Work Preference
Overview
Professional Summary
Work History
Education
Skills
Websites
Certification
Timeline
CYBERSECURITY
Open To Work

MOHAMED FARAH

ROCKWELL AUTOMATION
Lakeville,MN
MOHAMED FARAH

Work Preference

Job Search Status:

Open to work

Desired Job Title

Cyber Security DirectorVulnerability Assessment and Penetration Tester

Work Type

ConsultingFull TimePart Time

Location Preference

Remote

Minimum Desired Compensation

$200000/yr

Important To Me

Company CulturePersonal development programsWork from home option
19
Years of experience
3
Certification
Cybersecurity leader with 10+ years of experience building and scaling enterprise cyber defense capabilities across financial services, healthcare, retail, fintech and industrial/OT environments. Lead global Threat & Detection Engineering programs spanning Cyber Threat Intelligence (CTI), Threat Hunting, Detection Engineering, and cloud security. Trusted advisor to executive leadership on cyber risk, security investment strategy, and the evolving threat landscape.

Work History

Manager, Threat & Detection Engineering

2 Years 6 Months
ROCKWELL AUTOMATION | Remote | 04.2024 - Current
  • Scope: Lead a 25-person global Threat & Detection Engineering team responsible for CTI, Threat Hunting, and Detection Engineering across enterprise, cloud, and OT environments. Own strategy, executive reporting, vendor management, and a multimillion-dollar cybersecurity portfolio.
  • Built and scaled a global Threat Hunting program from the ground up within 12 months, increasing detection coverage by 50%
  • Directed enterprise CTI and detection strategy across endpoint, network, cloud, and OT environments, translating adversary intelligence into prioritized defensive actions and security investments
  • Manage a multimillion-dollar cybersecurity portfolio, optimizing technology investments, vendor relationships, and capability roadmaps while reducing tooling redundancy
  • Integrated CTI, Threat Hunting, Detection Engineering, and Security Engineering capabilities into global Security Operations workflows, strengthening proactive detection and accelerating response to emerging threats.
  • Partner with Information Security executives, Incident Response, SOC, Software and Security Engineering, Architecture, and business stakeholders across a 160-person global security organization to align detection priorities with enterprise risk
  • Deliver executive-level reporting on threat exposure, detection maturity, program performance, and strategic investment priorities

Staff Security Analyst, Threat Intelligence

1 Year 5 Months
ROBINHOOD | Remote | 11.2022 - 04.2024
  • Scope: Led development of enterprise threat detection and intelligence capabilities within a highly regulated fintech environment
  • Built and operationalized enterprise Threat Hunting program, expanding proactive detection across cloud and enterprise environments
  • Automated intelligence workflows, reducing manual analysis time by 40% and significantly improving response speed
  • Delivered executive-level intelligence briefings that influenced strategic security investments and risk decisions
  • Developed and standardized threat intelligence playbooks, improving consistency and scalability of detection operations
  • Partnered with cross-functional teams (SOC, Engineering, IR) to enhance detection coverage and response coordination

Senior Manager, Cyber Threat Operations

7 Months
MORGAN FRANKLIN CONSULTING | Remote | 04.2022 - 11.2022
  • Scope: Led global CTI and Incident Response engagements across multiple enterprise clients in regulated industries
  • Directed globally distributed CTI and Incident Response teams supporting healthcare, financial, and industrial clients
  • Led high-severity incident response engagements, ensuring rapid containment and compliance with regulatory requirements
  • Built and matured client CTI programs, establishing KPIs, reporting frameworks, and operational processes
  • Delivered executive-level briefings to leadership, regulators, and legal stakeholders, translating technical risk into business impact
  • Advised organizations on threat landscape alignment, risk posture, and long-term defensive strategy

Senior Cyber Threat Intelligence Analyst

1 Year 5 Months
PRINCIPAL FINANCIAL GROUP | Remote | 11.2020 - 04.2022
  • Helped establish and operationalize enterprise CTI program aligned to business priorities
  • Led attack surface management initiatives, improving visibility into external threats and vulnerabilities
  • Delivered executive-level intelligence reporting to support strategic decision-making
  • Managed vendor relationships and contributed to tool selection, improving capability and cost efficiency
  • Mentored analysts and ensured quality control of intelligence products

Lead Threat Intelligence Analyst

8 Months
THRIVENT FINANCIAL | Remote | 03.2020 - 11.2020
  • Built enterprise threat intelligence platform (TIP) to expand automation and integration across security tools.
  • Led advanced data analysis and multi-source intelligence fusion to identify emerging threats.
  • Partnered with global security teams and vendors to strengthen defensive capabilities.
  • Delivered predictive intelligence insights to guide proactive security strategies.
  • Advanced early threat detection through predictive, data-driven intelligence analysis.

Senior CTI Analyst & Threat Hunter

1 Year 11 Months
EXPRESS SCRIPTS | Remote | 04.2018 - 03.2020
  • Directed CTI operations through major corporate merger, maintaining continuity across security capabilities and integration efforts.
  • Planned and executed threat hunting campaigns aligned to MITRE ATT&CK, expanding detection coverage and analytic depth.
  • Implemented CTI technology stack to modernize DFIR capabilities and support investigative workflows.
  • Delivered intelligence briefings to leadership, informing risk-based decision-making across business priorities.
    Provided technical guidance on emerging threats and defensive controls to strengthen response readiness.
  • Advanced detection maturity through structured threat hunting and ATT&CK-aligned methodology.

Senior Cyber Threat Intelligence Analyst

1 Year
Best Buy | 04.2017 - 04.2018
  • Timely collection, correlation, storage, and dissemination of cyber threat intelligence strengthened advance warning, proactive security planning, and incident response support.
  • Threat monitoring for Best Buy brand, regional operations, technology infrastructure, and customer trust informed rapid risk awareness and response.
  • Security posture improved through recommendations delivered to security architecture and infrastructure teams.
  • Proactive threat intelligence products supported EIP in addressing threats to Best Buy IT infrastructure. External intelligence partnerships expanded through liaison with intergovernmental organizations, non-government organizations, law enforcement agencies, industry associations, peer institutions, and public and private sharing groups.
  • Emerging security threat research surfaced new risks and attack trends for defensive planning. Additional detection and prevention techniques improved proactive identification of malicious activity.
  • Collaborative monitoring and prevention strategies advanced through close work with information security and IT team members. In-depth analysis supported network monitoring and incident response operations.
  • Threat intelligence provider evaluation improved prioritization of potential security incidents. Additional security services created value for organization, key stakeholders, and customers.
  • Private intelligence vendor and tool selection supported stronger intelligence capability. Junior analysts gained stronger skills through training and mentoring.

Cyber Threat Intelligence Analyst

8 Months
BEST BUY | Richfield, MN | 08.2016 - 04.2017
  • Adversary TTPs collected for threat analysis. Intel deliverables delivered for Best Buy teams.
  • Executive threat assessments completed for leadership review.
  • Threat intelligence platforms supported through administration and content updates. Malicious software analyzed for security insight.
  • Information collected, analyzed, and distributed to meet intelligence requirements.
  • Feeds reviewed, imported into threat intelligence platforms, and exported to security tools.
  • Information-sharing lists and groups used to collect and share intelligence aligned with requirements.
  • Indicators of compromise identified, rules developed from analysis, and threat intelligence platforms updated.
  • Intelligence reports and deliverables produced for situational awareness across teams and leadership at Best Buy.
  • Threat assessments built with tools and information-gathering methods to collect, analyze, draft, and review research on select Best Buy executives.
  • Threat intelligence platforms integrated with security tools. Malware samples analyzed to support defensive operations.

Infantryman

8 Years
UNITED STATES ARMY | 02.2008 - 02.2016

Education

Master of Science - Security Technologies, Cyber Security

University of Minnesota

Bachelor of Science - Information Technology

Saint Mary's University of Minnesota

Skills

Cybersecurity frameworks
Digital forensics
Threat intelligence
Identity management
Network security
Security policy development
Zero trust architecture
Security architecture
Vendor risk management
Cloud security
Compliance management
Endpoint security
Log analysis
Vulnerability assessment
Business continuity
Audit preparation
Incident response
Security operations center
Forensic analysis
Incident response management
Digital forensics investigation
Advanced threat analysis
Regulatory compliance
Security information and event management
Network security monitoring
Cloud security expertise
Identity and Access management
Data protection
Threat hunting
SIEM management

Certification

  • Certified Expert in Cyber Investigations (CECI)
  • Certified Cyber Investigative Expert (CCIE)
  • Certified Counterintelligence Threat Analyst (CCTA)

Timeline

Manager, Threat & Detection Engineering

ROCKWELL AUTOMATION
04.2024 - CurrentRead More

Staff Security Analyst, Threat Intelligence

ROBINHOOD
11.2022 - 04.2024Read More

Senior Manager, Cyber Threat Operations

MORGAN FRANKLIN CONSULTING
04.2022 - 11.2022Read More

Senior Cyber Threat Intelligence Analyst

PRINCIPAL FINANCIAL GROUP
11.2020 - 04.2022Read More

Lead Threat Intelligence Analyst

THRIVENT FINANCIAL
03.2020 - 11.2020Read More

Senior CTI Analyst & Threat Hunter

EXPRESS SCRIPTS
04.2018 - 03.2020Read More

Senior Cyber Threat Intelligence Analyst

Best Buy
04.2017 - 04.2018Read More

Cyber Threat Intelligence Analyst

BEST BUY
08.2016 - 04.2017Read More

Infantryman

UNITED STATES ARMY
02.2008 - 02.2016Read More

University of Minnesota

Master of Science from Security Technologies, Cyber Security
Read More

Saint Mary's University of Minnesota

Bachelor of Science from Information Technology
Read More
MOHAMED FARAHCYBERSECURITY