Inaam Kabbara

🔐 SOC & Threat Intelligence Analyst (CTI) | Blue Team Operations • SIEM (ELK, Splunk) • Incident Response • Data Analysis • Python Automation

France

About

👋 I’m Inaam Kabbara, a Cybersecurity Analyst with over 7 years of experience across IT systems, security operations, and data-driven environments. I hold a Master’s degree in Cybersecurity (EPITA, France) and a Master’s degree in Computer Science. My profile combines hands-on SOC experience with a strong foundation in systems, data handling, and operational security. I gained operational SOC experience at Ubility, where I worked in a structured SOC environment on: Security monitoring and alert triage (L1/L2) Log analysis and incident investigation using SIEM (ELK) and Zeek CTI enrichment, escalation, and SLA-driven ticket handling Python-based automation to optimize SOC workflows Prior to specializing in cybersecurity, I worked for several years as an IT Specialist in a public-sector environment, managing systems, user access, and sensitive data, while handling security-related incidents and ensuring operational continuity. Alongside my cybersecurity experience, I developed strong expertise in data handling and validation, including contributing to official national exam processes as a seasonal Data Entry Operator with the Ministry of Education. In this context, I processed and validated 800–1000 records per day, ensured strict data accuracy under tight deadlines, and handled highly sensitive datasets with full confidentiality. 🛠️ Core areas of expertise: SOC operations · SIEM (ELK, Splunk, Sentinel) · Log analysis · Incident response · CTI · Zeek · Python automation · Data analysis · Data validation 📊 Tools & strengths: Microsoft Excel (filters, formulas, pivot tables) · Multi-source data analysis · Data cleaning & structuring · Automation (Python, Bash) 📚 I also share my learning journey through a bilingual (FR/EN) LinkedIn series focused on SOC fundamentals and Threat Intelligence, translating complex concepts into practical insights. 🎯 Currently open to CDI/CDD opportunities in France (and remote) as: • SOC Analyst / Cybersecurity Analyst • Data Analyst / Data Operations (entry to junior level) 📍 Based in France — available immediately 🌍 Open to relocation and international opportunities

Experience

  • Cybersecurity Analyst – Infrastructure Security & Incident Response at Self-Employed
    Jan 2026 · 1 mo

    - Investigated and remediated security incidents on Linux servers and compromised WordPress environments - Designed and deployed Cloudflare WAF rules to mitigate brute-force attacks, bot traffic, XML-RPC abuse, and exploitation attempts - Performed server hardening activities, including Linux permission enforcement, site isolation, and restriction of PHP execution in writable paths - Contributed to clean recovery and remediation strategies to prevent reinfection following compromise - Implemented infrastructure monitoring using Zabbix to detect abnormal resource usage, service disruptions, and operational anomalies

  • SOC Analyst Intern (L1/L2) – Cybersecurity & Automation at Ubility
    Jul 2024 - Dec 2024 · 6 mos

    - Monitored and analyzed security events in a SOC environment using ELK Stack, performing alert triage, log correlation, and investigation of anomalies (e.g., failed logins, brute-force patterns) - Designed and implemented an end-to-end threat detection pipeline combining ELK (Elasticsearch, Logstash, Kibana) with Python automation - Developed rule-based threat categorization (JSON) to classify events (brute-force, phishing, malware), improving detection consistency - Implemented GeoIP enrichment to add geographic context to threats and enhance investigation capabilities - Built real-time Kibana dashboards (GeoIP maps, threat categories, time-series) to support monitoring and incident analysis - Automated high-severity alerting via Slack webhooks, improving response time and analyst reactivity Performance & Results - Achieved 73.68% accuracy, 85.71% recall, and 70.59% F1-score in threat detection - Reduced manual analysis effort by automating log ingestion, enrichment, and visualization AI / LLM Project (BERT) - Built an anomaly detection system using BERT to classify anomalies in system logs and network traffic - Processed auth.log and .pcap data, extracting features (IP, protocol, timestamps, messages) - Automated full ML pipeline: preprocessing → tokenization → training → inference → evaluation Additional Technical Contributions - Designed log parsing and normalization workflows (Logstash pipelines), structuring raw logs into analyzable formats for SIEM ingestion - Simulated attack scenarios (e.g., brute-force, unauthorized access) to validate detection logic and improve rule effectiveness - Applied detection patterns aligned with real SOC use cases, identifying suspicious authentication activity and abnormal network behavior - Leveraged Python for data processing, enrichment, and automation tasks, improving scalability and consistency of detection workflows

  • Data Entry Operator – National Exams (Seasonal Assignment) at Ministry Of Education and Higher Education - Lebanon
    Jul 2017 - Aug 2022 · 5 yrs 2 mos

    Handled seasonal data entry and validation during official national exam periods (Brevet and Baccalauréat), working under strict deadlines and high accuracy requirements. - Processed and validated 800–1000 records per day across large-scale student exam datasets using official examination systems - Ensured data accuracy by detecting and correcting inconsistencies (missing entries, invalid values) - Worked under zero-error tolerance conditions during critical exam periods - Performed data validation and cross-checking before final submission for official publication - Supported data organization and reporting using tools such as Excel when required - Maintained strict confidentiality of sensitive academic and exam data

  • IT Specialist – Systems & Information Security (Public Education) at Al-Baddawi Primary Mixed Official School
    Sep 2016 - Aug 2022 · 6 yrs

    Served as the sole IT Specialist in a public-sector education environment, responsible for system administration, security operations, and management of sensitive academic and administrative data. - Administered and secured SIMS (Student Information Management System), handling structured student and staff data in a high-responsibility environment - Managed user accounts, roles, and access rights for teachers, administrative staff, and school management (IAM) - Applied IT security best practices including system hardening (Windows/Linux), access control, backups, and service continuity - Monitored systems and analyzed logs to detect anomalies, misconfigurations, and unauthorized access - Handled IT incidents with security impact (malware infections, compromised accounts), ensuring timely remediation - Managed, validated, and maintained large volumes of structured data (students, staff, academic records), ensuring accuracy, consistency, and integrity - Organized, cleaned, and structured data for administrative reporting using Excel (filtering, formulas, data organization) - Prepared reports and summaries for school administration using Microsoft Word and Excel to support decision-making - Produced technical documentation and supported user awareness on data protection and secure system usage

  • Web Developer at BEA Technology Company
    Oct 2021 - Feb 2022 · 5 mos

    Designing front-end architecture, and implementing functionalities.