Ugonna Ezenekwe.

Secure // Analyse // Comply

UGONNA
EZENEKWE

Aspiring GRC Analyst assembling the full compliance picture, piece by piece: security controls audits, risk assessments and incident reports mapped to NIST CSF, PCI DSS, GDPR and SOC frameworks.

[ OPEN TO WORK / LONDON, UK / REMOTE, HYBRID OR ONSITE ]

0

Security Audits

0

Incident Reports

0

Journal Case Logs

0

Frameworks Applied

[ // Profile ]

About

Cybersecurity · GRC · Security Operations · Internal Audit

I'm an aspiring cybersecurity and GRC analyst with a BSc in Sociology with Criminology.

I've built a portfolio of hands-on projects mirroring real analyst work: internal security audits assessed against NIST CSF, PCI DSS and GDPR with risk registers and remediation roadmaps, incident investigations using tcpdump and Wireshark tracing attack chains across DNS and HTTP traffic, SOC analyst simulation training triaging alerts across SIEM, XDR and firewall consoles, and a home lab running an Ubuntu virtual machine with Splunk for log monitoring and alert triage.

My background adds strong communication, something many entry level candidates lack. Through my research internship at Reimagining Criminal Justice C.I.C. I drafted correspondence for senior stakeholders, and my criminology degree trained me to analyse risk and evidence, skills that matter in GRC, where translating findings for non-technical audiences is half the job.

I'm seeking entry level roles in GRC, compliance analysis, security operations or internal audit, and I'm available to work remote, hybrid or onsite.

[ 01 / Experience ]

Security and research experience.

May 2026 to Present

Home SOC Lab (Splunk / Ubuntu) · Independent

Built and maintained an Ubuntu security lab running Splunk and tcpdump on the command line, equipping virtual machines, managing packages and resolving boot and configuration failures to keep the environment running. Triaged alerts across simulated incidents including brute force, ransomware, phishing and data exfiltration, applying the NIST incident response lifecycle to document detection and containment. Analysed captured traffic with Wireshark and tcpdump to identify SYN flood and ICMP flood denial of service attacks, tracing a high volume of half opened TCP connections from a single source IP to root cause.

June 2026 to Present

SOC Analyst Simulation Training (SOCSimulator / LetsDefend) · Independent

Completed alert triage and investigation exercises across simulated SIEM, XDR and firewall consoles, prioritising alerts by severity and context and correlating events into attack narratives. Documented each investigation using structured session and case report templates, recording findings, evidence and response decisions in a consistent format.

May 2026 to Present

Security Control and Compliance Audits · Independent

Conducted internal audits of two simulated organisations across retail and healthcare contexts, assessed against PCI DSS, UK GDPR, SOC and NIST CSF, covering asset inventory, control gap identification and risk register development. Delivered written audit reports and remediation roadmaps presenting prioritised findings to technical and non-technical audiences.

Jan 2025 to Apr 2025

Justice Research and Communications Intern · Reimagining Criminal Justice C.I.C.

Maintained a structured stakeholder database of over 50 national and international organisations, drafted professional outreach correspondence on behalf of senior staff, and distilled complex documents into concise summaries for senior decision-makers.

[ 02 / Education ]

Academic and professional training.

Degree

BSc Sociology with Criminology · Middlesex University

Grounding in structured analysis, research methods and clear written communication, applied directly to risk assessment and governance documentation.

Certification

Google Cybersecurity Professional Certificate · Coursera

In progress, expected 2026. Completed: Foundations of Cybersecurity, Play It Safe: Managing Security Risk, and Connect and Protect: Networks and Network Security. Certificates are verifiable in the certifications section below.

[ 03 / Audit Case Studies ]

Controls audits, risk registers and incident reports.

GitHub profile →
SOC Simulation · Alert Triage [ True Positive · Host Contained ]

Phishing Defence & Malware Containment

LetsDefend SOC simulation · Alert SOC114 · June 2026

Objective

Investigate a high priority alert for a malicious attachment and establish whether the host was actually compromised rather than merely targeted.

Evidence

Equation Editor spawned by Excel retrieving an executable over plain HTTP, confirming exploitation of CVE-2017-11882 rather than inferring it.

Method

Correlated email delivery, process activity and network traffic into a single timeline, ending at an encrypted channel to a known command and control server.

Outcome

Host isolated 27 minutes after delivery, before exfiltration or lateral movement, with indicator blocking, credential reset and patch verification recommended.

Vendor Risk · Tooling [ Python ]

Third Party Risk Questionnaire Scorer

Independent · Hackathon build · September 2026

Objective: Turn vendor questionnaire responses into a consistent, defensible risk score, rather than a reviewer's judgement call on a spreadsheet.

Build: A Python scoring engine behind a Streamlit interface, with a 40 question control set mapped to NIST CSF 2.0 and ISO/IEC 27001:2022 Annex A.

Outcome: Each response maps to its control reference and weighted score, so two reviewers assessing the same vendor reach the same result and can show why.

Controls & Compliance Audit [ High Gaps ]

Botium Toys Security Audit

Independent · Retail scenario · May 2026

Objective: Assess the full security programme of a growing e-commerce retailer against PCI DSS, GDPR and SOC expectations.

Gaps: No least privilege or separation of duties, unencrypted cardholder data, and no formal disaster recovery plan.

Outcome: Risk register plus a prioritised remediation plan covering encryption, IDS deployment and password policy.

Incident Report · NIST CSF [ Availability ]

DoS Incident Analysis: ICMP Flood

Independent · July 2026

Objective: Analyse a two hour internal network outage caused by a sustained ICMP flood and structure the full response using the five NIST CSF functions.

Root cause: An unconfigured perimeter firewall with no rate limiting or filtering allowed the flood straight into the internal network.

Outcome: Documented ICMP rate limiting, source IP verification, network monitoring and IDS/IPS controls, with a staged recovery playbook restoring critical services first.

[ Repository ]
Incident Report · OS Hardening [ Access Control ]

Brute Force Attack & Malicious Redirect

Independent · July 2026

Objective: Investigate a compromised recipe website luring visitors into downloading malware that redirected them to a spoofed domain.

Method: Replicated the attack in a sandboxed VM and traced the full chain across DNS and HTTP tcpdump logs, confirming a brute force takeover of a default admin password.

Outcome: Formal incident report recommending a strong password policy, multi factor authentication and login attempt limits.

Network Traffic Analysis [ DNS ]

Wireshark DNS Outage Investigation

Independent · July 2026

Objective: Diagnose why customers could not reach a website, working from packet captures rather than assumptions.

Findings: Repeated UDP requests to port 53 returned ICMP "port unreachable" errors, isolating the fault to a DNS server that was down or blocked.

Outcome: Structured incident report separating evidence from interpretation and setting out the next investigative steps.

End-to-End Internal Audit [ Healthcare Scenario ]

Meridian Health Partners Controls Audit

Independent practice project · May to June 2026

Objective: Run a full internal audit for a fictional mid-size healthcare company, from asset inventory through to remediation roadmap.

Scope: Threat likelihood, control gap identification and risk register development across administrative, technical and physical control categories.

Outcome: Written audit report presenting prioritised findings to technical and non-technical audiences, aligned to NIST CSF.

[ 04 / Incident Handler's Journal ]

Four incident response cases, one consistent method.

A completed log of incident response cases written while building SOC analyst skills. Every entry uses the same format: description, tools used, the 5 W's and follow-up notes, tagged with the matching NIST Incident Response Lifecycle phase. All company names, people, IP addresses and file hashes are fictitious and written for practice.

Business email compromise attempt

Description · The accounts payable team at a mid-sized architecture firm flagged an email requesting an urgent change to a vendor's payment routing number. The message impersonated a known supplier and was investigated as a suspected business email compromise (BEC) attempt.

Tools used · Email header analyser (message trace with SPF, DKIM and DMARC results), domain age lookup (WHOIS).

The 5 W's · An external actor spoofed the domain of a long-standing HVAC supplier from a look-alike domain registered nine days earlier, with the digit "1" substituted for the letter "l". The email arrived at 8:47 AM in the accounts payable inbox on the corporate Microsoft 365 tenant and was flagged by the clerk nine minutes later. No payment was released, so no compromise beyond the phishing attempt itself occurred.

Additional notes

Header analysis: SPF = fail, DKIM = none. Domain registered via a privacy-proxy registrar 9 days prior.

Actions taken: blocked sender domain at the mail gateway, notified the real supplier out-of-band, added a payment-change verification step (call-back to a known number) to the AP procedure.

Open question: should look-alike domain monitoring be added for the top 20 vendors?

Ransomware via exposed RDP

Description · A file-encrypting ransomware variant was detected on two servers at a regional logistics company after an exposed remote desktop (RDP) port was brute-forced. The case covers containment through recovery.

Tools used · EDR alert console, firewall and VPN logs, offline backup restore procedure.

The 5 W's · An unattributed actor gained access via credential-stuffing against an internet-facing RDP endpoint (port 3389 left open on a warehouse management server). After roughly 40 minutes of repeated login attempts starting at 1:31 AM, the attacker authenticated with a weak local admin password, disabled the endpoint agent and deployed a payload that encrypted shared drives on two on-premises Windows servers. Encryption activity triggered an EDR alert at 2:14 AM. The port had been left exposed without MFA or IP allowlisting after a vendor's temporary remote-support setup was never rolled back.

Additional notes

Containment: isolated both hosts from the network, closed RDP at the perimeter firewall, rotated all local admin credentials.

Recovery: restored affected shares from the previous night's offline backup (4-hour data loss window). No ransom paid.

Follow-up: audit all firewall rules for other temporary vendor-access exceptions; require MFA on any remote administration path going forward.

Departing employee data removal

Description · A departing employee at a software company copied a customer contract archive to a personal USB drive three days before their resignation date. The case was reviewed for policy violation and closed out with process recommendations.

Tools used · DLP (data loss prevention) alert log, endpoint USB device history, HR offboarding checklist.

The 5 W's · A sales operations employee who had submitted their resignation but remained on payroll for a two-week transition period triggered a DLP rule with a bulk transfer of a shared drive folder containing signed customer contracts to an unregistered USB device at 4:05 PM, three business days before their last day, on a company-issued laptop on-site. USB storage was not blocked by policy for the role, and departing-employee monitoring was not yet in place until the final offboarding day.

Additional notes

Resolution: HR and legal were looped in; the employee confirmed and deleted the copy under supervision as a condition of a clean separation.

Process gap: departing-employee monitoring should begin at resignation notice, not on the last working day.

Recommendation: block removable storage by default for roles with access to customer contract data, with exceptions granted case-by-case.

Misconfigured cloud storage bucket

Description · A misconfigured cloud storage bucket belonging to a health-and-wellness app was found publicly listable by an external security researcher, who reported it through the company's disclosure programme before any confirmed misuse.

Tools used · Cloud provider access logs, bucket policy and IAM review, responsible-disclosure intake ticket.

The 5 W's · No malicious actor was identified. The exposure was traced to an internal engineering change that set a storage bucket's access policy to public during a migration, caught and reported responsibly before confirmed misuse.

Why this entry matters

Detection and analysis is not only about attackers. Configuration drift during routine engineering work is one of the most common causes of real-world data exposure.

The journal applies the same 5 W's discipline whether the cause is an adversary, an insider or an honest mistake.

[ 05 / SOC Monitor ]

The analyst's view, running live.

A recreation of the incident review workflow practised in the home lab: triage summaries, alert volume and a rolling notables feed. Every value on this board is synthetic and generated in your browser, the way a training range would present it.

SOC Monitor // Home Lab SIEM
[ Simulated Data ]

Urgency

0

Low

Medium

High

Critical

Status

0

New

In progress

Resolved

Closed

Security Domain

0

Network

Access

Endpoint

Threat / Audit

Events / Min

0Notables

Threat Level

Safe

Auto-assessed from open notables

Critical
8%
High
18%
Medium
34%
Low
26%
Safe / Info
14%
TimeTitleUrgency
Sources: LAB-UBU02 · LAB-WIN01 · perimeter-fw // ubuntu home lab · siem tooling · alert triage