CYBERSECURITY / SOC

Security
meets
infrastructure.

I'm William, a cybersecurity engineer/analyst focused on security operations, detection engineering and infrastructure. I also build and experiment in my homelab.

Understanding systems is part of securing them.

I'm interested in cybersecurity from both the defensive and technical side. My focus is on understanding what is happening inside an environment, investigating suspicious activity and turning that knowledge into useful detections.

Outside of work, I run my own homelab where I experiment with Linux, networking, virtualization, Docker, security tooling and self-hosted infrastructure.

FOCUS Cybersecurity
INTERESTS Detection · Digital Forensics ·
Vulnerability Management
ENVIRONMENT Linux · Windows · Cloud
LAB Self-hosted / Homelab

Where I've worked.

2023 — Present

SOC

Kriminalvården · Norrköping

Monitor security logs and alerts, investigate and respond to incidents, and perform post-incident analysis. I also work with vulnerability assessments, penetration testing and digital forensics.

SIEM Detection DFIR Vulnerability Management Penetration Testing


2022 — 2023

IT Technician & Helpdesk

Kriminalvården · Norrköping

Provided technical support for hardware, software and network issues. Administered user accounts, permissions and access rights, while also helping employees follow IT and security practices.

IT Support Windows Networking Active Directory


2020

IT Technician

Rsdata · Norrköping

Provided onsite technical support, diagnosing and resolving hardware and software issues. Installed, configured and maintained computers, printers and other IT equipment.

IT Support Hardware Windows Troubleshooting


2018 — 2019

Apple Support

Koneo · Norrköping

Diagnosed and repaired hardware and software issues on Apple devices, including iPhones, iPads, MacBooks and iMacs. Performed inspections of batteries, screens, logic boards and connectors.

Apple Hardware Troubleshooting

Areas I work with.

Detection

Security monitoring, alert investigation, incident analysis, detection rules and security operations.

Elastic

Elastic Security, KQL, EQL, Fleet, detection engineering and log analysis.

Windows & Linux

Hands-on experience managing and troubleshooting Linux and Windows environments. Comfortable working from both an administration and security perspective.

Logging & Log Sources

I have hands on Experience with Elastic Agent and logstash, onboarding and troubleshooting security logs from Windows, Active Directory, firewalls and endpoints.

Digital Forensics

Forensic investigation and analysis of disk images, browser artefacts, email activity and other digital evidence.

Vulnerability Management

Vulnerability scanning, assessment, prioritisation, penetration testing and security testing.

Things I've built and investigated.

01

Homelab

A self-hosted environment used to experiment with infrastructure, networking, virtualization, security and automation.

Proxmox Docker Linux Tailscale Caddy
Explore Homelab

What I do outside of security.

Bowling

A hobby I enjoy both casually and competitively. Always trying to improve my game and consistency.

3D Printing

Designing and printing practical projects, experimenting with different materials and learning how hardware and software work together.

Gaming & Tinkering

Gaming, experimenting with hardware and software, and generally finding things I can take apart, troubleshoot and figure out.

Disc Golf

A good excuse to get outside, compete with friends and spend some time away from a screen.

Magic: The Gathering

Playing Commander and building decks. I enjoy the strategy, experimenting with different ideas and finding interesting ways to make a deck work.