Profile
Constantin Ududec, owner of this profile and a Security Engineer focused on cyber defense.
I work with structured security processes, log analysis, incident investigation and operational automation designed for faster and cleaner response workflows.
Skills
Core areas where I bring value as a Security Engineer
Security Monitoring
Monitoring alerts and correlating events to identify suspicious activity quickly and accurately.
Incident Analysis
Analyzing technical context, prioritizing incidents and escalating correctly when the situation requires it.
Detection Engineering
Building, tuning and optimizing rules and workflows for stronger detections and less operational noise.
Highlights
Three areas that define how I work inside modern security environments
Investigation-first mindset
I focus on context, signal quality and clear decision-making when moving from alert to validated incident handling.
Automation with purpose
I use SOAR and workflow thinking to remove repetitive analyst work and make response processes more consistent.
Detection and tuning discipline
I care about improving detections, reducing false positives and making tooling easier to trust during real investigations.
Tool Stack
Platforms and tools I use across monitoring, detection and response workflows
Operational tooling across SIEM, EDR, SOAR and case management
My workflow sits at the intersection of security visibility, detection tuning, incident investigation and response automation.
Wazuh
Cortex XSOAR
Microsoft Defender
CrowdStrike Falcon
TheHive
Praeco
Exabeam
SentinelOne
Palo Alto EDR
Security Onion
Engineering
The area where I combine security analysis with automation and operational workflows
Cortex XSOAR, playbooks and response workflows
I worked with automation for incident response and playbook execution, helping create workflows that are faster, more consistent and easier to follow.
Investigation, triage and technical context
Alert analysis, severity assessment and case investigation to identify real impact and the actions required.
Rules, tuning and false positive reduction
Tuning detection rules and improving correlations to raise signal quality across monitoring environments.
Publicly verified
Capabilities I highlight across security engineering work
- Incident response automation and playbook execution through Cortex XSOAR.
- Initial incident investigation and escalation of complex cases.
- Threat hunting and behavioral analysis across EDR and SIEM platforms.
- Design and fine-tuning of detection rules in platforms such as Praeco.
- Event correlation and case management workflows in TheHive.
Experience
Publicly verified experience adapted for a Security Engineer profile
Security Operations Center Analyst
Expertware, Suceava, Romania. Continuous monitoring of security alerts generated by SIEM, IDS/IPS and firewalls, including triage, analysis and initial investigation of security incidents.
Incident response, threat analysis and automation
Alert severity analysis, escalation of complex cases, root cause investigation, plus operational automation for response workflows.
SIEM, EDR, SOAR and analytics
Microsoft Defender, Wazuh, SiemBiot, Praeco, TheHive, CrowdStrike Falcon, Cortex XSOAR, Exabeam, SentinelOne, Palo Alto EDR and Security Onion.
Highlights
What stands out from the publicly available experience
- Analysis and triage of security events to determine severity and urgency.
- Initial investigation and incident response support in enterprise environments.
- Threat hunting, behavioral analysis and event correlation across multiple tools.
- Creation and tuning of detection rules to reduce false positives.
- Operational collaboration and mentoring to improve SOC team efficiency.
Career Timeline
Professional path across security, operations and support roles
Security Operations Center Analyst
Expertware
Suceava, Romania
Log analysis, Microsoft Defender and security operations workflows.
Assistant Manager
IConta 24
Operational support, coordination and day-to-day business assistance.
Technical Department
Oficiul de Cadastru si Publicitate Imobiliara
Suceava, Romania
Technical support responsibilities inside an administrative environment.
Education
Academic background that supports my technical and analytical foundation
Stefan cel Mare University of Suceava
Bachelor's Degree, Computer Science
Colegiul National Stefan cel Mare Suceava
Bacalaureat, Mathematics and Computer Science
Projects
Case-study style highlights that show how I think, investigate and automate
Response automation with Cortex XSOAR
Built around the idea of reducing repetitive analyst work through cleaner playbooks, faster triage and more consistent response handling.
Improving signal quality and reducing false positives
Focused on refining rules, correlations and alert logic so investigations start from better quality detections.
Threat analysis across SIEM, EDR and case platforms
Worked across tools such as Wazuh, TheHive, Defender and Exabeam to connect context quickly and move incidents forward with clarity.
Certifications
Certifications and badges that reflect my hands-on path across security operations, automation and analysis
Credential wall
Real badges, verified links and issuer-backed credentials
A curated certification section built from your actual badge links, with stronger visuals, cleaner spacing and more motion on hover.
Fortinet Certified Associate Cybersecurity
View credentialFortinet FortiGate 7.6 Operator
View credentialIntroduction to the Threat Landscape 3.0
View credentialWorking with Context and Parsing in Log Stream
Open certificateInvestigating Threats with Advanced Analytics
Open certificateUsing Advanced Analytics
Open certificateRule Tuning for Advanced Analytics
Open certificateCortex XSOAR 6 Security Orchestration and Automation Course
Open certificateMicrosoft Security, Compliance, and Identity Fundamentals
View credentialCisco Certified CyberOps Associate
View badgeIC3 Key Applications - Global Standard 4
Issued May 2015
IC3 GS4 - Key Applications
Internet and Computing Core Certification
IC3 GS4 - Living Online
Issued June 2015
IC3 Certification - Global Standard 4
Issued November 2015
2 additional Exabeam certificates
Available as PDF copies and ready to be added once you send the final names or links.
Contact
Available for opportunities in cyber security, detection and security engineering.
Open to Security Engineer, SOC, detection engineering and automation-focused roles. Reach out through email or connect with me on the platforms below.