Jocelyn V.

Cyber Threat Intelligence Analyst & Threat Hunting at Orange Cyberdefense

Rennes, Brittany, France

About

CTI Analyst working within the Threat Hunting team at Orange Cyberdefense. My main job is to track threat actors (APTs, campaigns, emerging vulnerabilities) and turn that into actionable hunting campaigns for our hunters. That intelligence also feeds into detection engineering work: writing detection and Sigma rules. I build internal tooling too: an automated hunting app that pushes IOCs/TTPs to our SIEM/EDR stack, and an app for generating threat study reports (APTs, campaigns, malware). I manage our OpenCTI instance on the side. MSSP context means working across a wide range of technologies daily: Microsoft Sentinel/Defender, Splunk, Google SecOps, CrowdStrike, SentinelOne. Previously spent 2 years as a L2 SOC Analyst on a multi-client scope. I also train L2 analysts regularly on topics like Active Directory, offensive techniques and threat intelligence.

Experience

  • Orange Cyberdefense (4 yrs)
    • Cyber Threat Intelligence Analyst
      Jan 2025 - Present · 1 yr 10 mos

      CTI Analyst within the Threat Hunting team. - Threat monitoring (APTs, campaigns, vulnerabilities) and production of actionable intelligence to drive threat hunting campaigns - AI & Threat Hunting Automation - Detection rule and Sigma rule creation - Development of an automated IOC/TTP hunting app targeting SIEM/EDR platforms - Development of an internal app for threat study report generation (APTs, campaigns, malware) - OpenCTI instance administration - Occasional threat hunting engagements - Training L2 analysts on Active Directory, threat intelligence and offensive techniques Stack: Microsoft Sentinel/Defender, QRadar, Splunk, Google SecOps, CrowdStrike, SentinelOne

    • CyberSOC Analyst L2
      Nov 2022 - Jan 2025 · 2 yrs 3 mos

      L2 SOC Analyst on a shared, multi-client scope. - Alert triage, investigation and incident response - Primary SIEM: QRadar. Also worked with Google SecOps and CrowdStrike - Built and delivered training sessions for L2 analysts on offensive techniques (exploitation) and detection, including hands-on lab environments

  • Cybersecurity Engineer at SILICOM SAS
    Oct 2022 - Jan 2023 · 4 mos

  • Pays de Montbéliard Agglomération (5 yrs 1 mo)
    • IT Security Assistant
      Sep 2020 - Sep 2022 · 2 yrs 1 mo

      - Internal audits - France Relance project management - EDR implementation and management - Educational phishing campaigns

    • Full Stack Web Developer
      Sep 2019 - Sep 2020 · 1 yr 1 mo

    • Information Technology Technician
      Sep 2017 - Sep 2019 · 2 yrs 1 mo

      - IT asset management - Linux server administration - Support