Summary
Overview
Work History
Education
Skills
Certification
Timeline
Generic

Mahdi Duale

Canberra, ACT,ACT

Summary

Experienced SOC Analyst with a solid background in cybersecurity operations, including threat detection, incident response, and vulnerability management. Proficient in using tools such as Google SecOps, Microsoft Sentinel, Splunk, CrowdStrike EDR, Defender for Endpoint, and vulnerability scanners like Nessus, Qualys, and OpenVAS. Skilled in identity and access management with Microsoft Entra ID (formerly Azure AD), and experienced in Windows Server administration and Active Directory. Familiar with ITSM practices and security frameworks including ITIL, NIST, MITRE ATT&CK, and ISO/IEC 27001:2022.

Overview

14
14
years of professional experience
1
1
Certification

Work History

Senior Technical Support Specialist

Community College of Qatar
06.2022 - Current
  • Performing real-time monitoring and analysis of
    security alerts and events using SIEM tools to
    identify and mitigate potential threats.
    • Conducting detailed analysis and correlation of
    logs and security events to identify patterns and
    anomalies in network traffic.
    • Conducting initial triage of security incidents,
    respond appropriately, and escalate according
    to severity and impact.
    • Contributing to continuous vulnerability
    management by monitoring systems and
    helping with remediation efforts.
    • Maintaining and updating incident response
    playbooks and documentation to improve the
    efficiency and effectiveness of SOC operations.
    • Assist in creating and delivering security
    awareness training to educate employees on
    cybersecurity risks and compliance.

Technical Support Specialist

Community College of Qatar
05.2018 - 05.2022
  • Administered user identities across hybrid
    environments by managing Microsoft Entra ID
    (formerly Azure AD) in conjunction with onpremises
    Active Directory.
    • Implemented and managed Microsoft Entra
    Connect to synchronize users, groups, and
    directory objects from Active Directory Domain
    Services (AD DS) to Microsoft Entra ID.
    • Configured and managed automated user
    provisioning and deprovisioning processes,
    ensuring efficient and secure identity lifecycle
    management.
    • Administered identity and access solutions
    using Microsoft Entra ID as the centralized
    identity platform for managing users, groups,
    and devices.
    • Enabled and managed Single Sign-On (SSO)
    across multiple applications, simplifying user
    authentication and enhancing security.
  • Implemented and maintained Microsoft Entra ID
    Multi-Factor Authentication (MFA), adding an
    additional layer of security through multiple user
    verification methods.
    • Deployed Microsoft Entra Privileged Identity
    Management (PIM) to enforce Just-In-Time
    (JIT) access for administrative roles, minimizing
    standing privileges and strengthening
    governance.
    • Designed and enforced Conditional Access
    policies in Microsoft Entra ID based on user risk,
    device compliance, location, and application
    sensitivity to secure access and reduce threat
    exposure.
    • Audited and monitored privileged access using
    access review policies and Microsoft Entra ID
    logs to maintain compliance and proactively
    detect anomalies.
  • Leveraged Microsoft 365 Defender to detect
    and remediate threats in real time by enabling
    self-healing for user accounts, endpoints, and
    mail systems.
    • Administer Microsoft Defender for Endpoint to
    manage and monitor corporate network
    devices, ensuring robust endpoint security and
    compliance.
    • Integrated identity and access management
    (IAM) policies with Microsoft Intune, Microsoft
    Defender, and third-party SIEM solutions to
    enable centralized security monitoring and
    policy enforcement.

TECHNICAL SUPPORT SUPERVISOR

Community College of Qatar
06.2011 - 05.2018

Manage and maintain Windows Servers

across multiple environments (development,

staging, production), optimizing uptime,

performance, and infrastructure scalability.

• Provided Tier 2/3 support for Windows Server

incidents, applying ITIL best practices to

reduce resolution time through efficient

troubleshooting and escalation

• Managed Active Directory identities,

overseeing user provisioning, OU structure,

and Group Policy to ensure secure and

efficient access control.

• Automated bulk user provisioning, access

control, and log maintenance using

PowerShell scripts, reducing manual tasks and

streamlining administrative processes.

• Administered and monitored DNS and DHCP

services, ensuring optimal network

performance and swift resolution of name

resolution issues.

Managed patching schedules and WSUS

deployments to maintain system security,

stability, and compliance with organizational

policies.

• Implemented and managed antivirus

configurations and policies aligned with

institutional security standards to safeguard

systems against threats.

• Managed file and print server operations,

optimizing access control, resource sharing,

and storage allocation to support daily

business functions.

• Administered vCenter infrastructure, optimized

HA configurations, and executed vMotion

migrations to minimize downtime and enhance

resource utilization.

Maintained and troubleshooted Microsoft

Hyper-V infrastructure across development

and staging environments to support reliable

testing and deployment processes.

• Managed ServiceDesk Plus platform by

designing workflows, automations, and

dashboards that enhanced ITSM process

efficiency and user satisfaction

• Facilitate Change Advisory Board (CAB)

meetings, ensuring risk assessments and

approvals are properly documented.

• Monitor SLA compliance, generate

performance reports, and communicate KPIs

to senior management.

Education

Master of Science - Information Technology

Sikkim Manipal University
India
01-2007

Bachelor of Science - Computer Application

Osmania University
India
01-2005

Skills

    Cybersecurity Tools:

    Wireshark, TCPdump, Metasploit, Kali Linux

    Identity and Access:

    Management: Microsoft Entra ID

    SIEM tools:

    SecOps, Splunk, and Sentinel

    Vulnerability Scanner tools:

    Nessus, Qualys, OpenVAS

    End-point Security: Microsoft

    Defender for endpoint, CrowdStrike

    Mobile device Management:

    Microsoft Intune

    Security Frameworks:

    ITIL, NIST, MITRE ATT&CK, and ISO/IEC 27001:2022

    Other Technical Skills:

    Incident Response, Risk Assessment, Cloud Security (Azure), firewalls (FortiGate), Microsoft XDR

    defender, Microsoft Purview

Certification

C E R T I F I C A T I O N S & C O U R S E S

MICROSOFT CYBER SECURITY

ANALYST

MICROSOFT CERTIFIED: SECURITY,

COMPLIANCE, AND IDENTITY

FUNDAMENTALS

MICROSOFT CERTIFIED: AZURE ADMINISTRATOR ASSOCIATE

MICROSOFT CERTIFIED: SECURITY OPERATIONS ANALYST ASSOCIATE

MICROSOFT AZURE ARCHITECT TECHNOLOGIES

CC – CERTIFIED IN CYBERSECURITY

CERTIFIED ETHICAL HACKER V11

COMPTIA SECURITY+

FCP- FORTIGATE SECURITY 7.2

FCP-FORTIGATE INFRASTRUCTURE 7.2

GETTING STARTED WITH WIRESHARK: THE ULTIMATE HANDS-ON COURSE

ISO/IEC 27001:2022: INFORMATION SECURITY MANAGEMENT SYSTEMS CERTIFIED

ITIL® V3 FOUNDATION

TRYHACME SECURITY OPERATIONS CENTER (SOC) LEVEL 1

QUALYS VULNERABILITY

MANAGEMENT FOUNDATION

Timeline

Senior Technical Support Specialist

Community College of Qatar
06.2022 - Current

Technical Support Specialist

Community College of Qatar
05.2018 - 05.2022

TECHNICAL SUPPORT SUPERVISOR

Community College of Qatar
06.2011 - 05.2018

Master of Science - Information Technology

Sikkim Manipal University

Bachelor of Science - Computer Application

Osmania University
Mahdi Duale