HELLO, I'M

MELUSI SHOKO

CISSP | Cybersecurity Specialist

SOC Analyst | CTI | Malware Analysis | Incident Response
CISSP
4+ YRS SOC
#1 LETSDEFEND ZW
CTI SPECIALIST
SOC ANALYST
INCIDENT RESPONSE
THREAT HUNTING
PROOFPOINT AI
shokomelu@gmail.com +263 782 354 610 https://www.linkedin.com/in/shokom95 Open to Remote & Relocation
Melusi Shoko

PROFESSIONAL SUMMARY

CISSP-certified Cybersecurity Specialist with 4+ years of hands-on SOC experience in threat detection, vulnerability management, and incident response. Ranked #1 on the LetsDefend Zimbabwe leaderboard (3,548 pts, 77% alert success rate) with 100+ real-world alerts investigated across malware, web attacks, ransomware, phishing, and privilege escalation scenarios. Proven ability to automate security workflows using Python, build threat intelligence pipelines, and communicate risk clearly to both technical teams and executive leadership.

PROFESSIONAL EXPERIENCE

SOC Analyst (Cybersecurity Specialist)
FBC Holdings Limited | Harare, Zimbabwe | Oct 2021 - Present
  • Lead enterprise-wide VAPT activities across web portals, applications, and infrastructure using Nessus and OWASP ZAP; collaborate with infrastructure and application teams to prioritize remediation by CVSS severity and business impact, reducing exposure window by an estimated 40% per quarter.
  • Engineered a Python/Pandas automation pipeline to parse FortiSIEM and CSV incident logs, reducing manual vulnerability reporting time by ~12 hours per week and accelerating report delivery by 3 days per cycle.
  • Championed ISO 27001 compliance remediation, developing all documentation, evidence artifacts, and technical workflows to fulfill Control 5.7 (Threat Intelligence) - contributing directly to the organization's audit readiness.
  • Applied CTI principles to analyze emerging zero-day threats and security advisories; built custom ELK Stack correlation rules to detect threats missed by standard signatures, reducing false-negative rate on targeted financial sector campaigns.
  • Maintained 24/7 incident response accountability - contained high-impact credential-harvesting campaigns targeting the financial sector by implementing strategic M365 mail flow rules and endpoint containment actions, achieving containment within SLA on all critical incidents.
  • Engineered a proprietary Python-based phishing simulation tool used in corporate security awareness exercises, providing objective telemetry data on human-layer risk to senior management.
  • Investigated and closed 100+ real-world security alerts on LetsDefend (77% success rate, 4,132 SLA score) covering malware, ransomware, web attacks, privilege escalation, data leakage, and phishing - including CVE-2025-53770 (SharePoint RCE), Lumma Stealer DLL side-loading, and Palo Alto PAN-OS command injection (CVE-2024-3400).
Information Security Intern
FBC Holdings Limited | Harare, Zimbabwe | Aug 2019 - Jul 2020
  • Designed and deployed a secure Windows Remote Desktop (RD) Gateway, eliminating exposed endpoints and enabling secure remote access for 200+ users.
  • Developed Python scripts to automate security monitoring and log parsing, saving the core engineering team ~5 hours/week in manual effort.
  • Assisted in deployment, policy configuration, and testing of enterprise NAC and DLP solutions.

CORE COMPETENCIES & TECHNICAL SKILLS

SECURITY OPERATIONS

SOC Alert Triage Incident Lifecycle Management ELK Stack EDR Darktrace FortiSIEM SIEM Alert Tuning Wireshark Log Analysis with Sysmon

THREAT INTELLIGENCE & MALWARE ANALYSIS

CTI Frameworks OSINT (Shodan, VirusTotal) Malware Analysis Fundamentals NTFS Forensics YARA Rules Sandboxing Obfuscated JavaScript PowerShell Keylogger Analysis Steganography Kernel Exploits

VULNERABILITY & RISK MANAGEMENT

VAPT (Nessus, OWASP ZAP) CVSS Framework Risk-Based Remediation Attack Surface Reduction ISO 27001 (Control 5.7) Infrastructure Hardening

AUTOMATION & SCRIPTING

Python (Pandas) Log Parsing Phishing Simulation Ransomware Simulation PowerShell Bash Base64 Decoding Scripts VirusTotal IP Scanning

CLOUD & EMAIL SECURITY

Microsoft 365 Security Proofpoint AI Email Security Email Header Analysis Phishing Analysis & Detection Social Engineering Defense

PLATFORMS & TOOLS

LetsDefend (Rank #1 Zimbabwe) HackTheBox VirusTotal Shodan Gophish oletools Wireshark

PROFESSIONAL CERTIFICATIONS

Proofpoint AI Email Security
Verify Proofpoint Credential
Proofpoint Certified AI Data Security Specialist 2025
Verify Proofpoint Data Security Credential
LetsDefend Cyber Defense
Verify LetsDefend Certificate
Mastering Cyber Threat Intelligence for SOC Analysts
View Certificate Details
Fundamentals Of Darkweb Training
Verify Certificate
Certified Cybersecurity Educator Professional (CCEP)
Verify CCEP Credential

SECURITY BADGES & CREDENTIALS

Proofpoint AI Email

Specialist
Proofpoint AI Email Security Specialist

Proofpoint Certified AI Email Security Specialist

2024 Credly

Proofpoint AI Data

Specialist 2025
Proofpoint Certified AI Data Security Specialist 2025

Proofpoint Certified AI Data Security Specialist 2025

2025 Credly

CISSP

Expert
CISSP Certified Information Systems Security Professional

Certified Information Systems Security Professional

2024 Gold Tier

CTI Master

Advanced
Mastering Cyber Threat Intelligence for SOC Analysts

Mastering Cyber Threat Intelligence for SOC Analysts

2023 SOC Radar

Dark Web

Specialist
Fundamentals of Dark Web Training

Fundamentals of Dark Web Training

2023 OSINT

Phishing Expert

Expert
LetsDefend Phishing Expert Badge

Phishing Analysis & Detection Specialist

2023 LetsDefend

Network Cable

Fundamentals
LetsDefend Network Fundamentals Badge

Network Fundamentals & Cable Analysis

2023 Networking

HANDS-ON TRAINING & ACHIEVEMENTS

LetsDefend Platform

Ranked #1 in Zimbabwe with a 64-day streak. 77% alert success rate across 100+ investigated alerts spanning malware, web attacks, ransomware, phishing, brute force, privilege escalation, and data leakage.

Phishing Expert Web Attack Investigator Malware Analyzer Incident Handler SIEM 101 Wireshark Expert Windows Forensics Expert NTFS Forensics
View Full Transcript & Progress

HackTheBox

Active participant (SpartanCr0w) in hands-on offensive and defensive security challenges covering web exploitation, forensics, and cryptography.

Web Exploitation Forensics Cryptography

LetsDefend Leaderboard - Zimbabwe

1
shokom
3548 pts
2
btasara
3468 pts
3
mercedessibanda
2298 pts

Scripting & Analysis

Obfuscated JavaScript Bash Script PowerShell Keylogger Batch Downloader Chrome Extension Analysis

Malware & Forensics

Malware Analysis Fundamentals NTFS Forensics Malicious Document Analysis Kernel Exploit Steganography

Defense & Detection

Log Analysis With Sysmon Email Header Analysis Detecting Web Attacks IT Security Fundamentals Windows Operating System Fundamentals VoIP Security

Investigated Alert Types

Malware investigations lead the caseload by a wide margin, with meaningful depth across web attacks, proxy, and Exchange alerts.

SECURITY RESEARCH & WRITING

Cybersecurity Technical Author
Medium Publication | 2022-Present
26 published articles covering threat intelligence, OSINT, malware analysis, and SOC operations - approved in System Weakness and OSINT Team publications.
Story Presentations Views Reads
Investigate Web attack. Letsdefend challenge #blueteam
- 7.9K 4.8K
Email OSINT (open source intelligence for email)
- 6.4K 2.4K
Checking Internet Speed with a Python Script
- 6.5K 2.6K
Analyze malicious .doc file_Letsdefend challenge #blueteam #Malware_Analysis
- 4.4K 2.3K
Incident Report: Lumma Stealer Deployment via Click Fix Phishing (DLL Side-Loading)
- - -
Simulating Ransomware in a Controlled Environment with Python
- - -
OSINT with Python: Scan IPs with VirusTotal
- - 1.6K
View all 26 articles on Medium
# Article Research & Development Workflow
def research_topic(topic):
    gather_osint_sources()
    analyze_attack_vectors()
    create_lab_environment()
    document_findings()
    publish_technical_guide()

Education

Bachelor of Technology in Information Security and Assurance
Harare Institute of Technology | 2017-2021
Specialized in Threat Intelligence, Digital Forensics, and Defensive Security Operations
Best Graduating Student Award & Book Prize - Top Design & Innovation Project

GET IN TOUCH

Bot Protection
Input Sanitization
Timestamp Verification

Email

[Email protected from harvesting bots]

Protected against email harvesting bots

Phone

+263 782 354 610

Telegram available on request

Professional Network

https://www.linkedin.com/in/shokom95

PGP Encryption

Available upon request for sensitive communications

End-to-end encryption for confidential messages

Send a Message

1000 character limit
Protected against spam and bots. Delivered securely via Formspree.

LOCATION

Based In

Harare, Zimbabwe

UTC+2 (Central Africa Time)

Availability

Remote & On-site Opportunities

Full remote work capability

Languages

English, Shona

Fluent in technical communication

Harare, Zimbabwe

Map data loaded securely from Google Maps