoft Defender; secured identities and access permissions in Microsoft Entra ID
- Automated incident response workflows and runbooks using Palo Alto XSOAR and implemented a “Detection & Response as Code” approach to scale security measures
- Designed and implemented XDR, EDR, and SOAR solutions while considering regulatory requirements under DORA, MaRisk, and BAIT
- Led the project and technically implemented the company-wide SentinelOne rollout across all endpoints
- Continuously planned, implemented, and optimized the IT security architecture to adapt to the current threat landscape
Technologies: Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID, SentinelOne, Palo Alto XSOAR
Senior IT-Security Engineer
Oldenburgische Landesbank AG
- Analyzed and assessed security alerts and reports in the IBM QRadar SIEM system, identified false positives, and detected and assessed security-relevant incidents
- Further developed and documented the alerting chain and ensured traceable escalation of critical security events according to project-specific requirements
- Independently created use case reports and alerts based on existing log data; checked the correct integration and interpretation of log files to reduce false positives
- Developed and deployed detection logic based on Sigma Rules for proactive threat detection
- Rolled out the EDR solution across the company and implemented cross-platform security policies
- Provided conceptual and technical consulting for the migration from IBM QRadar to Palo Alto Cortex XDR
- Targeted optimization of SIEM processes to improve detection quality and efficiency in security monitoring
Technologies: IBM QRadar, Palo Alto Cortex XDR, Sigma
IT-Security Expert
Taschen GmbH
- Identified the company’s specific requirements and goals for SIEM and developed a detailed implementation plan
- Implemented security policies and rules for detecting and responding to threats
- Created comprehensive documentation for implementing and using the system and conducted training sessions and workshops
Technologies: Wazuh, Linux Administration, Windows Server
IT-Security Engineer / Security Officer
chargecloud GmbH
- Designed secure infrastructure, network, and application architectures and created reference architectures and security best practices for internal teams
- Integrated and implemented SIEM and EDR in hybrid cloud environments (AWS, Hetzner), planned and carried out EDR/XDR rollouts, and configured log source integration
- Developed and implemented SIEM use cases to improve threat detection and adapt it to specific business requirements
- Built vulnerability management: designed and integrated vulnerability scanners (Tenable Nessus), assessed and remediated security vulnerabilities, and defined corresponding policies
- Designed and wrote ISMS policies according to ISO 27001, NIS2, and CIS v8
- Implemented and managed firewall security solutions (pfSense) and network security monitoring with IDS/IPS (Suricata, Snort)
- Secured web applications based on the OWASP Top 10, integrated security controls into system design and development, and planned and reviewed network segmentation
Technologies: Elastic, Wazuh, Security Onion, Suricata, Snort, pfSense, Tenable Nessus, Sumo Logic, Ansible, Terraform, GitLab, Docker, AWS Cloud, Hetzner Cloud, ISO 27001, CIS v8
Security Officer
Lufthansa AirPlus International
- Primary escalation point for complex security incidents and root cause analyses in multi-stage attack scenarios (lateral movement, data exfiltration) – Tier 2/L2 analysis
- Assessment of the current system landscape, configuration, and integration of log sources with the SIEM, as well as infrastructure monitoring for the early detection of security incidents
- Definition and maintenance of detection use cases and automated SOAR workflows for regulatory and security-related requirements
- Implementation of solutions in compliance with DORA, MaRisk, and BAIT requirements, as well as the introduction of processes and technologies to meet PCI DSS requirements
- Planning, execution, and setup of an ISMS based on ISO 27001, including ISO 27001-oriented audits and regular internal security reviews
- Implementation of a case management system with TheHive, as well as automation of analysis, response, and threat intelligence with Cortex and MISP
- Development of data loss prevention strategies and customized KPIs and metrics for monitoring and assessing vulnerabilities and security incidents
- Evaluation of interfaces between the EDR system and ZTNA solution (Zscaler) for dynamic access control; design and further development of the architecture in the Azure Cloud
Technologies: Azure Cloud, Logpoint, Elastic, TheHive, Cortex, MISP, Rapid7 InsightVM, NeuVector, Zscaler, Jira, Confluence, Bitbucket, Linux (RHEL), Ansible, PostgreSQL, ISO 27001, PCI DSS
Network Security Engineer
Telefónica Tech GmbH
- Implementation and management of Fortinet security solutions and network security monitoring
- Implementation and consulting on SD-WAN, including technical consulting for the setup of underlay and overlay networks
- Network design for customer environments, as well as planning and review of current network segmentation
- Connecting network devices to a central management console for advanced control
- Definition and development of security policies based on business requirements
Technologies: Fortinet (FortiManager, FortiExtender, FortiGate), Wireshark, Nmap
DevSecOps Engineer
BMW Group AG
- Integration of automated security tests into the development process for the early detection of vulnerabilities, as well as source code reviews (Snyk, CodeQL, Contrast Assess, OpenText Fortify)
- Design and implementation of cloud security best practices in Azure and AWS (GuardDuty, IAM, Security Hub), as well as information queries through Azure Resource Graph
- Operation, implementation, and maintenance of Kubernetes clusters (EKS, AKS), as well as application rollouts through ArgoCD workflows
- Selection and integration of tools such as Terraform for infrastructure automation and Kubernetes for container orchestration in the CI/CD pipeline
- Selection and implementation of Sentinel use cases, as well as leading and coordinating security incident response activities, including triage processes for prioritization
- Planning and execution of ISO 27001-oriented audits, as well as development of a strategy to optimize patch management
- Development and delivery of security awareness programs, as well as introduction of ITIL best practices to optimize IT service management processes
Technologies: Azure Cloud, AWS Cloud, Microsoft Sentinel, Kubernetes (EKS, AKS), Terraform, ArgoCD, Docker, Snyk, CodeQL, Contrast Assess, OpenText Fortify, Wiz, Elastic, Apache Kafka, GitHub, Bitbucket, ISO 27001, CIS v8
SOC Analyst
dacoso GmbH
- SIEM administration and service monitoring in compliance with SLAs and KPIs, as well as administration of network and security infrastructure (via SIEM and EDR)
- Design and consulting for the setup of the security operations platform and integration of critical infrastructure areas
- Setup, configuration, and integration of log sources with the SIEM, as well as configuration and monitoring of EDR/NDR systems
- Leading and coordinating security incident response activities for the rapid detection, analysis, and containment of security incidents, including triage and mitigation measures
- Implementation of detection rules in the EDR (SentinelOne), as well as selection and configuration of Sentinel use cases
- Design of the security incident handling process and creation of a SOC reporting baseline for compliance and management levels
- Identification of vulnerabilities in web applications using Burp Suite and OWASP ZAP, as well as definition and tracking of remediation measures
- Implementation of zero-trust security strategies through continuous verification and authentication, as well as automation of cross-system and cross-application integrations via interfaces/APIs
Technologies: Microsoft Sentinel, Microsoft Defender, IBM QRadar, Darktrace, Elastic, Wazuh, SentinelOne, FortiGate, Burp Suite, OWASP ZAP, Tenable Nessus, Wireshark, Nmap, Linux, ISO 27001
Cyber Security Engineer
dacoso GmbH
- Setup and subsequent monitoring of the infrastructure, as well as analysis of network traffic to detect and defend against potential threats
- Planning, installation, and configuration of SIEM, EDR/XDR, and IDS/IPS systems, including the further development of HIDS/NIDS architecture
- Creation and validation of runbooks for SOC L1 analysis, as well as support in implementing automation solutions
- Analysis of customer requirements for EDR based on critical infrastructure and NIS2
- Setup of firewalls, as well as planning, review, and adjustment of network segmentation
- Containerization of applications using virtualization solutions, as well as support for version control and configuration management
Technologies: Snort, Palo Alto Cortex XDR, FortiGate, Elastic, Loki, Prometheus, Grafana, InfluxDB, Telegraf, Docker, Terraform, GitHub, Linux
IT Consultant / CAx Team Lead
Telekom AG
- Interface contact between Mercedes-Benz Group AG and Telekom AG
- Administration and 2nd-level support, including incident, change, and release management
- BCM process review and coordination of BCM development and adjustments
- Identification of vulnerabilities and opportunities for improvement in CAD, CAE, and CAM workflows to increase efficiency
- Introduction and integration of new software solutions, adaptation of existing systems, and delivery of training
IT Systems Administrator
Devoteam GmbH
- Installation, configuration, and maintenance of servers, workstations, and network components
- Management and monitoring of networks, including routers, switches, and firewalls
- Support with the implementation and monitoring of IT security measures
- Creation and maintenance of documentation on system configurations, processes, and IT policies
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Automotive, Banking and Finance, and Telecommunication.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Operations, Product Development, Audit, and Project Management.
Summary
Over 9 years of experience in IT. I design and operate SOC, SIEM, and SOAR platforms for banks, automotive, telecommunications, and energy companies – from connecting log sources and engineering use cases and detections to incident response. Focus on the Microsoft security stack (Sentinel, Defender XDR, Entra ID) as well as multi-SIEM environments (QRadar, Elastic, Splunk, Wazuh). Implementation of regulatory requirements under DORA, MaRisk, BAIT, ISO 27001, NIS2, BSI IT-Grundschutz, and PCI DSS in complex hybrid infrastructures.
Skills
- Security Operations: Siem Setup And Operations, Detection Engineering, Use Case Design, Alert Tuning, Threat Hunting, Incident Response (L2/L3), Soc Reporting, Kpi/Metric Design, Vulnerability Management
- Detection & Response: Microsoft Sentinel, Defender Xdr, Ibm Qradar, Palo Alto Cortex Xdr/Xsoar, Sentinelone, Elastic, Splunk, Logpoint, Wazuh, Darktrace, Security Onion, Thehive, Misp, Opencti
- Cloud & Infrastructure: Azure (Policy, Entra Id, Resource Graph), Aws (Guardduty, Iam, Security Hub), Gcp Log Sources, Kubernetes (Eks/Aks), Docker, Terraform, Ansible, Argocd, Linux (Rhel, Ubuntu)
- Frameworks & Compliance: Iso/Iec 27001, Nist Csf, Bsi It-Grundschutz, Dora, Marisk, Bait, Nis2, Kritis, Pci Dss, Cis V8, Mitre Att&Ck, Owasp Top 10
- Automation: Soar Playbooks, Detection-As-Code, Sigma Rules, Kql, Python, Bash, Ci/Cd (Github, Gitlab, Azure Devops), Infrastructure As Code
Languages
Education
Hochschule Darmstadt – University of Applied Sciences
B. Sc. Information Science · Information Science · Darmstadt, Germany
Evening Grammar School for Working Professionals
University of Applied Sciences entrance qualification · Evening Grammar School · Germany · 2.7
Certifications & licenses
API Security Fundamentals
APIsec University
Black Hat Python
EC-Council
Blue Team Junior Analyst
Security Blue Team
CompTIA CASP+
CompTIA CySA+
CompTIA Pentest+ Path
TryHackMe
Endpoint Security
Cisco Networking Academy
Fortinet NSE 1, NSE 2, NSE 3
Category B
Linux Foundation Certified System Administrator (LFCS)
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Network Defense
Cisco Networking Academy
Practical Cyber Threat Intelligence
EC-Council
Practical Ethical Hacking
TCM Security
Practical Web Application Security and Testing
TCM Security
Practical Windows Forensics
TCM Security
Scrum.org
SOC Core Skills
Antisyphon Training
Security Operations Center
EC-Council
Windows Penetration Testing Essentials
EC-Council
Statistics
Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Reza is based in Dreieich, Germany and can operate in on-site, hybrid, and remote work models.
Reza speaks the following languages: German (Native), English (Advanced).
Reza has at least 8 years of experience. During this time, Reza has worked in at least 12 different roles and for 11 different companies. The average length of individual experience is 1 year and 8 months. Note that Reza may not have shared all experience and actually has more experience.
Based on recent experience, Reza would be well-suited for roles such as: Senior IT-Security Expert, Principal IT-Security Engineer, Senior IT-Security Engineer.
Reza's most recent position is Senior IT-Security Expert at Teambank AG.
In recent years, Reza has worked for Teambank AG, nicos GmbH, Oldenburgische Landesbank AG, Taschen GmbH, and chargecloud GmbH.
Reza is most experienced in industries like Information Technology, Automotive, and Banking and Finance. Reza also has some experience in Telecommunication and Media and Entertainment.
Reza is most experienced in business areas like Information Technology, Operations, and Product Development. Reza also has some experience in Audit and Project Management.
Reza has recently worked in industries like Information Technology, Banking and Finance, and Telecommunication.
Reza has recently worked in business areas like Information Technology, Audit, and Operations.
Reza holds a Bachelor in Information Science from Hochschule Darmstadt – University of Applied Sciences.
Reza has 22 certificates. Among them, these include: API Security Fundamentals, Black Hat Python, and Blue Team Junior Analyst.
Reza is immediately available part-time for suitable projects.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 7 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Senior IT-Security Expert
Nearby freelancers
Professionals working in or nearby Dreieich, Germany
