Abdul Syed, Developer in Victoria, BC, Canada
Abdul is available for hire
Hire Abdul

Abdul Syed

Bio

Abdul is a cybersecurity expert and CISM-certified professional specializing in threat detection, incident response, GRC, security architecture, application security, and AI-driven security solutions. With a master's in engineering and 10+ years of experience in enterprise environments, he delivers practical, results-driven security solutions. Clients trust Abdul to find and fix vulnerabilities, reduce risk, and build resilient defenses from day 1.

Portfolio

Camosun
Microsoft Sentinel, IT Security, Security Incident Triage, CrowdStrike...
Huawei Technologies Co.
Incident Response, SIEM, Security Operations Centers (SOC)...

Experience

  • Incident Response - 8 years
  • Artificial Intelligence (AI) - 8 years
  • Cybersecurity Operations - 7 years
  • Microsoft Defender XDR - 7 years
  • Sentinel - 5 years
  • Security Monitoring & Threat Protection - 5 years
  • Machine Learning - 5 years
  • AI Agent Security - 3 years

Preferred Environment

Windows, Ubuntu Linux, Python, Microsoft Defender XDR, Sentinel, IT Security, Penetration Testing, Playbook, Mobile App Security

The most amazing...

...security platform I've built is Indus Shield—an AI-powered XDR/SIEM solution that automates threat detection across enterprise environments.

Work Experience

Security Engineer

2021 - PRESENT
Camosun
  • Led incident response operations as Incident Commander, reducing mean time to containment across security events by coordinating cross-functional response teams.
  • Deployed and tuned Microsoft Sentinel SIEM, building custom KQL detection rules that reduced false positives by 40% and improved threat visibility.
  • Mentored and coordinated SOC team members on incident handling procedures, threat hunting techniques, and security tool usage to elevate team capability.
  • Triaged 100+ security incidents monthly using Microsoft Defender XDR and CrowdStrike, ensuring rapid escalation and resolution within defined SLA windows.
  • Implemented data-loss prevention (DLP) policies and security controls across enterprise systems, reducing data exposure risk and ensuring compliance with institutional security frameworks.
Technologies: Microsoft Sentinel, IT Security, Security Incident Triage, CrowdStrike, FortiSIEM, Kusto Query Language (KQL), TDX, Teamwork, Team Leadership, Team Coordination, Cisco Umbrella, Playbook, Cybersecurity Operations, Artificial Intelligence (AI), Windows, Ubuntu Linux, Python, Microsoft Defender XDR, Sentinel, AI Agent Security, Penetration Testing, SIEM, Mobile Wireless Networks, Ethical Hacking, Web Development, Security and Data Analysis, Incident Response, Security Monitoring & Threat Protection, Security, SOC 2, Zero Trust, Zero Trust Network Access (ZTNA), Amazon Web Services (AWS), Security Audits

Senior Information Security Analyst

2011 - 2017
Huawei Technologies Co.
  • Led enterprise-wide security operations covering threat detection, incident response, and vulnerability management, reducing mean time to respond to critical incidents by 40%.
  • Designed and implemented a SIEM-based monitoring framework aligned with NIST SP 800-53 controls, improving real-time visibility across 500+ endpoints and network assets.
  • Developed and enforced DLP policies and security baselines, achieving full compliance with organizational information security standards and audit requirements.
  • Conducted risk assessments and security audits across critical infrastructure, identifying and remediating high-severity vulnerabilities before exploitation occurred.
  • Built and delivered security awareness training programs for 200+ staff, measurably reducing phishing susceptibility and improving overall security posture.
Technologies: Incident Response, SIEM, Security Operations Centers (SOC), Vulnerability Assessment, Risk Assessment, NIST Framework, Network Security, Threat Intelligence, Information Security, GRC, Security, SOC 2, Zero Trust Network Access (ZTNA)

Experience

Indus Shield – Enterprise XDR, SIEM, & Agentic AI SOC Platform

Designed and built Indus Shield, a production-grade unified security platform combining XDR, SIEM, and an autonomous Agentic AI SOC in a single dashboard.

Architecture: Real-time log ingestion via Apache Kafka, with a Python agent normalizing logs from endpoints, servers, and cloud APIs into a unified event schema. Elasticsearch indexes all security events with sub-second search. PostgreSQL manages alerts and cases. Redis handles caching and rate limiting.

Detection engine: Sigma rules evaluation engine loading YAML-based detection rules against incoming events in real time. MITRE ATT&CK auto-mapping classifies every detection by tactic and technique. Alert generation with severity scoring and deduplication.

AI SOC agent: Autonomous AI analyst powered by Claude API triages alerts, investigates root cause, maps to threat frameworks, and recommends response actions 24/7.

Dashboard: React and TypeScript with real-time threat overview, live alert queue, MITRE ATT&CK visualization, and interactive investigation panel.

Stack: Python, FastAPI, Kafka, Elasticsearch, PostgreSQL, Redis, React, TypeScript, Docker, Sigma, MITRE ATT&CK, and Claude API.

Malicious URL Detection Using Machine Learning

https://dspace.library.uvic.ca/items/4bfcea4c-f71e-4431-bcbb-d9cc3f533e4d
Completed as a master of engineering project at the University of Victoria. I developed a supervised machine learning system to detect and classify malicious URLs across four threat categories: spam, malware, phishing, and benign.

I used the ISCX-URL-2016 dataset from the Canadian Institute for Cyber Security, containing 79 features across 4 URL classes. I applied principal component analysis (PCA) for dimensionality reduction, selecting the top 10 and 25 features based on eigenvalues. I then evaluated 5 classifiers: random forest, decision tree, K-nearest neighbors (KNN), Bayesian network, and simple logistic, using 5-fold and 10-fold cross-validation.

RESULTS
Random Forest achieved the highest accuracy at 98.7% using all 79 features. KNN delivered 98.3% accuracy with the fastest execution time of 0.06 seconds, making it optimal for real-time detection in production security environments. Performance was measured across accuracy, precision, recall, F-measure, and execution time.

The findings were directly applicable to real-time proxy filtering, firewall URL inspection, and enterprise threat detection pipelines.

Stack: WEKA, Python, random forest, KNN, decision tree, PCA, cross-validation, and ISCX-URL-2016 dataset.

Education

2017 - 2022

Master's Degree in Engineering: Cybersecurity and Artificial Intelligence

University of Victoria - Victoria, BC, Canada

2007 - 2010

Bachelor's Degree in Computer Science

University of Sindh - Jamshoro, Pakistan

Certifications

AUGUST 2025 - PRESENT

Certified Information Security Manager (CISM)

ISACA

DECEMBER 2023 - PRESENT

Microsoft Azure Security Technologies (AZ-500)

Microsoft

JANUARY 2023 - PRESENT

Microsoft Certified: Security Operations Analyst (SC-200)

Microsoft

DECEMBER 2022 - PRESENT

Microsoft Certified: Azure Fundamentals (AZ-900)

Microsoft

Skills

Libraries/APIs

React

Tools

Sentinel, Weka, Cisco Umbrella

Paradigms

Penetration Testing

Platforms

Playbook, Apache Kafka, Docker, Azure, Amazon Web Services (AWS), Windows, Ubuntu Linux, CrowdStrike

Languages

TypeScript 5, Python, Kusto Query Language (KQL), SQL

Storage

Redis, Databases, Elasticsearch

Other

Microsoft Defender XDR, IT Security, AI Agent Security, Cybersecurity Operations, Artificial Intelligence (AI), Incident Response, Security Incident Triage, MITRE ATT&CK, Security Operations Centers (SOC), Vulnerability Assessment, Risk Assessment, NIST Framework, Threat Intelligence, Information Security, Security, SOC 2, AI Security, Agentic AI Systems, Zero Trust, Zero Trust Network Access (ZTNA), Mobile App Security, SIEM, Machine Learning, Ethical Hacking, Security and Data Analysis, Security Monitoring & Threat Protection, PostgreSQL 9, XD to HTML, Endpoint Security, Random Forests, K-nearest Neighbors (KNN), Principal Component Analysis (PCA), Microsoft Azure, Cloud Security, GRC, Security Audits, Network Security, Mobile Wireless Networks, Web Development, Cybersecurity & Incident Response, Security Information and Event Management (SIEM), Application Security & Penetration Testing, GRC (Governance, Risk & Compliance), Microsoft Sentinel (SIEM & SOAR), Threat Detection and Response (TDR), Azure Cloud Security, Azure Security Center & Defender for Cloud, Identity & Access Management (Azure AD / Entra ID), Network Security (NSGs, Firewalls, VPNs), Data & Application Security (Key Vault, Encryption), Microsoft Sentinel, FortiSIEM, TDX, Teamwork, Team Leadership, Team Coordination, Programming, Enterprise Cybersecurity, Mobile App Development, FastAPI, Decision Trees, Cloud Computing

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring