Eren Atalay

Security Engineer

SIEM & detection engineering, with an offensive edge.

Interactive

A read-only shell over the same content — type, or tap a chip.

Eren Atalay — Security Engineer
SIEM & detection engineering, with an offensive edge.
This is a read-only shell over the same content in the sections below.
Type `help` to list commands — or tap a chip.

About

I'm a security engineer focused on SIEM and detection engineering — building and tuning production detections across cloud, identity and endpoint telemetry — with active offensive practice on HackTheBox, TryHackMe and Bugcrowd.

I hold a BSc in Computer Science and care about the boring parts: signal quality, clean fallbacks, and evidence over claims.

London, UK · open to opportunities.

Skills

AI/ML for Security

  • Scikit-learn
  • Supervised learning
  • Anomaly detection
  • Feature evaluation
  • Model validation

Cloud & Identity Security

  • Microsoft 365
  • Azure AD
  • Cloudflare logs
  • Google Cloud Platform (IAM, VM, Storage)
  • Secure access controls

Databases & Data Handling

  • SQL
  • MySQL
  • Pandas
  • Data analysis
  • Log parsing

Networking & Infrastructure

  • TCP/IP
  • DNS
  • DHCP
  • VLANs
  • Subnetting
  • VPNs
  • Firewall concepts
  • Windows
  • Linux (Ubuntu, Kali)
  • macOS

Programming & Scripting

  • Python
  • Java
  • C++
  • Bash
  • PowerShell
  • Flask

Security Operations & Monitoring

  • SIEM monitoring
  • Alert triage
  • Log analysis
  • Correlation rules
  • Threat detection
  • Incident investigation
  • Phishing analysis
  • Anomaly detection

Security Tools & Platforms

  • Wazuh
  • Splunk
  • ELK Stack
  • Burp Suite
  • Nmap
  • Wireshark
  • OWASP ZAP
  • Suricata

Projects

  • Cloud File Management Platform

    File sharing needs secure upload/download with access control rather than open buckets.

    • Flask
    • GCP
    • Google Cloud Storage
    • IAM

    Built a Flask web app for tagged file upload/download backed by Google Cloud Storage with IAM-enforced access control.

  • Distributed Key-Value Store

    A resilient store needs to spread keys across peers with no central coordinator.

    • Java
    • TCP/IP
    • SHA-256

    Implemented a peer-to-peer key-value network with PUT/GET operations and node discovery, verified for protocol compliance with Wireshark.

  • AI-Powered Network Threat Detection

    Network intrusions like DDoS and port scans hide inside high-volume traffic telemetry that manual review cannot keep up with.

    • Python
    • Scikit-learn
    • Pandas
    • CICIDS2017

    Built an ML intrusion-detection system on the CICIDS2017 dataset reaching 90%+ F1 detecting DDoS and PortScan, validated with cross-validation and confusion matrices.

  • AI-Assisted Phishing Detection

    Phishing emails slip past static rules and flood analysts with low-signal alerts.

    • Python
    • Scikit-learn
    • NLP

    Built an ML-assisted phishing detection system that scores suspicious messages to prioritise analyst triage and reduce false positives.

  • PwnDojo

    Offensive skills need a structured, repeatable practice ground beyond one-off CTF boxes.

    • Linux
    • CTF
    • Offensive Security

    A public repository documenting hands-on offensive-security practice and CTF/lab exercises.

    View repo
  • Bug-Bounty Reconnaissance Tool

    Security testing needs fast, repeatable reconnaissance across large attack surfaces instead of slow manual enumeration.

    • Python
    • Automation
    • OSINT

    Built an internal reconnaissance tool that automates asset discovery and enumeration, cutting manual recon time and surfacing testable targets faster.

  • UK Legal Case Search

    UK legal documents are hard to search by keyword and metadata at scale.

    • Apache Solr
    • Python
    • Web Scraping

    Scraped UK legal documents and indexed them in Apache Solr for fast keyword and metadata search.

Certifications

  • CompTIA A+ (Cyber Specialization)

    CompTIA · Dec 2023

  • Google Cybersecurity Professional Certificate

    Google / Coursera · May 2025

Contact

Reach me directly:

Download CV

All offensive work in authorized labs/programs · no client data shared.