Ilyas Ousbaa | Security Consultant & SOC Engineer
Morocco | +212 642 10 96 68 | ousbaailyas@gmail.com
Professional Summary
Security Consultant and SOC Engineer with 3+ years of experience delivering SOC operations, detection engineering, and vulnerability management at enterprise scale. Proven ability to collaborate across IAM, Vulnerability Management, and Penetration Testing teams to strengthen security posture and drive remediation outcomes.
Professional Experience
HackerOne | Security Researcher & Detection Engineer
Jun 2025 - Present | Remote
- Research authentication flows, access control weaknesses, and real-world misconfigurations with an exploitability-focused lens.
- Conduct web application penetration testing with responsible disclosure via structured reports.
AXA GBS (via WITKY Group) | Cyber Security Consultant
Mar 2024 - May 2025 | Rabat, Hybrid
- Engineered credential-exposure detection solution scanning local systems, GitHub, SharePoint, Confluence, and NAS environments while substantially reducing false positives through refined regex and YAML detection rules.
- Collaborated with distributed teams to close the remediation loop, automated owner lookup, revocation notifications, and validation checks across IAM and VM teams.
- Managed vulnerability scanning and remediation workflows using automated tools, enabling prioritized, actionable findings across enterprise infrastructure.
SMA Services | Cyber Security Operations Analyst (
Internship)
Apr 2023 - Jun 2023 | Rabat, On-site
- Monitored threats across B2B infrastructure using FortiGate/FortiSIEM, Sophos, Check Point, Tenable Security Center, and Qualys.
- Deployed and hardened VPNs and network access points to secure client environments.
Barid Al-Maghrib (DCSI) | Cyber Security Analyst (
Internship)
Jan 2023 - Mar 2023 | Rabat, On-site
- Improved SOC detection pipeline by refining alert logic and detection rules, enhancing alert fidelity and vulnerability prioritization.
- Rebuilt SIEM/XDR log pipelines on Wazuh and Docker, increasing log coverage for a government-scale environment.
Provincial Delegation of Health | IT Security Specialist (
Internship)
May 2022 - Jun 2022 | Khénifra, On-site
Implemented security hardening measures and refined SOC detection workflows, reducing vulnerability exposure and improving alert fidelity.
Provincial Hospital of Khenifra | IT Security Specialist (Internship)
Jun 2021 - Jul 2021 | Khénifra, On-site
Hardened IT infrastructure across clinical and administrative environments and collaborated with healthcare staff to ensure operational alignment.
Core Competencies
Security Operations: SOC Monitoring, Incident Response, Threat Detection, SIEM/XDR Engineering
Vulnerability Management: Tenable SC, Nessus, Risk Prioritization, Remediation Automation
Detection Engineering: Alert Logic Refinement, Rule Optimization, Pipeline Engineering
Stakeholder Collaboration: Cross-Team Coordination (IAM, VM, Pentest), Security Advisory
Infrastructure Hardening: Systems Hardening, Secure Configuration, Docker
Tools & Technologies
Wazuh (SIEM/XDR), FortiGate/FortiSIEM, Sophos, Check Point, Tenable Security Center, Qualys, Bash, PowerShell, Go, Python, GitHub, SharePoint, Confluence, Docker
Research
Compound Exposure Model (CEM) for Software Secret Severity: Additive Identity and Noisy-OR Exposure v1.1.0, preprint. Deterministic hybrid framework: additive structural severity (5 facets) and noisy-OR exposure (8 factors) with independent Confidence Index and Floor/Ceiling dual-scoring; validated against 1,373 unified detectors from GitGuardian × TruffleHog.
Selected Projects
webtechalyser — Go-based web technology fingerprinting and reconnaissance tool
offsectoolman — Bash orchestration framework for automated pentest workflows
lolnetscan — Lightweight Living-off-the-Land network discovery scanner
credhunt (in development) — Go-based engine for automated, in-depth secrets scanning across diverse environments
Education & Certifications
Associate Degree in Computer Systems & Network Security — INFOSANTE Institute University, Khenifra (Oct 2020 – Aug 2022)
Fortinet NSE 1, 2 & 3 (Network Security Associate) — 2022
Languages
Arabic: Native
English: Professional
French: Intermediate
Additional Info
LinkedIn:
Portfolio:
WhatsApp: