SOC
Kriminalvården · Norrköping
Monitor security logs and alerts, investigate and respond to incidents, and perform post-incident analysis. I also work with vulnerability assessments, penetration testing and digital forensics.
CYBERSECURITY / SOC
I'm William, a cybersecurity engineer/analyst focused on security operations, detection engineering and infrastructure. I also build and experiment in my homelab.
01 — ABOUT
I'm interested in cybersecurity from both the defensive and technical side. My focus is on understanding what is happening inside an environment, investigating suspicious activity and turning that knowledge into useful detections.
Outside of work, I run my own homelab where I experiment with Linux, networking, virtualization, Docker, security tooling and self-hosted infrastructure.
02 — EXPERIENCE
Kriminalvården · Norrköping
Monitor security logs and alerts, investigate and respond to incidents, and perform post-incident analysis. I also work with vulnerability assessments, penetration testing and digital forensics.
Kriminalvården · Norrköping
Provided technical support for hardware, software and network issues. Administered user accounts, permissions and access rights, while also helping employees follow IT and security practices.
Rsdata · Norrköping
Provided onsite technical support, diagnosing and resolving hardware and software issues. Installed, configured and maintained computers, printers and other IT equipment.
Koneo · Norrköping
Diagnosed and repaired hardware and software issues on Apple devices, including iPhones, iPads, MacBooks and iMacs. Performed inspections of batteries, screens, logic boards and connectors.
03 — SKILLS
Security monitoring, alert investigation, incident analysis, detection rules and security operations.
Elastic Security, KQL, EQL, Fleet, detection engineering and log analysis.
Hands-on experience managing and troubleshooting Linux and Windows environments. Comfortable working from both an administration and security perspective.
I have hands on Experience with Elastic Agent and logstash, onboarding and troubleshooting security logs from Windows, Active Directory, firewalls and endpoints.
Forensic investigation and analysis of disk images, browser artefacts, email activity and other digital evidence.
Vulnerability scanning, assessment, prioritisation, penetration testing and security testing.
04 — PROJECTS
A self-hosted environment used to experiment with infrastructure, networking, virtualization, security and automation.
Explore Homelab →05 — BEYOND SECURITY
A hobby I enjoy both casually and competitively. Always trying to improve my game and consistency.
Designing and printing practical projects, experimenting with different materials and learning how hardware and software work together.
Gaming, experimenting with hardware and software, and generally finding things I can take apart, troubleshoot and figure out.
A good excuse to get outside, compete with friends and spend some time away from a screen.
Playing Commander and building decks. I enjoy the strategy, experimenting with different ideas and finding interesting ways to make a deck work.