Athens-based SOC Analyst

Spiros Grouztidis

SOC Analyst | Detection Engineering

Final-year M.Eng. candidate in Information and Communication Systems Engineering, graduating in November 2026. I work in an Athens-based MSSP SOC, where I investigate alerts, write detection rules, and turn operational findings into useful dashboards and documentation.

MSSP SOC Hands-on alert triage, investigation, escalation, and detection work
Nov 2026 Expected M.Eng. completion at the University of the Aegean
2 paths LetsDefend SOC Analyst and Detection Engineering career paths completed
Cert study SC-900, SC-200, and SC-500 curricula studied; exams pending

Current work

Hands-on security operations, from alert to documented outcome.

MSSP SOC | Athens | 2026 - Present

Security Operations Center Analyst

Supporting day-to-day security operations in a multi-environment MSSP setting, with a focus on reliable triage, clear evidence, and detection quality.

  • Investigate security events and logs, validate alerts, and escalate incidents with supporting context.
  • Create detection rules in DRL and review the signal behind the alert logic.
  • Work with Microsoft Sentinel and Elastic during investigation and monitoring workflows.
  • Build dashboards and write operational documentation that supports consistent analyst work.
Applied work Current focus
DRL
Detection rules

Writing logic that turns relevant behavior into an actionable signal.

SIEM
Sentinel & Elastic

Reviewing telemetry, investigating alerts, and following evidence across logs.

VIEW
Dashboards

Organizing operational data so analysts can read status and patterns quickly.

DOC
Documentation

Recording processes, context, and decisions for repeatable security operations.

Skills

What I work with.

SOC & incident triage

Alert validation, log review, event correlation, phishing analysis, escalation, and clear incident notes.

Detection engineering

DRL rules, KQL-oriented investigation, MITRE ATT&CK mapping, detection logic, signal review, and tuning fundamentals.

SIEM & security tooling

Microsoft Sentinel, Elastic, Defender XDR, Defender for Endpoint, Entra ID, dashboards, and security documentation.

GRC & engineering

NIS2, DORA, GDPR, supply-chain security, risk-aware analysis, networks, operating systems, Python, databases, and applied AI coursework.

GitHub / @spirosgro

Security work and engineering coursework, in code.

My code portfolio brings together detection-rule work and university projects across artificial intelligence, Java, web development, APIs, and core systems topics.

github.com/spirosgro View GitHub profile
SEC-01

Detection rules

Detection logic, blue-team experiments, and security-focused rule development.

DRL / SIEM / Threat detection
AI-02

AI & data

University work in artificial intelligence, data analysis, and recommendation models.

Python / AI / Data
JAVA-03

Java projects

Object-oriented programming, application logic, and software engineering coursework.

Java / OOP
WEB-04

Web & API development

Web applications, frontend foundations, backend services, and API development.

HTML / CSS / JavaScript / APIs
SYS-05

Engineering foundations

C, databases, networks, algorithms, and systems work from the ICSD curriculum.

C / SQL / Networks

Education & training

Academic foundations backed by practical study.

University of the Aegean

M.Eng. Information & Communication Systems Engineering

Five-year engineering program with a core in programming, data structures, algorithms, databases, operating systems, networks, distributed systems, software engineering, internet programming, AI, information law, and systems security.

Network security Cryptography Privacy AI Data mining
LetsDefend

SOC Analyst Career Path + Detection Engineering Career Path

Completed both practical learning paths, covering alert investigation, phishing, malware and network-log analysis, incident handling, threat intelligence, detection logic, and rule development.

SOC Analyst Detection Engineering MITRE ATT&CK Incident handling
Microsoft Learn

SC-900, SC-200, and SC-500 study

Studied the certification curricula across security, compliance, identity, security operations, threat protection, and cloud security. Exams are pending.

SC-900 SC-200 SC-500 Sentinel Defender XDR

M.Eng. thesis

Threat detection and cyber resilience in the supply chain.

My thesis examines how organizations can improve threat detection and strengthen cybersecurity across supply-chain relationships. It connects technical incident examples with governance and regulatory requirements from NIS2, DORA, and GDPR.

This work reflects my broader interest in GRC: translating regulation and risk into practical controls, incident readiness, and decisions security teams can use.

01 NIS2

Cyber-risk management, reporting, resilience, and supply-chain responsibilities.

02 DORA

Operational resilience, incident handling, testing, and third-party ICT risk.

03 GDPR

Data protection, breach response, accountability, and impact-aware security controls.

Case work Incident examples connect the frameworks to real security decisions.

Contact

Professional contact and security writing.

I use this site and my blog to keep a concise record of my work, learning, and notes on security operations, detection engineering, and GRC.