root@operator: ~/identity.log
root@operator:~# whoami

RAYAN AWAD
FRIHAT

Cybersecurity & Network Security Engineer

Versatile Technical & Network Security Engineer with 3+ years of practical IT experience across network administration, VoIP systems, system hardening, and enterprise technical support. Recently supported ERP (Odoo) and infrastructure security at EJAF Technology. Strong hands-on foundation in SOC operations and Security Automation — SOAR playbooks (Tines), SIEM/EDR management (Wazuh, Splunk, Security Onion), threat log analysis, and automated host containment. B.Sc. in IT Engineering (Cybersecurity), 9 industry certifications, and pursuing the HTB CDSA path.

📍 Erbil, Iraq Open to Remote B.Sc. IT Engineering HTB CDSA — In Progress
02 //

Deployment History

Technical & Network Security Engineer

EJAF Technology Iraq — Erbil, Iraq · Full-time, Hybrid
MAR 2026 — SEP 2026
  • Assisted senior engineers in configuring and maintaining network security controls for enterprise Odoo ERP and infrastructure environments.
  • Supported system hardening procedures across Linux/Windows servers and network devices to limit the enterprise attack surface.
  • Helped maintain, configure, and troubleshoot network infrastructure, IP PBX systems, and CCTV/NVR surveillance servers.
  • Collaborated with the technical team to enforce access controls, network segmentation, and system monitoring baselines.

Courses Instructor — Python & C Programming

LearnUpscale — Remote · Contract
MAR 2026 — PRESENT
  • Design and deliver online curricula for Python and C programming focused on practical, job-ready skills.
  • Mentor students through hands-on scripting exercises, code logic, and programming fundamentals.

Information Technology Support Specialist

OFFTEC Arabia — Syria · Full-time, On-site
AUG 2023 — NOV 2024
  • Provided end-user technical support — troubleshooting hardware, software, network connectivity, and OS issues.
  • Installed, maintained, and configured workstations, user accounts, and local network peripherals.
  • Documented resolution procedures in the internal knowledge base to improve support response efficiency.

Freelance IT & Cybersecurity Instructor

Self-Employed — Remote
AUG 2022 — JAN 2026
  • Mentored IT Engineering students in Linux administration, network security, operating systems, and core security concepts.
  • Guided practical lab setups: Linux hardening, Cisco Packet Tracer networking, and troubleshooting tooling.

Freelance Front-End Web Developer

Self-Employed — Remote
FEB 2019 — OCT 2021
  • Developed responsive web interfaces using React.js and integrated REST APIs.
  • Automated repetitive operational tasks using Python and Bash scripts, improving workflow efficiency.
03 //

Technical Arsenal

SOAR & Security Automation

Tines Workflows Analyst-in-the-Loop EDR Host Isolation Slack + Email Alerting Incident Escalation Generative AI in Security

SOC Operations & Detection

Wazuh Splunk ES Security Onion CrowdStrike Defender for Endpoint Incident Response Threat Hunting Log Analysis Sysmon Atomic Red Team

Network & Systems Admin

Network Segmentation Firewalls TCP/IP DNS VPN VoIP / PBX CCTV / NVR Windows Server System Hardening

Vuln Assessment & Linux

Nessus Nmap Ubuntu Kali CentOS Triage

Programming & Scripting

Python Bash SQL C JavaScript React.js REST APIs

Languages & Soft Skills

Arabic — Native English — Professional Technical Documentation Problem Solving Cross-Team Collaboration
04 //

Security Disclosures

SOAR

Automated Incident Response & Host Containment Workflow

View repo ↗
Integrated Automated Incident Response Framework (EDR & SOAR) — architecture diagram
Fig. 1 — Detection → Tines SOAR → Analyst prompt → LimaCharlie isolation workflow
Independent Cybersecurity Project · 2025
  • Designed and deployed an automated Incident Response workflow using Tines SOAR and EDR integration to process security alerts end-to-end.
  • Implemented context-rich alerting delivered via Slack & Email to ensure immediate SOC visibility.
  • Integrated interactive "Analyst-in-the-Loop" prompts to facilitate fast, human-approved containment decisions.
  • Automated host network isolation upon analyst confirmation (simulating CrowdStrike / Defender) and validated containment efficacy via ICMP ping failure proofs.
EDU

B.Sc. Information Technology Engineering — Cybersecurity

Syrian Virtual University (SVU) · Graduated Jan 2026
  • Key coursework: Network Security & Cisco Networking, Ethical Hacking & Penetration Testing.
  • Cryptography & Risk Management, Linux System Administration, Vulnerability Assessment.
05 //

Credentials & Certs

HTB Certified Defensive Security Analyst (CDSA)
Hack The Box · In Progress — Exp. Nov 2026
Generative AI Primer
Vanderbilt University · Sep 2026 · ID 26MUHJFH0J4Q
OCNA Wireless — Omada Certified Network Administrator
TP-Link · Jun 2026 – Jun 2029 · ID 4850C7DFAA364F7A
Operating Systems and You: Becoming a Power User
Google / Coursera · Jun 2026 · ID 9MBC6YR6B85G
The Bits and Bytes of Computer Networking
Google / Coursera · Nov 2025 · ID M33IN5QCH8XV
Technical Support Fundamentals
Google / Coursera · Sep 2025 · ID I6IA1VZ3R1D6
Connect and Protect: Networks and Network Security
Google / Coursera · Jul 2024 · ID Y886FNH7PUV4
Play It Safe: Manage Security Risks
Google / Coursera · Mar 2024 · ID CHM7FMNEF89F
Tools of the Trade: Linux and SQL
Google / Coursera · Nov 2024 · ID Y49RUD9NAFV2
Foundations of Cybersecurity
Google / Coursera · Nov 2023 · ID USWYBPWSEPLY
06 //

Establish Uplink

root@operator: ~/contact.sh
root@operator:~# cat contact.sh
Base of Operations
Erbil, Iraq
LinkedIn
Connect →
GitHub Portfolio
View repos →
Availability
Open to Remote