Alex Dafnis, Developer in Zielona Gora, Poland
Alex is available for hire
Hire Alex

Alex Dafnis

Cybersecurity Developer

Zielona Gora, Poland

Toptal member since February 27, 2026

Bio

Alex is a dedicated cybersecurity professional specializing in B2B security services for startups and Fortune 500 enterprise environments. His core focus is on incident response, threat hunting, risk reduction, compliance, and driving security operations center (SOC) maturity. Alex has extensive experience operating within global 24/7 SOCs and delivering multi-client operations, frequently managing security for more than 20 clients simultaneously.

Portfolio

Freelance Clients
FortiSIEM, FortiGate, FortiAnalyser, FortiEDR, FortiSOAR, NIST, MITRE ATT&CK...
Freelance Client
Data Loss Prevention (DLP), ISO 27001, PCI/PA-DSS, Security Monitoring...
Freelance Client
FortiSIEM, fortiEDR, Cyber Threat Hunting, Wireshark, SOC 2, IT Security

Experience

  • Security Monitoring - 5 years
  • Cybersecurity Operations - 4 years
  • Cyber Threat Hunting - 3 years
  • Incident Response - 3 years
  • Splunk - 3 years
  • SOC Analyst - 3 years
  • Data Loss Prevention (DLP) - 3 years
  • FortiSIEM - 3 years

Preferred Environment

Linux, Splunk, Microsoft Sentinel, FortiSIEM, FortiSOAR, FortiEDR, FortiAnalyser, ISO 27001, NIST, General Data Protection Regulation (GDPR)

The most amazing...

...achievement has been optimizing alert triage across over 20 clients, reducing false positives by 85% and escalating threats in under 20 minutes 91% of the time.

Work Experience

Security Operations Center (SOC) and Network Operations Center (NOC) Analyst

2024 - PRESENT
Freelance Clients
  • Monitored combined dashboards for over 30 clients, acting as the first line of defense for security alerts and network performance availability.
  • Assisted in tuning security information and event management (SIEM) alert thresholds to reduce background noise, helping senior analysts focus on critical events.
  • Contributed to a 15% reduction in the daily incident volume by identifying and whitelisting repetitive false positives.
  • Documented standard operating procedures (SOPs) for routine alert triage and client communication.
Technologies: FortiSIEM, FortiGate, FortiAnalyser, FortiEDR, FortiSOAR, NIST, MITRE ATT&CK, Microsoft Defender XDR, Microsoft Sentinel, Nagios, Incident Response, Cyber Threat Hunting, Security Monitoring, SOC 2, IT Security

Security Support Specialist

2024 - 2024
Freelance Client
  • Assisted with the deployment of data loss prevention (DLP) agents to workstations to prevent unauthorized data transfer.
  • Performed periodic user access reviews to ensure adherence to the principle of least privilege (PoLP) for sensitive financial folders.
  • Conducted periodic user access reviews for sensitive financial directories to meet PCI-DSS and ISO 27001 access control requirements.
  • Identified and remediated more than 50 unencrypted endpoints, bringing the fleet into full compliance with General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) data privacy standards.
Technologies: Data Loss Prevention (DLP), ISO 27001, PCI/PA-DSS, Security Monitoring, Microsoft Intune, ClickHouse, SOC 2, IT Security

SOC Analyst

2024 - 2024
Freelance Client
  • Performed real-time monitoring of security queues, specifically looking for indicators of compromise (IoCs) related to network traffic.
  • Escalated validated threats with detailed triage notes and packet capture evidence.
  • Analyzed phishing emails reported by employees and blocked malicious sender domains in the email gateway.
  • Participated in shift handovers to ensure continuity of monitoring for high-priority banking assets.
Technologies: FortiSIEM, fortiEDR, Cyber Threat Hunting, Wireshark, SOC 2, IT Security

Experience

Enterprise SOC Lab Deployment

I architected, implemented, and configured a fully functional SOC lab environment to simulate real-world enterprise network traffic and security events using Fortinet's network and security products.

Certifications

JANUARY 2026 - PRESENT

Certified Ethical Hacker (CEH)

EC-Council

JANUARY 2025 - PRESENT

NIST SP 800-53B

NIST

JANUARY 2025 - PRESENT

NIST SP 800-53A

NIST

DECEMBER 2024 - PRESENT

SIEM Engineer

LetsDefend

DECEMBER 2024 - PRESENT

Blue Teal Level 1 (BTL1)

Security Blue Team

JULY 2024 - PRESENT

Incident Responder

LetsDefend

APRIL 2024 - PRESENT

Malware Analysis

LetsDefend

FEBRUARY 2024 - PRESENT

SOC Analyst Certification

LetsDefend

OCTOBER 2023 - PRESENT

Project Management

Vellum Global Educational Services SA

SEPTEMBER 2023 - PRESENT

Network Defense

EC-Council

SEPTEMBER 2023 - SEPTEMBER 2025

Splunk Core Certified User

Splunk

JULY 2023 - PRESENT

Cybersecurity Specialization

Google

JUNE 2023 - PRESENT

Cybersecurity Analyst

IBM

Skills

Tools

Splunk, Wireshark, Microsoft Intune, Nagios

Languages

Bash, Python

Paradigms

Penetration Testing

Platforms

Linux

Storage

ClickHouse

Other

FortiSIEM, Security Monitoring, Incident Response, Cybersecurity Operations, SOC Analyst, SOC 2, Cyber Threat Hunting, Microsoft Sentinel, FortiSOAR, FortiEDR, FortiAnalyser, ISO 27001, NIST, General Data Protection Regulation (GDPR), FortiGate, fortiEDR, Data Loss Prevention (DLP), PCI/PA-DSS, MITRE ATT&CK, Microsoft Defender XDR, Cybersecurity Consulting, Enterprise Cybersecurity, Splunk Enterprise Security, Network Security, IT Project Management, Malware Analysis, SIEM engineer, SOAR Engineer, NIST SP 800-53A, NIST SP 800-53B, IT Security

Collaboration That Works

How to Work with Toptal

Toptal matches you directly with global industry experts from our network in hours—not weeks or months.

1

Share your needs

Discuss your requirements and refine your scope in a call with a Toptal domain expert.
2

Choose your talent

Get a short list of expertly matched talent within 24 hours to review, interview, and choose from.
3

Start your risk-free talent trial

Work with your chosen talent on a trial basis for up to two weeks. Pay only if you decide to hire them.

Top talent is in high demand.

Start hiring