Aspiring SOC Analyst with a BSc in Computer Systems Engineering, Google Cybersecurity certification, and a passion for threat detection, incident response, and securing digital infrastructure.
$ status: ACTIVE | role: SOC_ANALYST | ops: OPEN_TO_REMOTE
// About Me
Born and raised in Harare, Zimbabwe, I graduated from Midlands State University with a BSc Honours (2.1) in Computer Systems Engineering — building a rigorous technical foundation in networking protocols, operating systems, software engineering, and computer architecture.
My focus in cybersecurity combines an adversary-aware mindset with structured defensive engineering. I hold the Google Cybersecurity Professional Certificate, completed the ALX 13-week Cybersecurity Programme, certified in Kubernetes & Cloud Native Essentials (LFS250) by The Linux Foundation, and earned the Microsoft GitHub Copilot Certification.
With practical experience in enterprise IT systems at the Central Vehicle Registry and custom SOC lab builds (Splunk, Wazuh, Python SIEM automation), I am prepared to deliver immediate value to a Security Operations Center in alert triage, log correlation, and incident mitigation.
2.1
Degree Class
BSc Hons Computer Systems Eng.
5
Certifications
Google · ALX · Linux Fdn · Microsoft
11 mos
Enterprise IT
Central Vehicle Registry Support
ZWE
Harare, Zimbabwe
CAT (GMT+2) · Remote & Relocation
// Target Role
SOC Analyst (Tier 1 / Tier 2) · Security Operations Specialist
Threat Detection · Incident Response · SIEM Log Correlation · EDR Monitoring
// Career Track Record
Hands-on IT operations, systems administration, network troubleshooting, and technical mentorship in enterprise and educational environments.
Central Vehicle Registry (CVR) · Harare, Zimbabwe
Provided technical support for enterprise vehicle registration databases and critical infrastructure, helping maintain high system availability and operational continuity in a high-demand government IT environment.
Opening Horizons Academy · Harare, Zimbabwe
Delivered structured instruction in programming, relational databases, data structures, algorithms, and network protocols, coaching students through hands-on laboratory exercises.
// Hands-On Security Operations
Production-style threat detection pipelines, SIEM automation tools, and adversarial investigation labs mapped to industry frameworks.
Simulates an end-to-end SIEM workflow: parses raw Linux SSH authentication logs with regex, stores events in SQLite, detects brute-force attacks and credential-stuffing patterns, assigns severity tiers (LOW to CRITICAL), and auto-generates actionable incident reports with firewall remediation commands.
Built a virtualized monitoring environment pairing Splunk SIEM and Wazuh EDR. Simulated multi-stage adversary tactics aligned to MITRE ATT&CK (T1003 OS Credential Dumping, T1059 Command & Scripting Interpreter) and authored correlation searches to identify anomalous process trees.
Conducted deep packet inspection (DPI) and protocol decoding on malicious packet captures. Identified asynchronous Command & Control (C2) beaconing patterns, investigated suspicious DNS tunneling queries, extracted Indicators of Compromise (IoCs), and authored Snort IDS perimeter signatures.
// Skills & Competencies
Log aggregation, search syntax, query correlation, and endpoint telemetry processing.
Adversarial modeling, detection rule authoring, and attack surface classification.
Triage playbooks, network packet decoding, and threat intelligence IoC correlation.
Automating repetitive analyst tasks, custom log parsers, and threat feed integrations.
// Credentials
Google · Coursera
9-course program covering SIEM, IDS, Python automation, Linux, SQL, threat & vulnerability management, and incident response.
ALX Africa
Intensive 13-week programme covering defensive cyber strategies, ethical hacking fundamentals, and hands-on security operations.
Program: Cybersecurity (13-week)
Issued by: Fred Swaniker, CEO AL Group
The Linux Foundation
Cloud native architecture, container security fundamentals, Kubernetes cluster concepts, orchestration, and infrastructure monitoring.
ID: LF-4nx7w75zcm
Issued: July 06, 2026
Microsoft · GitHub
Certified in AI-assisted development using GitHub Copilot — accelerating secure automation, testing, and defensive script authoring.
ID: 4D1A6B4306E7BDD5
Valid: Dec 2025 – Dec 2027
Oracle University
Core concepts in artificial intelligence, machine learning pipelines, cloud services infrastructure, and AI-driven automation on Oracle Cloud.
Credential: OCI 2025 AI Foundations
Issuer: Oracle
// Academic Foundation
Degree
Midlands State University, Gweru, Zimbabwe
Faculty of Science & Technology
* Grade scale: 1 = Distinction, 2.1 = Merit (Upper Second Class)
// Get In Touch
Actively seeking Junior / Tier-1 SOC Analyst positions, security operations roles, and cybersecurity graduate opportunities. Available for remote roles globally or on-site relocation.
$ whoami
matthew_vonroy_magombo
$ cat status.txt
AVAILABLE · HARARE (CAT / GMT+2) · OPEN TO REMOTE & RELOCATION
$ cat contacts.json
{ "email": "mvmagombo@gmail.com", "github": "VonMagombo", "linkedin": "matthew-v-magombo" }
$ cat focus.txt
Threat Detection · SIEM Correlation · EDR Monitoring · Incident Triage · Security Scripting
$ |