Hayri Celik

Threat Detection & Response Analyst @Normcyber

Bournemouth, GB
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Dec 2024 — Present

Threat Detection & Response Analyst @Normcyber

View department →

Fareham, GB

EDUCATION

N/A

Akdeniz University

Associate's degree, Accounting and Business/Management

N/A

CS VISOR

Cyber Security Anlayst Immersion Programme, Computer and Information Systems Security/Information Assurance

ABOUT HAYRI CELIK

Experienced Threat Detection & Response Analyst Shift Lead working in a fast‑paced Security Operations Center (SOC), focused on protecting organisations through SIEM, EDR/XDR, and structured incident response. I monitor, triage, and investigate 100–120+ daily security alerts across FortiSIEM, Microsoft Sentinel, FortiEDR, SentinelOne, and Defender for Endpoint, delivering rapid alert triage with a consistent 6‑minute handling SLA while maintaining strict quality and escalation KPIs.My core strengths are threat detection, incident investigation, and phishing/malware analysis, using frameworks such as MITRE ATT & CK, Cyber Kill Chain, and OWASP Top 10 to distinguish real attacks from noise and reduce false positives. Day to day, I correlate logs, host telemetry, and email/security appliance data to validate alerts, scope suspicious activity, and produce clear, actionable incident response notes and escalation summaries for L2/L3 and client teams.As Shift Lead, I coordinate SOC workflows, act as first point of contact for client requests, and oversee ticket handling and escalations from L1 to senior analysts. I mentor and support junior SOC analysts, help standardise investigation approaches, and contribute to playbooks, checklists, and documentation that improve consistency in SOC operations, alert handling, and communication under pressure.My toolkit spans FortiSIEM, Microsoft Sentinel, Splunk, CrowdStrike Falcon, QRadar, Rapid7, Tenable, Qualys, Mimecast, and Wireshark, supported by KQL and PowerShell for deeper log analysis and querying across SIEM and EDR environments. Outside production, I build and use home labs (AD–SIEM integrations, VPNs, honeypots, Pwnagotchi) to strengthen blue‑team skills and stay current with modern cybersecurity operations practices.I am SC/DBS‑cleared and hold certifications including CompTIA Security+,(ISC)², NSE, Splunk Core, ISO 27001, and hands‑on enterprise defence training, reflecting a strong commitment to continuous learning in SOC, threat detection & response, and incident handling. Passionate about advancing SIEM/EDR operations and blue-team collaboration, I enjoy connecting with security professionals, MSSPs, and fellow analysts to exchange insights on alert triage, threat detection, and effective SOC operations.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.