Cybersecurity | Security Operations | eJPT certified (97%)
Security professional with a background in high-security operational environments at Mastercard (cryptographic operations, PKI, PCI compliance), at Binance (AML/KYC fraud investigation, OSINT, pattern analysis and risk escalation), and customer-facing roles.
At Binance, my work included enhanced due diligence, blockchain and on-chain tracing, and the detection of synthetic-identity and deepfake fraud, with high-risk cases escalated within a high-volume, AML/CFT-regulated environment.
At Mastercard, I was part of the information security operations team, focusing on cryptographic key lifecycle management under On-Behalf Key Management (OBKM) and PKI services, certificate workflows, and PCI-DSS compliance within a strict dual-control environment.
In 2025, I completed an intensive six-month cybersecurity bootcamp covering SOC, SIEM, DFIR, MITRE ATT&CK, and red-team methodology, and earned the eJPT (97%) certification. I continue to develop my skills through home-lab projects, currently building an AI-augmented detection pipeline (Wazuh, Suricata, n8n, Claude API).
🛡️ Argus SOC | AI-Augmented Home Lab Security Operations Center - Active Directory detection engineering · Wazuh · Suricata · Proxmox · Claude API triage · MSSP topology (in development)
📂 Cybersecurity Portfolio | Comprehensive documentation of my red team and blue team projects and tools
✍️ Blog | Cybersecurity projects documentation, CTF writeups and certifications
🏆 TryHackMe: Top 3% globally | Profile
Currently building a three-tier AI-Augmented Home Lab Security Operations Center that mirrors real MSSP/MDR infrastructure
- Argus SOC | https://github.com/Al3grus/Argus-SOC (in development)
- Hetzner VPS (argus-soc) — Cloud SOC platform: Wazuh SIEM (Manager + Indexer + Dashboard), detection rule tuning, dashboard interpretation, false positive reduction, n8n workflow engine automated SOC workflows and alert routing, Velociraptor DFIR, Claude API alert triage
- ThinkCentre M920x (argus-hypervisor) — Proxmox virtualisation host: Active Directory domain (Windows Server 2022 DC, Windows 11 domain-joined workstation), Kerberos/GPO/DNS configuration, vulnerable target VMs (Metasploitable 2, DVWA)
- Pi 5 (argus-central) — MSSP edge sensor + admin: Suricata NIDS (SPAN port mirroring via Cisco SG300), Zeek protocol analysis, Cowrie SSH honeypot, Wazuh Agent, Velociraptor agent, Pi-hole DNS, WireGuard VPN, Grafana dashboards
📱 Corlang | Language learning app | Prepares users for citizenship, work & language exams | on-device data · no accounts, no ads, no tracking · optional AI tutor
