Cybersecurity · Security Engineering · Offensive & Defensive Security

Mohammad Moradi

Senior Security Engineer

Senior Security Engineer with about 5 years of experience and a development background, working across blue team, red team, security engineering, detection engineering, Python development, Kubernetes security, and DevSecOps.

01

Professional Focus

Security Engineering Detection, SIEM, EDR, logging and security architecture.
Offensive Security Adversary simulation, red teaming and security tooling.
Engineering Python, automation, distributed systems and infrastructure.
02

Experience

BLU-BANK
2022 — NOW
Tehran, Iran · Security Engineering
Blue Team Engineer
Designing procedures for Notables and dashboard design and implementing them.
Designing Asset Management and Patch Management flows.
Developing and tuning Data Models.
Developing Use Cases and Dashboards.
Acting as Security Architect for Kubernetes and implementing laboratory scenarios for testing, implementation and demos.
Developing a Python-based logging module for Apache Superset and other tools in different programming languages.
Red / Purple Team Engineer · 2 Years
Adversary Simulation and Emulation.
Developing Red Team tools and malware.
Implementing Red Team scenarios and helping Blue Team engineers develop detection rules.
Developing a malware analysis platform based on LLM, MCP and IDA Pro to analyze malware automatically.
EDR bypassing and tuning the rules.
Developing an Access Matrix in Splunk to help Blue Team engineers implement complex logical Splunk queries.
Hunting unofficial network traffic based on hypothesis hunting.
SOC Analyst · 2 Years
Developing detection rules for different attacks.
Developing a Python module connecting to Splunk using splunk-sdk and checking queries based on KMeans and Machine Learning.
Setting up Splunk Data Models for Endpoint, Network and Authentication.
Developing and tuning Notables based on Data Models.
Investigation using Splunk Investigate and Workbenches.
Developing Auditd rules for Linux.
Basic forensics using FTK, Volatility and related tools.
Detecting DNS tunneling attacks with URL Toolbox.
PAYAMPARDAZ
2020 — 2022
Isfahan, Iran · Python Developer
R&D on SD-WAN products and gathering a large budget from Hamrah Aval for Payam Pardaz.
Developing Firewall Agents for SD-WAN products using Python, Ansible, VPP and FRR, with gRPC as the communication channel.
Developing a three-layer GRE-IPSec-VXLAN tunnel for firewalling.
Developing firewall modules with eBPF and iptables.
Developing a Dynamic Route Module with FRR for Edge Firewalls to provide OSPF routing capability.
Developing a Firewall Central Management Console for SD-WAN network management based on Python, Redis, RabbitMQ and REST API.
Developing CI/CD rules based on RabbitMQ and GitLab CI for automating procedures.
Dockerizing projects for compatibility and serving them as services.
03

Education

2021 — 2024
MSc of Secure Computing
Amirkabir University
ISO2700X Standards · Cryptography · Selected CISSP Chapters
2017 — 2021
BSc of Computer Engineering
University of Isfahan
2013 — 2017
Mathematics Diploma
SAMPAD KHORRAMABAD
04

Technical Skills

SIEM & Detection Splunk SIEM, Data Models, Notables, Detection Engineering
Security Operations Blue Team, SOC Analysis, Threat Hunting, EDR
Offensive Security Red Teaming, Adversary Simulation, Tool Development
Programming Python, Django, gRPC
Infrastructure Docker, Kubernetes, K8S Administration
Cloud-Native Security EFK, Falco, Rancher, Tetragon, Istio
Linux Security Tracee, eBPF, Auditd, SELinux, AppArmor
Automation & DevSecOps Shuffle, Ansible, Git, GitLab CI, Trivy
Databases PostgreSQL, Redis
Messaging RabbitMQ
Networking FRR, VPP, eBPF, iptables, SD-WAN
Machine Learning Basic Machine Learning & Deep Learning