Skip to main content

Capability Profile

This public profile is intentionally sanitised. It uses the submitted assessment and professional profile to establish a development baseline without publishing private contact details.

Current profile evidence

  • aspiring Junior SOC Analyst;
  • hands-on Wazuh SIEM home lab experience;
  • practical interest in threat detection, log analysis and incident response;
  • stated strengths in cloud security, security monitoring and Windows;
  • foundation networking/cybersecurity learning through Cisco and Google programmes;
  • public SOC Analyst portfolio already exists on GitHub;
  • current interests include SIEM platforms, AI, website building and cybersecurity learning;
  • preferred learning mode is self-paced, with regular one-on-one feedback;
  • comfortable working independently and collaboratively;
  • willing to participate in cross-functional projects.

Existing foundation learning

The supplied profile lists foundation achievements including:

  • Networking Devices and Initial Configuration;
  • Introduction to Cybersecurity;
  • Google Cybersecurity Professional Certificate;
  • Networking Basics;
  • Cybersecurity and Cloud Fundamentals 1.0.

These provide a useful starting point. The IDR focuses on converting that learning into repeatable investigation and operational evidence.

Strengths to leverage

StrengthHow the roadmap uses it
Wazuh home-lab initiativeBecomes the main SIEM/detection laboratory
Security monitoring interestDrives triage, alert analysis and detection exercises
Windows familiarityBecomes the foundation for Event Viewer/Sysmon/Windows event investigations
Networking fundamentalsSupports packet analysis, source/destination reasoning and network triage
Problem solvingApplied to incident hypotheses and investigation logic
CreativityUsed in lab design, detection ideas and portfolio presentation
Communication awarenessDeveloped through incident notes, one-page briefs and mentor review
High learning commitmentConverted into structured evidence rather than unbounded course consumption

Priority development gaps

AreaDevelopment targetEvidence
SOC triageConsistent alert-to-decision processThree complete investigation packs
Windows telemetryRecognise important authentication/process eventsEvent 4625/4624/process-creation investigations
Wazuh operationsUnderstand agents, rules, alerts and tuningWazuh detection pack and tuning notes
Incident responseDocument severity, containment, escalation and recoveryIncident runbook + tabletop
Threat mappingRelate detections to attacker behaviourMITRE ATT&CK mappings
Cloud securityUnderstand identity, logging, least privilege and monitoringCloud-control comparison artefact
GitHub workflowProfessional repositories, branches, commits and README evidenceReviewed portfolio PRs
CommunicationConcise technical writing and verbal explanationMentor-reviewed incident summaries
Time managementSustain learning without fragmentationWeekly plan + sprint completion rate

Capability proof rule

A capability is treated as developed when Nkateko can explain it, demonstrate it safely, document the evidence and respond to review questions. Certificates and learning records support this evidence but do not replace it.