Open to Security Engineer roles

Owner: Constantin Ududec

Security Engineer focused on detection, response and automation in cyber security.

This is my online CV, built to present clearly who I am, what I do, and how I contribute inside modern cyber security environments.

3+ Years across security operations and engineering
10+ Platforms and tools used in monitoring and response
14+ Certifications, badges and technical training records
SOC Focus Monitoring active
Triage

Alert review, prioritization and incident validation.

Investigation

Context building across SIEM, EDR and case management.

Response

Containment playbooks and cleaner analyst workflows.

Quick profile

Security Status Operational
Detection 97%

Signal confidence across active monitoring flows.

Response Auto

Playbook-driven triage and containment ready.

Threat Feed 4 live

Correlated events moving through the defense scene.

Portrait of Constantin Ududec
Photo Preview
Sec Security engineering, incident analysis and detection across operational environments
2022 Professional experience in security operations and engineering
SOAR Automation, playbooks and workflows for investigation and response

Constantin Ududec, owner of this profile and a Security Engineer focused on cyber defense.

I work with structured security processes, log analysis, incident investigation and operational automation designed for faster and cleaner response workflows.

Core areas where I bring value as a Security Engineer

Security Monitoring

Monitoring alerts and correlating events to identify suspicious activity quickly and accurately.

Incident Analysis

Analyzing technical context, prioritizing incidents and escalating correctly when the situation requires it.

Detection Engineering

Building, tuning and optimizing rules and workflows for stronger detections and less operational noise.

Three areas that define how I work inside modern security environments

01

Investigation-first mindset

I focus on context, signal quality and clear decision-making when moving from alert to validated incident handling.

02

Automation with purpose

I use SOAR and workflow thinking to remove repetitive analyst work and make response processes more consistent.

03

Detection and tuning discipline

I care about improving detections, reducing false positives and making tooling easier to trust during real investigations.

Platforms and tools I use across monitoring, detection and response workflows

Operational tooling across SIEM, EDR, SOAR and case management

My workflow sits at the intersection of security visibility, detection tuning, incident investigation and response automation.

SIEM

Wazuh

SOAR

Cortex XSOAR

EDR

Microsoft Defender

EDR

CrowdStrike Falcon

Case Mgmt

TheHive

Detection

Praeco

Analytics

Exabeam

Endpoint

SentinelOne

Endpoint

Palo Alto EDR

Network

Security Onion

The area where I combine security analysis with automation and operational workflows

SOAR Automation

Cortex XSOAR, playbooks and response workflows

I worked with automation for incident response and playbook execution, helping create workflows that are faster, more consistent and easier to follow.

Incident Analysis

Investigation, triage and technical context

Alert analysis, severity assessment and case investigation to identify real impact and the actions required.

Detection Work

Rules, tuning and false positive reduction

Tuning detection rules and improving correlations to raise signal quality across monitoring environments.

Capabilities I highlight across security engineering work

  • Incident response automation and playbook execution through Cortex XSOAR.
  • Initial incident investigation and escalation of complex cases.
  • Threat hunting and behavioral analysis across EDR and SIEM platforms.
  • Design and fine-tuning of detection rules in platforms such as Praeco.
  • Event correlation and case management workflows in TheHive.

Publicly verified experience adapted for a Security Engineer profile

08.2022 - Present

Security Operations Center Analyst

Expertware, Suceava, Romania. Continuous monitoring of security alerts generated by SIEM, IDS/IPS and firewalls, including triage, analysis and initial investigation of security incidents.

Responsibilities

Incident response, threat analysis and automation

Alert severity analysis, escalation of complex cases, root cause investigation, plus operational automation for response workflows.

Tooling

SIEM, EDR, SOAR and analytics

Microsoft Defender, Wazuh, SiemBiot, Praeco, TheHive, CrowdStrike Falcon, Cortex XSOAR, Exabeam, SentinelOne, Palo Alto EDR and Security Onion.

What stands out from the publicly available experience

  • Analysis and triage of security events to determine severity and urgency.
  • Initial investigation and incident response support in enterprise environments.
  • Threat hunting, behavioral analysis and event correlation across multiple tools.
  • Creation and tuning of detection rules to reduce false positives.
  • Operational collaboration and mentoring to improve SOC team efficiency.

Professional path across security, operations and support roles

Aug 2022 - Present

Security Operations Center Analyst

Expertware

Suceava, Romania

Log analysis, Microsoft Defender and security operations workflows.

Apr 2022 - Aug 2022

Assistant Manager

IConta 24

Operational support, coordination and day-to-day business assistance.

Apr 2021 - Aug 2021

Technical Department

Oficiul de Cadastru si Publicitate Imobiliara

Suceava, Romania

Technical support responsibilities inside an administrative environment.

Academic background that supports my technical and analytical foundation

2018 - 2022

Stefan cel Mare University of Suceava

Bachelor's Degree, Computer Science

2013 - 2017

Colegiul National Stefan cel Mare Suceava

Bacalaureat, Mathematics and Computer Science

Case-study style highlights that show how I think, investigate and automate

SOAR Workflow

Response automation with Cortex XSOAR

Built around the idea of reducing repetitive analyst work through cleaner playbooks, faster triage and more consistent response handling.

Focused on standardizing response steps, reducing analyst friction and making repetitive workflows easier to execute and review.

Detection Tuning

Improving signal quality and reducing false positives

Focused on refining rules, correlations and alert logic so investigations start from better quality detections.

The goal was cleaner alerts, better prioritization and less wasted time for analysts handling noisy security events.

Investigation Flow

Threat analysis across SIEM, EDR and case platforms

Worked across tools such as Wazuh, TheHive, Defender and Exabeam to connect context quickly and move incidents forward with clarity.

Built around fast context gathering, evidence correlation and clearer case progression from alert to validated incident handling.

Certifications and badges that reflect my hands-on path across security operations, automation and analysis

Fortinet Badge

Fortinet Certified Associate Cybersecurity

View credential
Exabeam Verified

Working with Context and Parsing in Log Stream

Open certificate
Exabeam Verified

Investigating Threats with Advanced Analytics

Open certificate
Palo Alto / Udemy Certificate

Cortex XSOAR 6 Security Orchestration and Automation Course

Open certificate
Microsoft Credential

Microsoft Security, Compliance, and Identity Fundamentals

View credential
Cisco Badge

Cisco Certified CyberOps Associate

View badge
IC3 No public link

IC3 Key Applications - Global Standard 4

Issued May 2015

IC3 No public link

IC3 GS4 - Key Applications

Internet and Computing Core Certification

IC3 No public link

IC3 GS4 - Living Online

Issued June 2015

IC3 No public link

IC3 Certification - Global Standard 4

Issued November 2015

Exabeam Offline copy

2 additional Exabeam certificates

Available as PDF copies and ready to be added once you send the final names or links.

Available for opportunities in cyber security, detection and security engineering.

Open to Security Engineer, SOC, detection engineering and automation-focused roles. Reach out through email or connect with me on the platforms below.

Location Suceava, Romania
Languages Romanian / English