MUSTAPHA EL BAKHKHAKH
+212 669 174 557
mustaphaelbakhkhakh@gmail.com
www.elpatrinum.me
EDUCATION
Baccalauréat Professional LYCEE IBN YASSINE, 2018 – 2019
Technicien Spécialisé ISGI KHOURIBGA, 2019 – 2021
Digital Technology Architect UM6P/1337 SCHOOL, 2023 – Present
CERTIFICATIONS :
Cisco Certified Network Associate (CCNA)
Google Cybersecurity Professional Certification
Cisco Security Operations Center (SOC)
SC-200 : Security Operations Analyst Associate
EXPERIENCE :
Company: Tribunal de première instance (khouribga) 02/09/2023 –15/09/2024
Title: Cyber Security Analyst (Intern)
• Secure Cloud Configurations: Implemented secure cloud configurations, resulting in a 40% reduction in security incidents over six months. This involved setting up firewalls, managing security groups, and ensuring compliance with best practices
• Network and Security Support: Provided network and security support, troubleshooting and maintaining services, resulting in a 30% decrease in network downtime and a 25% reduction in security breaches. Worked extensively with firewalls, intrusion detection systems, and SIEM tools to maintain and enhance network security.
• Log Analytics and SIEM Development: Developed queries for log analytics and SIEM systems, creating 10 new dashboards and workbooks. This improved monitoring capabilities by 35% and facilitated quicker incident response, reducing the average incident response time by 20%.
Company : SOCVISION
Title : SOC Analyst 20/09/2024 – 26/06/2025
As part of a strategic cybersecurity initiative, I’ve been leading the design and implementation of tailored security
solutions to meet the organization’s unique needs.
• Cybersecurity Strategy: Assessed the organization’s security posture, identified requirements, and recommended scalable solutions aligned with business goals.
• MDM & Endpoint Security: Crafted MDM strategies with Microsoft Intune for onboarding and securing Windows, macOS, Linux, Android, and iOS devices. Integrated all endpoints into the XDR/EDR ecosystem.
• Asset & Server Hardening: Onboarded on-prem servers, analyzed asset inventory, and provided actionable security recommendations.
• Threat Detection & Response: Monitored threats and proactively identified vulnerabilities. Developed incident response playbooks, reducing incident impact by 30% short term and 67% long term.
• Data Protection & Recovery: Implemented backup and DLP solutions to protect data and accelerate recovery from ransomware or data loss.
• SIEM Customization: Built custom dashboards across multiple SIEM platforms, improving visibility and focusing detection on critical assets.
• Network Security Architecture: Reengineered the network for segmentation and security. Deployed OPNsense firewalls, Suricata/Snort IPS, and integrated them with the Elastic Stack (Elasticsearch, Logstash, Kibana) for local monitoring.
• Documentation & Collaboration: Created Technical Architecture Documents (DATs) to support team knowledge sharing and future onboarding.
• Stakeholder Communication: Managed technical discussions, cross-team coordination, and vendor negotiations to ensure effective implementation and adoption.
Company : AXA Group Operations
Title : Operations Security Analyst 31/06/2025 – Present
Operational Security Management:
• Management and supervision of analysis for requests to open firewall rules and the feedback provided by the security department on these requests.
• Responsible for managing security incidents with criticality levels 3 and 4 (DC SE scope).
• Control the management of threat blocks, handle SPAM reporting, manage exceptions (Blacklist & Whitelist)
for URLs, and process requests for proxy rule analysis.
• Manage the relationship with the Global SOC during the handling of security incidents.
• Oversee the process for managing security-related requests.
• Ensure the updating of use cases for critical security vulnerabilities.
• Manage and respond to security incidents in cloud environments, ensuring compliance with cloud security
policies and best practices.
• Monitor and analyze cloud security alerts and events, coordinating with cloud service providers as necessary.
• Collaborate with other teams to ensure cloud security is maintained.
• Stay updated on the latest cloud security threats and trends to enhance the organization’s security posture.
. PROJECTS :
• Project : Implemented and configured an IDS to detect network intrusions.
Source : https://github.com/ELPatrinum/Intrusion-Detection-System-IDS-
Platforms and Technology Used : Linux, Snort, Network Infrastructure, Elastic Stack (formerly ELK Stack)…
• Project : Wazuh XDR and SIEM Implementation : Monitor a Windows and a Linux machines simultaneously.
Source : https://github.com/ELPatrinum/Wazuh-XDR-and-SIEM-Implementation
Platforms and Technology Used : Wazuh, ELK Stack (Elasticsearch, Logstash, Kibana), SSL/TLS Encryption, …
• Project : Building a Network Packet Analyzer from Scratch.
Source : https://github.com/ELPatrinum/NETWORK_SNIFFER
Source : linkedin.com/feed/update/urn:li:activity:7243635305176514560
Platforms and Technology Used : Python, Core Networking Libraries, Protocol Parsing, Encryption Awareness…
SKILLS AND TECHNOLOGIES :
Microsoft Cloud Solutions, Microsoft Security Solutions, Network Security, System Administration, Firewalls, Virtual Machines,
Security Information and Event Management (SIEM), Intrusion Detection Systems (IDS), WAF, Logs Analysis, Malware Analysis, Linux, SQL, C, C++, Assembly, Python, Problem-Solving, Teamwork, Adaptability, Cyber Threat Intelligence (CTI).