Available for Opportunities

Matthew
Vonroy
Magombo

Aspiring SOC Analyst with a BSc in Computer Systems Engineering, Google Cybersecurity certification, and a passion for threat detection, incident response, and securing digital infrastructure.

SIEM Tools IDS/IPS Linux Python Network Security GitHub Copilot
Matthew Vonroy Magombo - SOC Analyst

$ status: ACTIVE | role: SOC_ANALYST | ops: OPEN_TO_REMOTE

// About Me

Defending the
Digital Frontier

Born and raised in Harare, Zimbabwe, I graduated from Midlands State University with a BSc Honours (2.1) in Computer Systems Engineering — building a rigorous technical foundation in networking protocols, operating systems, software engineering, and computer architecture.

My focus in cybersecurity combines an adversary-aware mindset with structured defensive engineering. I hold the Google Cybersecurity Professional Certificate, completed the ALX 13-week Cybersecurity Programme, certified in Kubernetes & Cloud Native Essentials (LFS250) by The Linux Foundation, and earned the Microsoft GitHub Copilot Certification.

With practical experience in enterprise IT systems at the Central Vehicle Registry and custom SOC lab builds (Splunk, Wazuh, Python SIEM automation), I am prepared to deliver immediate value to a Security Operations Center in alert triage, log correlation, and incident mitigation.

2.1

Degree Class

BSc Hons Computer Systems Eng.

5

Certifications

Google · ALX · Linux Fdn · Microsoft

11 mos

Enterprise IT

Central Vehicle Registry Support

ZWE

Harare, Zimbabwe

CAT (GMT+2) · Remote & Relocation

// Target Role

SOC Analyst (Tier 1 / Tier 2) · Security Operations Specialist

Threat Detection · Incident Response · SIEM Log Correlation · EDR Monitoring

// Career Track Record

Professional Experience

Hands-on IT operations, systems administration, network troubleshooting, and technical mentorship in enterprise and educational environments.

Enterprise IT & Systems Support

IT Intern

Central Vehicle Registry (CVR) · Harare, Zimbabwe

Oct 2023 – Aug 2024 (11 mos)

Provided technical support for enterprise vehicle registration databases and critical infrastructure, helping maintain high system availability and operational continuity in a high-demand government IT environment.

  • Diagnosed and resolved software, hardware, and network incidents across departments to reduce user downtime.
  • Maintained comprehensive technical documentation, incident logs, and system support operating procedures.
  • Collaborated with senior engineers to analyze system faults, telemetry logs, and support performance improvements.
Enterprise Systems Hardware & Network Triage Incident Logging User Access Management Linux / Windows
Technical Education & Mentorship

Computer Science Tutor

Opening Horizons Academy · Harare, Zimbabwe

Jan 2023 – May 2023 (5 mos)

Delivered structured instruction in programming, relational databases, data structures, algorithms, and network protocols, coaching students through hands-on laboratory exercises.

Python C++ SQL & Relational Schemas Networking Fundamentals Technical Mentorship

// Hands-On Security Operations

Featured Projects & Labs

Production-style threat detection pipelines, SIEM automation tools, and adversarial investigation labs mapped to industry frameworks.

Flagship Build
SIEM Automation · Threat Detection

Failed Login Detector & Threat Alerter

Simulates an end-to-end SIEM workflow: parses raw Linux SSH authentication logs with regex, stores events in SQLite, detects brute-force attacks and credential-stuffing patterns, assigns severity tiers (LOW to CRITICAL), and auto-generates actionable incident reports with firewall remediation commands.

// Pipeline: auth.log → parser.py → SQLite DB → analyzer.py → reporter.py
  • Regex parsing of timestamp, IP, username, and authentication outcome
  • Configurable threat thresholds for brute-force & credential-stuffing
  • Automated firewall / iptables blocking recommendation generation
Python 3 SQLite3 Regex Linux auth.log
View Source on GitHub
SIEM & EDR · Threat Hunting

Enterprise SOC Detection & Triage Lab

Built a virtualized monitoring environment pairing Splunk SIEM and Wazuh EDR. Simulated multi-stage adversary tactics aligned to MITRE ATT&CK (T1003 OS Credential Dumping, T1059 Command & Scripting Interpreter) and authored correlation searches to identify anomalous process trees.

// Pipeline: Sysmon Telemetry → Wazuh Agent → Splunk SPL → Triage Playbook
  • Crafted Splunk SPL queries for abnormal PowerShell execution and privilege spikes
  • Configured custom Wazuh XML rules mapped to MITRE ATT&CK technique IDs
  • Documented incident triage playbooks with host isolation procedures
Splunk (SPL) Wazuh EDR Sysmon MITRE ATT&CK
Detection Rules & Playbooks Active Lab
Network Security · Packet Forensics

PCAP Traffic Analysis & Beacon Detection

Conducted deep packet inspection (DPI) and protocol decoding on malicious packet captures. Identified asynchronous Command & Control (C2) beaconing patterns, investigated suspicious DNS tunneling queries, extracted Indicators of Compromise (IoCs), and authored Snort IDS perimeter signatures.

// Pipeline: PCAP Capture → TCP Stream Reassembly → IoC Extraction → Snort Rule
  • Decoded TCP/UDP/DNS streams to uncover hidden payload transfers
  • Correlated extracted domain/IP IoCs against VirusTotal & AbuseIPDB
  • Authored custom Snort rules for automated intrusion alerting at the gateway
Wireshark TCP/IP Snort / Suricata Threat Intel
PCAP Forensics & Signatures Case Study

// Skills & Competencies

Technical Arsenal

Cybersecurity

  • Threat Detection & Analysis
  • Incident Response
  • Vulnerability Assessment
  • Network Security & Monitoring
  • SIEM Tools (Splunk, Chronicle)
  • Intrusion Detection Systems (IDS)
  • Cryptography Principles
  • Security Risk Management

Programming & Tools

  • Python (Cybersecurity Automation)
  • Linux / Bash Scripting
  • SQL & Database Security
  • Git & GitHub Copilot
  • Object-Oriented Programming
  • Data Structures & Algorithms
  • Web & Mobile Development
  • Parallel & Distributed Computing

Networks & Systems

  • TCP/IP & Network Protocols
  • Data Communication & Networks
  • IoT & Cloud Systems Engineering
  • Embedded Systems
  • Microprocessors & Controllers
  • Communications Network Design
  • Operating Systems
  • Control Systems Engineering

SOC Operational Framework & Tooling Matrix

// Defense-in-Depth Capabilities

SIEM & Telemetry Ingestion

Log aggregation, search syntax, query correlation, and endpoint telemetry processing.

Splunk (SPL) Google Chronicle Wazuh EDR Linux auth.log / Syslog Windows Sysmon

Threat Detection & Mapping

Adversarial modeling, detection rule authoring, and attack surface classification.

MITRE ATT&CK Cyber Kill Chain Sigma Rules Snort / Suricata IDS YARA Basics

Incident Response & Triage

Triage playbooks, network packet decoding, and threat intelligence IoC correlation.

Wireshark PCAP Alert Triage (NIST SP 800-61) VirusTotal / AbuseIPDB Root-Cause Analysis

Security Automation & Scripting

Automating repetitive analyst tasks, custom log parsers, and threat feed integrations.

Python 3 (re, requests, sqlite) Linux / Bash Scripting SQL Queries & Auditing Git & GitHub Copilot

// Credentials

Certifications

G

Google · Coursera

Google Cybersecurity
Professional Certificate

9-course program covering SIEM, IDS, Python automation, Linux, SQL, threat & vulnerability management, and incident response.

Foundations of Cybersecurity & Network Security
SIEM Tools (Splunk, Chronicle) & IDS/IPS
Python Security Scripting & Automation
Linux CLI & SQL Database Auditing
Incident Detection & Response Workflows
Dec 2025 Verify
alx

ALX Africa

Cybersecurity
Programme Certificate

Intensive 13-week programme covering defensive cyber strategies, ethical hacking fundamentals, and hands-on security operations.

Program: Cybersecurity (13-week)

Issued by: Fred Swaniker, CEO AL Group

Apr 2026 Verify
LF

The Linux Foundation

Kubernetes & Cloud Native
Essentials (LFS250)

Cloud native architecture, container security fundamentals, Kubernetes cluster concepts, orchestration, and infrastructure monitoring.

ID: LF-4nx7w75zcm

Issued: July 06, 2026

Jul 2026 Certified

Microsoft · GitHub

GitHub Copilot
Certification

Certified in AI-assisted development using GitHub Copilot — accelerating secure automation, testing, and defensive script authoring.

ID: 4D1A6B4306E7BDD5

Valid: Dec 2025 – Dec 2027

Dec 2025 Verify
OCI

Oracle University

OCI AI Foundations
Associate

Core concepts in artificial intelligence, machine learning pipelines, cloud services infrastructure, and AI-driven automation on Oracle Cloud.

Credential: OCI 2025 AI Foundations

Issuer: Oracle

2025 Certified

// Academic Foundation

Education

Degree

BSc Honours in Computer Systems Engineering

Midlands State University, Gweru, Zimbabwe

Class 2.1 Upper Second
Duration Sep 2021 – Jun 2025
Focus Systems & Security Engineering

Faculty of Science & Technology

Selected Engineering Coursework

// Distinctions & Merits
HCSCI234 Research Methods 1 (Distinction)
HCSE433 IoT & Cloud Systems Engineering 2.1
HTENG432 Communications Network Design 2.1
HCSCI433 Parallel & Distributed Computing 1 (Distinction)
HCSE432 Embedded Systems 2.1
HCSCI237 Data Communication & Networks 2.1
HCSCI133 Operating Systems 1 (Distinction)
HCSE135 Database Systems 1 (Distinction)
HCSCI439 Fundamentals of Data Science & Big Data 2.1
HCSE436 Control Systems Engineering 2.1

* Grade scale: 1 = Distinction, 2.1 = Merit (Upper Second Class)

// Get In Touch

Ready to Defend &
Open to Roles

Actively seeking Junior / Tier-1 SOC Analyst positions, security operations roles, and cybersecurity graduate opportunities. Available for remote roles globally or on-site relocation.

soc_analyst@harare-node:~

$ whoami

matthew_vonroy_magombo

$ cat status.txt

AVAILABLE · HARARE (CAT / GMT+2) · OPEN TO REMOTE & RELOCATION

$ cat contacts.json

{ "email": "mvmagombo@gmail.com", "github": "VonMagombo", "linkedin": "matthew-v-magombo" }

$ cat focus.txt

Threat Detection · SIEM Correlation · EDR Monitoring · Incident Triage · Security Scripting

$ |