This is a plain, single-column, ATS-friendly version of this resume — no tables, no multi-column layout,
built to parse cleanly through applicant tracking systems. Print this page to PDF (Ctrl/Cmd+P) when applying.
For the full portfolio-styled version, see
inksec.io/resume.
Tate Pannam
SOC Analyst | Blue Team | Threat Detection
tate@inksec.io | 0491 600 241 | inksec.io | Melbourne, Australia — Remote-ready
Professional Summary
- Cybersecurity practitioner transitioning into Security Operations Center (SOC) roles with hands-on experience across threat detection, log analysis, incident triage, and MITRE ATT&CK mapping.
- Background in offensive security (penetration testing certifications) provides attacker-behaviour context that directly improves detection accuracy and alert quality.
- Completed Cert IV in Cyber Security (Victoria University), a nationally recognised AQF qualification, with a TAFE medal nomination.
- Maintains a public portfolio (inksec.io) documenting 118+ Security Information and Event Management (SIEM) alert investigations and 174+ full digital forensics and incident response (DFIR) lab writeups, mapped across 95+ unique MITRE ATT&CK techniques.
Technical Skills
Detection & Monitoring
- Alert triage and escalation workflows
- Windows Event Log and Sysmon telemetry analysis
- Linux audit log and authentication log investigation
- Security Information and Event Management (SIEM) log ingestion, normalisation, and correlation
- DNS / HTTP / TLS traffic pattern analysis
- Anomaly detection: process trees, persistence mechanisms
- MITRE ATT&CK technique mapping
- Cloud logging fundamentals (AWS CloudTrail, Identity and Access Management (IAM))
Incident Response
- Alert validation, Indicator of Compromise (IOC) identification, containment
- PowerShell abuse, scheduled task, and registry Run key analysis
- Incident timeline construction and documentation
- Memory forensics (Volatility 3)
- Network forensics (Wireshark, Zeek, Suricata)
- Open-Source Intelligence (OSINT) pivoting and IOC enrichment
Offensive Security Knowledge (Detection Context)
- Web attack patterns: SQL Injection (SQLi), Local File Inclusion (LFI), Remote Code Execution (RCE), Insecure Direct Object Reference (IDOR), Server-Side Request Forgery (SSRF)
- Active Directory (AD) attack paths: Kerberoasting, Pass-the-Hash, ESC1 certificate abuse
- Attacker tooling familiarity: Mimikatz, Impacket, PsExec
- Privilege escalation and post-exploitation behaviour patterns
Tools & Platforms
- SIEM: Splunk, Wazuh, Elastic SIEM
- Network analysis: Wireshark, Zeek, Suricata, Snort
- Forensics: Volatility 3, Autopsy, FTK Imager, NetworkMiner
- Endpoint telemetry: Sysmon with the SwiftOnSecurity ruleset
- Scripting: Bash, Python (intermediate)
Certifications
- CDSA – Certified Defensive Security Analyst — Hack The Box (Completed)
- SAL1 – SOC Analyst Level 1 — TryHackMe (Completed)
- SOC Analyst Learning Path — LetsDefend / HTB (Completed)
- AWS Academy Cloud Foundations — AWS Academy (Completed)
- CPTS – Certified Penetration Testing Specialist — Hack The Box (Completed)
- CWES – Certified Web Exploitation Specialist — Hack The Box (Completed)
- BSCP – Burp Suite Certified Practitioner — PortSwigger (Completed)
- eJPT – Junior Penetration Tester — INE (Completed)
- ICCA – INE Certified Cloud Associate — INE (Completed)
- BTL1 – Blue Team Level 1 — Security Blue Team (Completed)
- CDL1 – Certified CyberDefender Level 1 — CyberDefenders (Completed)
- CDCA – Cyber Defense Certified Analyst — Level Effect (Completed)
- Cert IV in Cyber Security — Victoria University (Completed)
- MS SC-200 — Microsoft Learn (In Progress)
Projects & Portfolio
inksec.io — public Blue Team SOC portfolio, updated daily.
- Daily investigations: 118+ LetsDefend SIEM alerts triaged using the 5W methodology, documented with MITRE ATT&CK mapping.
- Lab writeups: 174+ CyberDefenders and Blue Team Labs Online (BTLO) labs covering memory forensics, network analysis, OSINT, DFIR, and malware investigation.
- CyberDefenders leaderboard: ranked #4 globally, #1 in Australia (1273 points).
- Blue Team Labs Online (BTLO) leaderboard: ranked #6 globally, #2 in Australia (1280 points).
- YouTube series: live investigation walkthroughs as part of the "Day N of Becoming a SOC Analyst" series.
- Custom tooling: built Python data pipelines powering a searchable command reference, auto-generated lab index, and MITRE ATT&CK heatmap on inksec.io.
Professional Experience
Freelance IT & Digital Systems Consultant — Thailand
2011 – 2024
- Managed end-to-end IT infrastructure for multiple small-business clients, including hosting, DNS, SSL, and access controls, serving as the sole security and systems contact for each account.
- Identified and responded to bot attacks, brute-force attempts, and outages through log-based analysis, restoring services and documenting root causes to prevent recurrence.
- Deployed monitoring and alerting across client systems, enabling proactive detection of malware and misconfigurations before they escalated to outages.
IT Helpdesk Support & Team Manager — Primus Telecom, Melbourne
2002 – 2010
- Delivered Level 1 / Level 2 technical support across broadband, VoIP, and email for a national customer base, resolving high call-volume queues consistently within Service Level Agreement (SLA) targets.
- Diagnosed complex network faults, including authentication failures, packet loss, and DNS issues, using modem and router telemetry to identify root causes and reduce repeat contacts.
- Led a team of 15+ support agents, exceeding key performance indicator (KPI) targets and building training materials and a knowledge base that improved first-call resolution across the team.
- Coordinated complex fault escalations with the Network Operations Center (NOC), correlating service data across systems to accelerate resolution of outages affecting multiple customers.
Education
- Cert IV in Cyber Security — Victoria University — Completed 2026 (TAFE Medal Nomination)
- Cert IV in Information Technology — Computer Power St Kilda — Completed