Available immediatelyLIVE · --:--:-- UTC

anomalous visitor detected

Charles Kwarteng / Blue Team Security Analyst

I read attacks the way editors read drafts, and close them before they publish.

I keep critical infrastructure standing while most people are asleep. Three years on the watch floor, an M.Sc. in Data Science, and certification to IAT Level II. Top 3% on TryHackMe.

3+
yrs SOC / NOC
Top 3%
TryHackMe
99.99%
uptime held
6
certifications
Charles Kwarteng, cybersecurity analyst
Subject 001 · Kwarteng, C.Cleared for hire

[ 01 ]Identify

Security isn't my job title. It's how I think.

My path into security did not start in a SOC. It started in Accra, where I studied Computer Engineering and spent my time fixing the things other people had given up on. That instinct followed me into network operations, and then into a master's in Data Science here in Germany, where I focused on IT security strategy.

I have always worked behind the scenes, securing devices, networks and critical infrastructure. Moving to Germany deepened that sense of responsibility: in articles, journals and boardroom conversations, CEOs, COOs and industry stakeholders kept returning to digital sovereignty and resilience. Hearing it that often sharpened my tenacity. It shaped a thesis that bridges IT security and data analytics, and the moment I finished it in February 2025 I went straight into hands-on training and the certifications that followed.

Location
Oberhausen, Germany
Availability
Immediate · willing to travel
Clearance path
IAT Level II (DoD 8570.01-M)
Languages
English & Twi (native) · German B1

Blue team first

SOC operations, SIEM correlation in Splunk, ELK and Microsoft Sentinel, and detection tied to MITRE ATT&CK. I take an alert from first triage to a clean incident write-up.

Watch-floor tested

Three years of round-the-clock monitoring across critical national infrastructure. I held 99.99% availability and closed 95% of incidents within SLA, without escalation.

Data-driven

An M.Sc. in Data Science focused on IT security strategy, plus Python and PowerShell automation. I turn noisy telemetry into decisions that scale.

Identity & compliance

Microsoft Entra ID for more than 200 users, mapped to NIST CSF, ISO 27001, GDPR, NIS2 and DORA. Certified to IAT Level II under DoD 8570.01-M.

[ 02 ]Scope

Three years on the watch floor.

From 24/7 monitoring of critical national infrastructure to data-driven security operations. Real responsibility, outcomes I can put a number on, and all of it current practice · ready from day one.

  1. Blue Team Security Researcher (CTF)

    Mar 2025 → Present

    TryHackMe · Freelance, Remote

    • Ranked top 3% globally by completing intensive hands-on labs in SIEM operations (Splunk, ELK), MITRE ATT&CK mapped threat detection, and network traffic analysis (Wireshark, PCAP).
    • Practised end to end Tier 1 SOC workflows: alert validation, true/false positive triage, IOC enrichment with MISP and TheHive, and structured incident documentation.
    • Worked through digital forensics learning paths (Autopsy, FTK Imager), malware analysis fundamentals, and automation with PowerShell and Python. These are not skills waiting to be refreshed: I run these workflows every week, so I can take a watch-floor seat from day one.
  2. Data Analyst & IT Support Specialist

    Feb 2022 → Feb 2023

    Danquah Institute, Ghana

    • Designed and maintained IT security documentation, incident procedures, and audit-ready governance records in SharePoint, reducing downtime by 25% through structured incident handling and continuous process improvement.
    • Administered Active Directory user accounts (15+ users), access permissions, and backup processes, strengthening identity governance and access control across the organisation.
    • Automated KPI reporting and compliance monitoring with Excel (Power Query), SQL, and Python. The dashboards gave senior management 90% operational visibility.
    • Managed hardware and software procurement end to end: vendor evaluation, quotation comparison, endpoint configuration, and asset lifecycle tracking.
  3. Network Operations Center (NOC) Engineer

    Sep 2020 → Jan 2022

    National Information Technology Agency (NITA), Ghana

    • Supervised continuous 24/7 operations across Tier III critical national infrastructure spanning WAN, LAN, WLAN, SD-WAN, and VoIP, sustaining 99.99% availability for government systems serving multiple public institutions.
    • Triaged and prioritised Tier 1/2 alerts with Nagios, SolarWinds, Cacti, and PingInfoView, closing 95% of tickets inside SLA windows and feeding post-incident reviews and KPI dashboards into Jira.
    • Partnered with the SOC team to correlate security events and enforce network-level controls, giving government clients real-time visibility into the threat landscape.
    • Administered Microsoft Entra ID (Azure AD) for 200+ users: provisioning, group policy, compliance settings, and audit readiness.
    • Hardened firewalls, routers, and switches to secure baselines, and implemented redundancy, failover, and disaster-recovery strategies that removed single points of failure.
  4. IT Support Intern

    Apr 2019 → Sep 2019

    Metro TV, Ghana

    • Delivered first-line support for hardware, software, and network issues across departments, setting up and maintaining desktops, laptops, printers, and broadcast IT equipment for 35+ users.
    • Lifted IT asset-tracking accuracy by 40% by tightening documentation and inventory practices, while resolving support tickets promptly and keeping systems patched, backed up, and antivirus-protected.
    • Led a team of interns to plan and deliver a full structured cabling upgrade, improving secure data transfer efficiency by 90% and handing the IT team complete infrastructure documentation.
    • Supported the Master Control Room across 50+ live productions, switching live feeds and monitoring on-air signals, earning recognition from senior engineers for composure under high-pressure broadcasts.

[ 03 ]Background

Academically grounded.

M.Sc. Data Science

Mar 2023 → Feb 2025

Focus: IT Security Strategy

University of Europe for Applied Sciences, Potsdam, Germany

Thesis: a robust cybersecurity framework leveraging GDPR and Zero Trust Architecture. A multi-jurisdictional governance framework applicable to NIS2, DORA, and ISO 27001 compliance.

View degree certificate

B.Sc. Computer Engineering

Jan 2017 → Aug 2020

Foundations in systems, networks & hardware

Ghana Communication Technology University (formerly GTUC), Accra, Ghana

View degree certificate

Languages

English
Native
Akan (Twi)
Native
German
B1 certified · B2 in progress
View certificate

Academic references

Prof. Dr. Rand Kouatly
Thesis supervisor · Professor of IT & Communication, UE
Read letter
Prof. Dr. Talha Ali Khan
Vice President of Research · Program Leader M.Sc. Data Science, UE
Read letter
Dr. Humera Noor Minhas
CTO, Digital Munich · Lecturer, UE Berlin
Read letter

[ 04 ]Evidence

Every claim comes with evidence.

Each capability carries its proof and the context it was earned in. If it can't be evidenced, it isn't listed.

Exhibit ASplunk · ELK · Microsoft Sentinel

SIEM correlation & alert triage

Proof
Top 3% on TryHackMe (SOC / SIEM labs) · CySA+, BTL1
Where
TryHackMe labs · Tier 1 SOC workflows
Exhibit BNagios · SolarWinds · Cacti · PingInfoView

24/7 infrastructure monitoring

Proof
99.99% availability · 95% of incidents closed within SLA
Where
NITA · Tier III critical national infrastructure (3 yrs)
Exhibit CWireshark

Network forensics & packet analysis

Proof
BTL1 certified (simulated real-work incident scenarios) · Top 3% on TryHackMe
Where
BTL1 practical training · TryHackMe labs
Exhibit DAutopsy · FTK Imager

Host & disk forensics

Proof
BTL1 certified (simulated real-work incident scenarios) · Windows forensics learning paths
Where
BTL1 practical training · TryHackMe labs
Exhibit EMITRE ATT&CK · NIST CSF

Detection mapped to MITRE ATT&CK

Proof
CySA+, BTL1 · ATT&CK-mapped adversarial simulations
Where
TryHackMe · SOC alert workflows
Exhibit FFirewalls · Routers · Switches · Failover / DR

Network & security infrastructure

Proof
Reduced attack surface · continuity strengthened · core domain across all six certifications
Where
NITA · Danquah Institute · Metro TV · every role since 2019
Exhibit GPython · PowerShell · SQL

Automation & reporting

Proof
25% downtime reduction · dashboards to 90% operational visibility
Where
Danquah Institute
Exhibit HMicrosoft Entra ID · Active Directory

Identity & access management

Proof
200+ users on Entra ID (NITA) · 15+ on AD (Danquah) · MS-900
Where
NITA · Danquah Institute · identity & access operations
Exhibit IIntune · MDM · Windows 10/11

Endpoint management

Proof
Endpoint configuration, patching & lifecycle across 35+ users
Where
Danquah Institute · Metro TV
Exhibit JISO 27001 · NIST CSF · GDPR · NIS2 · DORA

Governance & compliance

Proof
ISO 27001:2022 ISMS course completed · M.Sc thesis mapping GDPR + Zero Trust onto NIS2, DORA and ISO 27001
Where
Academic research + coursework

Toolchain

  • Splunk
  • ELK Stack
  • Microsoft Sentinel
  • Wireshark
  • Autopsy
  • FTK Imager
  • MISP
  • TheHive
  • MITRE ATT&CK
  • Nagios
  • SolarWinds
  • Cacti
  • PingInfoView
  • Microsoft Entra ID
  • Active Directory
  • Intune
  • SharePoint
  • Jira
  • Python
  • PowerShell
  • SQL
  • Power Query
  • NIST CSF
  • ISO 27001
  • GDPR
  • NIS2
  • DORA
  • Zero Trust
  • TryHackMe

[ 05 ]Evidence

Credentials that speak.

Six certifications, IAT Level II compliant. Each card links to the verifiable credential.

Additional training & courses

Play It Safe: Manage Security Risks
Google / Coursera
Cybersecurity Job Simulation
Forage
Learning ITIL
LinkedIn Learning
Cybersecurity in Healthcare
Continuing Education

[ 06 ]Proving ground

Tested where it actually counts.

TryHackMe is where theory meets a real keyboard. Every badge here was earned under pressure.

Top 3%
Global ranking
90+
Day streak
Tier 1
SOC workflows
5
Skill badges
Platinum Rank, TryHackMe badge TryHackMe

Platinum Rank

Top 3% globally. Earned through consistent advanced labs in SOC operations, SIEM analysis, and adversarial simulation.

Gold Badge, TryHackMe badge TryHackMe

Gold Badge

Advanced tier recognition for mastery across offensive and defensive security challenges.

Silver Badge, TryHackMe badge TryHackMe

Silver Badge

Intermediate skill validation across network security, web exploitation, and cryptography.

SOC Level 1, TryHackMe badge TryHackMe

SOC Level 1

Completed the dedicated SOC analyst path: alert triage, threat hunting, and SIEM operations.

90-Day Streak, TryHackMe badge TryHackMe

90-Day Streak

An unbroken 90 day streak. Proof that I show up every single day, not only when it is convenient.

[ 07 ]Case files

Work that proves it.

M.Sc. thesis

GDPR-Compliant Zero Trust Architecture

Where data-protection law meets never-trust-always-verify.

My master's research designed a cybersecurity framework that brings GDPR compliance together with Zero Trust Architecture. The applied work covered detection logic, access control, and secure data handling across multiple jurisdictions.

  • Mapped GDPR data-protection duties onto Zero Trust control planes
  • Designed identity-centric access control and segmentation logic
  • Defined detection logic for cross-border data-handling risk
  • Applied research bridging legal compliance and technical enforcement
  • Zero Trust
  • GDPR
  • Access Control
  • Detection Logic
  • Research
Cloud security

AWS Cloud Security Project

Defence-in-depth, modelled on AWS.

A cloud computing project designing a secure, segmented AWS architecture with IAM least privilege, VPC segmentation, security groups, and CloudTrail logging, all documented with a threat model and a risk assessment.

  • Multi-tier VPC with public/private subnet segmentation
  • IAM role-based access designed on least privilege
  • CloudTrail + CloudWatch for audit logging
  • Documented threat model and risk register
  • AWS
  • IAM
  • VPC
  • CloudTrail
  • CloudWatch
  • S3
Data science

Data Science & Business Report

Turning raw data into decisions.

An applied data science and business project: analysing a dataset end to end and turning the findings into a structured report with KPIs and recommendations for stakeholders. It is the same instinct I bring to security metrics.

  • End-to-end data analysis and cleaning in Python
  • KPI-driven reporting for non-technical stakeholders
  • Clear, decision-oriented written deliverable
  • Visualisation of trends and business impact
  • Python
  • Pandas
  • Excel
  • SQL
  • Data Viz
PeTi · Startup Concept logoEntrepreneurship

PeTi · Startup Concept

Product thinking, validated.

An entrepreneurship project that took an idea from a shortlist of 30 down to one pitched concept, with market research, a business model, and an investor deck. Proof that I understand the business security exists to protect.

  • Shortlisted and ranked 30 startup ideas
  • Built business model and go-to-market outline
  • Produced a full investor pitch deck
  • Market research and competitive analysis
  • Business Strategy
  • Market Research
  • Pitching

[ 08 ]Resolution

Recommend immediate engagement.

Whether you're staffing a 24/7 watch floor, a SOC analyst seat, or an incident response team, let's talk about how I can defend your organisation from day one.

Available immediately · willing to travel

// case closed · recommend immediate engagement