Summary
Overview
Work History
Education
Skills
Certification
Target Roles
Personal Information
Languages
Core Expertise
Selected Achievements
Timeline
Generic
ZEINA AL ABASSI

ZEINA AL ABASSI

Riyadh,Saudi Arabia

Summary

Cybersecurity & Risk Analyst experienced in supporting diverse organizations across security operations, incident response, and vulnerability management. Achieved significant operational efficiency by automating processes, notably reducing security reporting preparation time by 67%. Focused on delivering actionable insights through thorough risk assessments and effective communication with both technical and non-technical stakeholders.

Overview

1
1
Certification
4
4
years of professional experience

Work History

SOC Analyst Level 1 — Cybersecurity, Risk & Client Advisory

Alliant Cybersecurity
Houston, USA
01.2023 - 08.2026
  • Monitor, triage, and investigate high-volume security alerts across 35+ client environments within a 24/7 Security Operations Center using Securonix SIEM, CrowdStrike Falcon, and Qualys.
  • Analyze security logs, alerts, and events to differentiate false positives from genuine threats, determine severity and business risk, and escalate validated incidents to clients and internal security teams.
  • Investigate and respond to cybersecurity incidents including ransomware, business/email compromise, and MFA account takeovers, supporting containment, remediation, account recovery, and prevention efforts.
  • Conducted proactive threat hunting and vulnerability analysis to identify indicators of compromise, suspicious activity, and potential threats, enhancing overall security posture across client environments.
  • Support Microsoft security environments including Microsoft Azure, Microsoft 365, Microsoft Defender, MFA, email security gateways, and related security configurations, working with clients through issue resolution.
  • Collaborate across SOC, IT, threat intelligence, and GRC teams to investigate security issues, coordinate remediation activities, and improve clients’ overall security posture.
  • Prepare weekly and monthly cybersecurity reports covering alert trends, severity levels, user status, log-source coverage, vulnerability posture, asset risk, and remediation priorities.
  • Present monthly cybersecurity reports directly to client stakeholders, explain technical findings and security trends, answer questions, and recommend prioritized remediation strategies.
  • Develop detailed incident reports documenting incident cause, affected systems or accounts, remediation activities, and recommendations to reduce recurrence.
  • Supported cybersecurity risk assessments through client discovery sessions and control reviews, identifying security gaps and documenting tailored remediation strategies for client environments.
  • Prepare risk assessment documentation aligned with CIS Controls v8, including maturity observations, gap analysis, and tailored remediation recommendations.
  • Support NIST and CMMC cybersecurity framework initiatives and assist with development of security policies, procedures, and Standard Operating Procedures (SOPs).
  • Contribute to SOP development across access control, asset management/CMDB, identification and authentication, media sanitization, physical protection, public information/content posting, system and communications protection, and system and information integrity.
  • Present cybersecurity assessment findings, identified gaps, and recommended remediation activities to clients in a clear, advisory-focused format.
  • Translate technical security findings and vulnerability information into actionable recommendations understandable by both technical and non-technical stakeholders.
  • Reduced monthly security reporting preparation time by approximately 67% (6 hours to 2 hours) by developing and implementing automation/macros while maintaining reporting quality and SLA expectations.
  • Consistently handled the highest volume of security alerts among team members while maintaining SLA compliance and timely incident escalation.
  • Developed and delivered internal cyber-threat presentations to educate SOC team members on emerging security threats, improving incident response capabilities and fostering a culture of security awareness.

Education

Bachelor of Business Administration - Cyber Security

The University of Texas at San Antonio — Alvarez College of Business
San Antonio, Texas, USA

Skills

  • Security Operations Center (SOC)
  • SIEM analysis
  • Incident Response & Management
  • Incident Response Automation
  • Threat Hunting & Detection
  • Vulnerability Management
  • Vulnerability Analysis
  • Remediation planning
  • Remediation Tracking
  • Risk assessment
  • Risk Assessments
  • Asset Risk
  • GRC management
  • CIS Controls v8
  • NIST/CMMC support
  • Security Monitoring
  • Alert Triage
  • Log Analysis
  • Microsoft 365 & Azure Security
  • Microsoft Azure
  • Microsoft Defender
  • CrowdStrike Falcon
  • Endpoint Detection and Response (EDR)
  • Qualys Vulnerability Management
  • Email Threat Protection
  • MFA
  • Client Security Briefing
  • Incident reporting
  • Incident Management Procedures
  • Microsoft Excel
  • Securonix

Certification

  • CompTIA IT Fundamentals+ (ITF+) — Certified
  • Snypr Certified Security Analyst 300
  • Qualys Vulnerability Management Foundation
  • CrowdStrike Fundamentals: Falcon Platform Training
  • Fortinet NSE — Network Security Associate
  • Google Crash Course on Python

Target Roles

  • Cybersecurity Analyst
  • Cyber Risk Analyst
  • GRC Analyst
  • Information Security Analyst
  • Cybersecurity Consultant
  • Security Advisory Analyst
  • Vulnerability Management Analyst
  • SOC Analyst
  • Information Security Governance Analyst

Personal Information

Title: Cybersecurity & Risk Analyst

Languages

  • Arabic, Native
  • English, Fluent

Core Expertise

  • Cybersecurity Analyst
  • Cyber Risk Analyst
  • GRC Analyst
  • Information Security Analyst
  • Cybersecurity Consultant
  • Security Advisory Analyst
  • Vulnerability Management Analyst
  • SOC Analyst
  • Information Security Governance Analyst

Selected Achievements

  • Cybersecurity Analyst
  • Cyber Risk Analyst
  • GRC Analyst
  • Information Security Analyst
  • Cybersecurity Consultant
  • Security Advisory Analyst
  • Vulnerability Management Analyst
  • SOC Analyst
  • Information Security Governance Analyst

Timeline

SOC Analyst Level 1 — Cybersecurity, Risk & Client Advisory

Alliant Cybersecurity
01.2023 - 08.2026

Bachelor of Business Administration - Cyber Security

The University of Texas at San Antonio — Alvarez College of Business
ZEINA AL ABASSI