SOC Analyst | Security Operations & SIEM (Wazuh) | Detection Engineering | OCI Certified

SOC analyst based in Botswana. I run day-to-day security operations for an enterprise client environment of 82 endpoints processing 800,000–900,000 security events daily through Wazuh — owning L1 triage and escalation, acting as the primary client-facing contact alongside an offshore L2/L3 team, and producing the daily, weekly and monthly SecOps reporting. I wrote the internal standard for that reporting and automated it in Python, cutting production time by around 70%.

Alongside that I publish a detection engineering lab series built on my own Wazuh deployment — engineering Windows telemetry with Sysmon and PowerShell logging, writing custom correlation rules mapped to MITRE ATT&CK, tuning out false positives, and auditing what those detections actually cover rather than what they claim to. Three OCI 2025 certifications and a software engineering background shape where I'm heading: cloud security engineering, at the intersection of detection and infrastructure.

Phatsimo Pheko

PROFESSIONAL EXPERIENCE

Junior Cybersecurity Consultant — SOC Analyst | TechBulls Botswana - Gaborone, Botswana | October 2024 – Present

Responsibilities:

  • Own L1 security operations for an enterprise client environment of 82 Wazuh agents spanning Windows Server, Red Hat Enterprise Linux, AIX, and CentOS, processing 800,000–900,000 security events per day.
  • Serve as one of two analysts covering the entire estate, and the only person in the organisation outside the offshore L2/L3 team able to produce client SecOps reporting.
  • Act as primary client-facing contact for security operations, coordinating incident escalation and remediation between the client and an offshore L2/L3 team across a 3.5-hour time zone gap.
  • Produce daily, weekly, and monthly SecOps reports covering detection findings, alert severity distribution, endpoint health, and remediation recommendations for client stakeholders.
  • Built a Python reporting tool that reduced report production from 1–2 hours to 15–40 minutes, a roughly 70% cut in a recurring daily operational task.
  • Authored the internal documentation standardising SecOps reporting methodology, then automated that methodology into the reporting pipeline.
  • Triage CVE vulnerability findings across the estate, assessing exposure and coordinating remediation guidance with the client.
  • Investigated a web-based attack campaign originating from a single source IP, establishing scope and coordinating response with the client and offshore team.
  • Monitor endpoint agent health and connectivity across the fleet, identifying and resolving agent disconnections to maintain continuous visibility.

Cybersecurity Intern | TechBulls Botswana - Gaborone, Botswana | October 2023 – October 2024

Responsibilities:

  • Monitored client endpoint agent health and connectivity across the estate via Wazuh SIEM, verifying continuous coverage and escalating platform issues to the offshore team responsible for L2/L3 support.
  • Compiled daily monitoring reports for internal supervisor review, building early security reporting and documentation practice.
  • Built working knowledge of the client environment, its telemetry sources, and the SIEM platform, later relied on when L1 support transferred in-house.

Tech Support Intern | Botswana Accountancy College - Gaborone, Botswana | January 2020 – August 2020

Responsibilities:

  • Delivered technical support to staff and students, resolving hardware, software, and network security issues efficiently.
  • Configured and maintained IT equipment and systems, contributing to a stable and secure IT environment.
  • Supported network monitoring and troubleshooting activities, gaining foundational experience in network security operations.
  • Provided technical onboarding and training to new staff on IT systems and security best practices.

TECHNICAL SKILLS

Security Operations

Detection Engineering

Telemetry & Logging

Platforms & Systems

Cloud & Infrastructure

Network Security

Automation & Reporting

Software Engineering

CERTIFICATIONS

OCI FOUNDATIONS ASSOCIATE

Validates core knowledge of Oracle Cloud Infrastructure services, cloud computing concepts, pricing models, and security fundamentals across OCI environments.

OCI ARCHITECT ASSOCIATE

Demonstrates the ability to design scalable, resilient, and secure cloud infrastructure solutions on Oracle Cloud Infrastructure, including networking, compute, and storage architecture.

OCI OBSERVABILITY PROFESSIONAL

Validates expertise in implementing monitoring, logging, alerting, and observability strategies across Oracle Cloud Infrastructure environments to maintain visibility and operational health.

EDUCATION

BSc (Honours) in Computer Systems Engineering | University of Sunderland | August 2017 – August 2021

  • Studied core topics in software development, database systems, artificial intelligence, and Internet of Things (IoT)
  • Gained hands-on experience with JavaScript, C#, Python, and SQL across industry-relevant projects
  • Completed a final year research project applying engineering principles to a real-world computing problem
  • Covered specialized areas including cybersecurity, secure software development, agile methodologies, and network security
  • Worked with professional-grade developer software and hardware through Cisco-accredited labs

CONTACT

I'm open to cybersecurity consultant roles, SOC analyst positions, and cloud security opportunities — locally in Botswana, remotely, and internationally, including relocation. Feel free to reach out via any of the channels below.