montreal, qc — xtended soc analyst @ orange cyberdefense

Xtended SOC Analyst at Orange Cyberdefense and software engineer.

▼

// 01 — whoami

analyst by day,
engineer always.

I'm an Xtended SOC Analyst at Orange Cyberdefense and a Software Engineer working across threat detection, incident response and security automation. My experience spans SOC operations, identity and access management, and data-protection compliance in enterprise and institutional IT environments. Bilingual (English / French). I've been taking software apart to see how it breaks since my teens — now I get paid to make sure it doesn't.

  • edu B.Eng. Software Engineering — Security & Mobility, Polytechnique Montréal (2019–2024)
  • certs CompTIA Security+ · Microsoft SC-200
  • langs English (native) · French (native) · Mandarin Chinese (advanced)
  • base Montreal, QC 🍁

// 02 — experience

where I've defended.

09/2026 — present

Xtended SOC Analyst @ Orange Cyberdefense

  • Monitor and triage alerts in Palo Alto Cortex XDR, XSIAM and Sekoia; correlate endpoint data and security logs to investigate suspicious activity.
  • Assess incident scope and severity, escalate confirmed incidents, and support containment, remediation and recovery.
  • Conduct threat hunting and tune detection rules to improve coverage and reduce false positives.
  • Develop and maintain Cortex XSOAR playbooks to automate alert enrichment, investigation and response workflows.
  • Monitor Grafana dashboards; document investigation findings, response actions and handovers, and prepare incident reports.
Cortex XDRXSIAMXSOARSekoiaGrafana

07/2025 — 09/2026

Cybersecurity Analyst @ Collège Ahuntsic

  • Deployed Microsoft Defender XDR and Sentinel with ManageEngine Log360; administered Fortinet/FortiGate and Check Point firewalls.
  • Remediated vulnerabilities from credentialed Nessus scans, penetration tests and audits; designed and implemented an IT recovery plan.
  • Managed Entra ID and Active Directory; developed PowerShell and Microsoft Graph API automation to replace static admin consents with user-driven app authorization.
  • Led cybersecurity and data-protection compliance initiatives; authored policies, assessed SaaS vendors against SOC 2/ISO 27001, and coordinated team meetings and technology monitoring.
Defender XDRSentinelLog360Fortinet / FortiGateCheck PointNessusEntra IDActive DirectoryGraph APIPowerShell

06/2025 — 07/2025

IT Support Specialist @ InterRent

  • Provided enterprise IT support and administered Windows devices through the Intune Settings Catalog, automating laptop setup and enrollment.
  • Implemented Conditional Access policies and managed privileged roles through Entra ID and PIM.
  • Monitored endpoints with CrowdStrike Falcon and configured YubiKeys for Microsoft SSO.
  • Managed mobile devices in Jamf, Exchange mailboxes, onboarding/offboarding, SharePoint access and user provisioning.
IntuneEntra IDPIMCrowdStrikeJamfYubiKey

09/2022 — 09/2023

Web Developer & LAN Technician @ Otakuthon

  • Built and maintained a centralized staff portal to automate internal workflows.
  • Managed Windows workstation provisioning, lifecycle and patching.
  • Configured pfSense firewall rules, routing policies and network monitoring.
WebpfSenseWindowsNetworking

01/2022 — 05/2022

Cybersecurity & Automation @ Hydro-Québec

  • Developed RegEx rules to detect unauthorized changes to configuration files.
  • Created Ansible playbooks to automate server deployment.
RegExAnsibleLinux

// 03 — threat hunting

hunt. detect. respond.

sentinel — advanced hunting

Representative KQL hunting queries: risky sign-ins, encoded PowerShell commands, and brute-force detection.

Representative KQL hunts from my Microsoft security work. 🛡

// 04 — the origin story

🌟hdf.services

licensing & distribution platform for CS:GO script modules · 2020 → 2021 · built & operated solo · retired, fully archived

↑ faithful replica of the original landing page — its tab-title typewriter lives on in your real browser tab. look up. 🌟

Before the blue team, I designed, built and ran hdf.services — a full-stack licensing and distribution platform for CS:GO script modules. Auth server, code-protection pipeline, Discord bot, admin panel: one teenager, one Ubuntu box, hundreds of users. Everything I know about how attackers think started here.

  • HWID-locked auth API — PHP endpoints binding every user to their hardware ID, serving role-gated scripts (User / Beta / Staff) with per-request logging.
  • Code-protection pipeline — every release automatically obfuscated through the Luraph and MoonSec APIs before delivery.
  • Discord bot — discord.py key generation & redemption, account linking and role sync.
  • Admin panel + ban system — live log viewer, IP bans, remote HWID resets and kill-switch.
  • Modular delivery — feature modules shipped as role-gated Lua, versioned and served per user.
PHPLuaPythonMySQLdiscord.pyApacheUbuntu

☠️ retired 2021, preserved as a complete server archive. defending against detection systems taught me more about them than any course — that's why I defend for a living now.

327 registered users
226,220 script deliveries
1,288 HWID auth checks
530 user uploads
49 invite codes

// 05 — projects

things I've built.

Apps for badminton, file transfer and sports operations, alongside client websites, a browser game and a home for future ideas.

patchi.ng ↗

optical file transfer

Transfer files from a screen to a camera without uploading them. A shared Expo app combines a C++/WebAssembly decoder with local file verification, transfer history and export.

ExpoReact NativeC++WebAssembly

web app · live

poki.ng ↗

badminton umpiring

A badminton umpiring app with rally scoring, service and court-position tracking, timers, multilingual calls and printable PDF score sheets. Built from one codebase for mobile and web.

ExpoReact NativeTypeScriptPDF

web app · live

ghosti.ng ↗

court booking automation

An invitation-only CEPSUM badminton booking planner with calendars, ranked preferences and scheduled browser automation. Tracks reservations, availability snapshots and run outcomes across linked accounts.

Next.jsPlaywrightPostgreSQLCloudflare Workers

invitation-only · web app

nuki.ng ↗

ZONE 01:23

ZONE 01:23 — a third-person browser survival game set during a fictional night shift in Pripyat. A thirty-minute scenario combines field assignments, NPC conversations, a map and notebook, and an evacuation on foot or by vehicle.

Three.jsWebGL2BlenderWeb Audio

browser game · playable

Richo Sports ↗

racket sports & stringing

A four-language racket-sports storefront and stringing-service app. Connects product browsing and inquiries with racket drop-off forms, service tracking, an admin work queue and monthly billing.

Next.jsTypeScriptWixNeonCloudflare Workers

storefront & service app · live

CST Badminton ↗

badminton training centre

A website for CST Badminton Training Centre, with programs, schedules and registration links. Contact forms and a built-in messenger save requests in Cloudflare D1 and queue email notifications.

HTMLCSSJavaScriptCloudflare D1Resend

club website · live

stacki.ng ↗

a home for future sites

A minimal landing page for a future collection of websites. Static HTML and CSS, system fonts and no client-side JavaScript keep it simple. The landing page is live; the collection is coming soon.

HTMLCSSCloudflare Pages

landing page live · collection coming soon

// 06 — toolkit

the toolkit.

🛡 Security, SIEM & SOAR

Palo Alto Cortex XDRXSIAMXSOARSekoiaGrafanaDefender XDRSentinelKQLPurviewMITRE ATT&CKCrowdStrike FalconLog360NessusIDS / IPS

🔑 Identity & Access

Entra IDActive DirectoryPIMConditional AccessIntuneJamfYubiKey / SSO

☁️ Cloud & DevOps

AWS (Boto3)DockerKubernetesTerraformAnsibleDependabotgitleaks

⌨️ Programming

PythonC / C++JavaPowerShellKotlinLuaSQL

🌐 Web & Automation

AngularNode.jsPHPFlaskREST / SOAPSeleniumFirebase

🕸 Networking

Fortinet / FortiGateCheck PointpfSenseCisco routersLAN / WAN

📋 Governance & Compliance

SOC 2ISO 27001Law 25 / GDPRVendor security assessmentsSecurity policies
🎖

CompTIA Security+

certified

🎖

Microsoft SC-200

Security Operations Analyst

🎓

B.Eng. Software Engineering

Polytechnique Montréal · Security & Mobility · 2019–2024

// 07 — connect

let's connect.

Want to talk threat detection, incident response, or security automation? My DMs are open.