About Projects Case Studies Experience Skills Education Certifications Contact
BASED IN DUBAI, UAE | IMMEDIATE AVAILABILITY

MUHAMMED ALI

IT SECURITY SUPPORT ENGINEER | CYBERSECURITY ANALYST

Cybersecurity-focused IT Security Support Engineer with hands-on experience in Microsoft 365 security, Microsoft Entra ID, FortiGate firewalls, endpoint protection, phishing investigation, identity and access management, and security operations. Based in Dubai, UAE and immediately available for SOC Analyst, Cybersecurity Analyst, Security Operations Analyst, and Junior Security Engineer opportunities.

Muhammed Ali — IT Security Support Engineer and Cybersecurity Analyst
500+
Enterprise Users Supported
200+
Security Trained Staff
15+
IT & Security Support Tickets Resolved Daily
About Me

Professional Profile

Muhammed Ali
MUHAMMED ALI
IT SECURITY SUPPORT ENGINEER
AVAILABLE IMMEDIATELY
DUBAI, UAE

Professional Profile

Cybersecurity-focused IT Security Support Engineer with hands-on experience securing Microsoft 365 environments, managing Microsoft Entra ID, administering FortiGate firewalls, investigating phishing incidents, monitoring endpoint protection, enforcing access controls, and supporting enterprise users. My current role combines IT support with substantial cybersecurity responsibilities, and I am actively pursuing a dedicated SOC or cybersecurity operations position.

SOC Operations
Monitoring security alerts, triaging endpoint and authentication events, and supporting incident response activities.
Perimeter Security
Configuring firewall rules, managing VPN topologies, and preventing intrusion attempts.
ACTIVE OBJECTIVE:

Currently pursuing the Microsoft SC-200 (Security Operations Analyst) certification. Actively seeking dedicated SOC Analyst, Cybersecurity Analyst, Security Operations Analyst, and Junior Security Engineer opportunities in the UAE.

Key Achievements

  • Supported security operations for 500+ enterprise users
  • Delivered cybersecurity awareness training to 200+ employees
  • Managed FortiGate firewalls
  • Administered Microsoft 365 & Entra ID
  • Implemented MFA and Conditional Access
  • Conducted vulnerability assessments and penetration testing
  • Managed endpoint protection using Acronis Cyber Protect Cloud
Security Assessment Protocols

Security Projects

WEB APPLICATION VAPT COMPLETED

Real-World Assessment

  • Conducted comprehensive vulnerability assessments on live internal web applications to identify operational flaws.
  • Identified critical OWASP Top 10 security vulnerabilities including misconfigurations, broken access controls, and sensitive data exposures.
  • Delivered detailed remediation reports with prioritized recommendations to stakeholders to secure codebases.
NETWORK SECURITY ASSESSMENT COMPLETED

Infrastructure Audit

  • Performed detailed internal network scanning and network traffic analysis to inspect core routing nodes.
  • Utilized monitoring tools to isolate active open ports, deprecated and weak protocols, and security misconfigurations.
  • Recommended and formulated security hardening roadmaps, emphasizing firewall rule optimization and network segmentation.
COMPUTER VISION / IOT PROTOTYPE PROTOTYPE

Smart Desk with Robotic Assistance for Students

  • Developed AI-powered posture detection and emotion recognition modules using Python and OpenCV to support student well-being.
  • Implemented prototype logic for parent monitoring and robotic assistance modules, extending the system toward assistive automation.
Field Investigations

Case Studies

In-depth write-ups of real security investigations — walking through the alert, the analysis, and the response. Client and organizational details have been generalized to protect confidentiality.

EMAIL SECURITY / PHISHING RESOLVED

When Zero Detections Didn't Mean Safe

Investigating a Microsoft 365 Credential Harvesting Attack — A suspicious email with a PDF attachment had clean VirusTotal reputation, but sandboxed VM analysis revealed a convincing M365 credential harvesting clone.

THREAT INTEL / REPUTATION RESOLVED

The Reputation Was Wrong

Investigating a False Positive Domain Detection on VirusTotal — 3 out of 91 vendors flagged a domain. Structured historical DNS and IP analysis proved the detections stemmed from legacy shared hosting infrastructure.

Interactive Profile

Profile Navigator

Use the read-only commands below to explore portfolio information. This interface is a navigation feature; it does not execute system or security commands.

mali@portfolio:~ (read-only navigator)
Interactive
Muhammed Ali Portfolio Navigator [Version 1.1]
Read-only profile interface — no system commands are executed.
 
Type help to display a list of available security commands, or click any command in the sidebar.
 
mali@portfolio:~$
Professional Experience

Professional Experience

SEP 2025 – PRESENT

IT Security & Support Engineer

Sahhim Trading and Technology
Dubai, UAE

Provide L1/L2 IT support to 500+ users across multiple client environments through managed IT support contracts, while also supporting security administration and investigations. Security responsibilities include Microsoft 365 and Entra ID security, FortiGate administration, endpoint protection, access controls, alert review, and phishing response. Resolve an average of 15+ IT and security support tickets daily.

FortiGate Firewall Administration

Managed, configured, and optimized FortiGate enterprise firewalls (40F, 80F, and 100F series). Configured firewall policies, IPS, antivirus, web filtering, application control, SSL inspection, and IPsec VPNs.

M365 & Entra ID Security Management

Administered Microsoft 365, Entra ID (formerly Azure AD), and Microsoft 365 Defender settings for 500+ active seats. Enforced Multi-Factor Authentication (MFA), Conditional Access policies, managed role assignments (RBAC), and conducted mailbox auditing and phishing quarantine remediation.

Endpoint Security Enforcement

Deployed, monitored, and managed endpoint protection systems across all company devices using Acronis Cyber Protect Cloud. Investigated malware detections and endpoint security alerts, configured patch management schedules, and implemented backup & disaster recovery profiles.

L1/L2 Technical Support

Provided L1/L2 technical support for Microsoft 365 services, including Outlook configuration, email delivery issues, Office applications, user authentication, and access-related troubleshooting.

Cybersecurity Awareness Training

Created material and conducted training sessions for over 200 employees, improving employee awareness of phishing, social engineering, and secure data handling practices.

Technical Skills

Technical Skills

Security Operations

Vulnerability Assessment Penetration Testing Web Application Security Security Monitoring Incident Response Awareness Security Awareness Training

Security Solutions

FortiGate Firewall IPS & Web Filtering Application Control Anti-Malware Endpoint Security Identity & Access Management (IAM) Policy Management

Microsoft Technologies

Microsoft 365 Administration Microsoft Entra ID Exchange Online MFA Configuration User & License Management

Networking

TCP/IP DNS & DHCP VPN Routing & Switching Fundamentals Network Troubleshooting

Security & Network Tools

Nmap Burp Suite Wireshark Nessus Kali Linux Splunk ELK Stack

Endpoint & Backup Security

Acronis Cyber Protect Cloud Endpoint Protection Malware Detection Patch Management Backup & Disaster Recovery 3CX Backup & Restore
Academic History

Education

B.Tech in Computer Science and Engineering

APJ Abdul Kalam Technological University
Kerala, India
2021 – 2025

Acquired solid foundational knowledge in computing architectures, data structures, network communications, operating systems engineering, and cryptography principles.

Professional Credentials

Certifications

Industry-validated credentials in offensive security, IT fundamentals, and active pursuit of SOC analyst certification.

3 Earned Credentials
1 In Progress
4 Total Tracked
ACTIVE CREDENTIAL

CEH

Certified Ethical Hacker · EC-Council

Credential covering ethical hacking methodology, reconnaissance, scanning, system security, web security, malware concepts, and cryptography.

Certificate: ECC6784352019 Expires: August 2028
EARNED

CPT

Certified Penetration Tester · RedTeam Hacker Academy

Training and assessment in penetration-testing methodology, vulnerability validation, exploitation fundamentals, and reporting.

Credential ID: RTXSTU135608698
VERIFIED ON CREDLY

Google IT Support

Google IT Support Professional Certificate (v.3) · Google

IT support credential covering troubleshooting, operating systems, networking, system administration, directory services, and security fundamentals.

IN PROGRESS

Microsoft SC-200

Security Operations Analyst · Microsoft

Exam preparation focused on Microsoft Sentinel, Defender XDR, incident triage, threat hunting, and KQL.

Status: Exam preparation in progress Target: 2026
Communication

Languages

English

PROFESSIONAL PROFICIENCY

Malayalam

NATIVE / BILINGUAL

Hindi

BASIC UNDERSTANDING

Tamil

BASIC UNDERSTANDING
Get In Touch

Get in Touch

Reach out directly using any of the channels below — I typically respond within 24 hours.

OPEN TO SOC, CYBERSECURITY ANALYSIS & SECURITY OPERATIONS ROLES
DUBAI, UAE
THREAT INTEL
The first computer virus, "Creeper", appeared in 1971 — decades before the term "malware" existed. // The vast majority of successful cyberattacks still begin with a simple phishing email. // A long, random 12+ character password can take modern computers centuries to brute-force. // "Firewall" was borrowed from construction — a wall built to stop fire from spreading between buildings. // White hat hackers are ethical professionals who test systems with permission to find flaws before criminals do. // Organizations often take well over 200 days on average to detect a data breach. // A SOC (Security Operations Center) monitors, detects, and responds to threats around the clock, every day of the year.