Capability Profile
This public profile is intentionally sanitised. It uses the submitted assessment and professional profile to establish a development baseline without publishing private contact details.
Current profile evidence
- aspiring Junior SOC Analyst;
- hands-on Wazuh SIEM home lab experience;
- practical interest in threat detection, log analysis and incident response;
- stated strengths in cloud security, security monitoring and Windows;
- foundation networking/cybersecurity learning through Cisco and Google programmes;
- public SOC Analyst portfolio already exists on GitHub;
- current interests include SIEM platforms, AI, website building and cybersecurity learning;
- preferred learning mode is self-paced, with regular one-on-one feedback;
- comfortable working independently and collaboratively;
- willing to participate in cross-functional projects.
Existing foundation learning
The supplied profile lists foundation achievements including:
- Networking Devices and Initial Configuration;
- Introduction to Cybersecurity;
- Google Cybersecurity Professional Certificate;
- Networking Basics;
- Cybersecurity and Cloud Fundamentals 1.0.
These provide a useful starting point. The IDR focuses on converting that learning into repeatable investigation and operational evidence.
Strengths to leverage
| Strength | How the roadmap uses it |
|---|---|
| Wazuh home-lab initiative | Becomes the main SIEM/detection laboratory |
| Security monitoring interest | Drives triage, alert analysis and detection exercises |
| Windows familiarity | Becomes the foundation for Event Viewer/Sysmon/Windows event investigations |
| Networking fundamentals | Supports packet analysis, source/destination reasoning and network triage |
| Problem solving | Applied to incident hypotheses and investigation logic |
| Creativity | Used in lab design, detection ideas and portfolio presentation |
| Communication awareness | Developed through incident notes, one-page briefs and mentor review |
| High learning commitment | Converted into structured evidence rather than unbounded course consumption |
Priority development gaps
| Area | Development target | Evidence |
|---|---|---|
| SOC triage | Consistent alert-to-decision process | Three complete investigation packs |
| Windows telemetry | Recognise important authentication/process events | Event 4625/4624/process-creation investigations |
| Wazuh operations | Understand agents, rules, alerts and tuning | Wazuh detection pack and tuning notes |
| Incident response | Document severity, containment, escalation and recovery | Incident runbook + tabletop |
| Threat mapping | Relate detections to attacker behaviour | MITRE ATT&CK mappings |
| Cloud security | Understand identity, logging, least privilege and monitoring | Cloud-control comparison artefact |
| GitHub workflow | Professional repositories, branches, commits and README evidence | Reviewed portfolio PRs |
| Communication | Concise technical writing and verbal explanation | Mentor-reviewed incident summaries |
| Time management | Sustain learning without fragmentation | Weekly plan + sprint completion rate |
Capability proof rule
A capability is treated as developed when Nkateko can explain it, demonstrate it safely, document the evidence and respond to review questions. Certificates and learning records support this evidence but do not replace it.