Blue team first
SOC operations, SIEM correlation in Splunk, ELK and Microsoft Sentinel, and detection tied to MITRE ATT&CK. I take an alert from first triage to a clean incident write-up.
anomalous visitor detected
Charles Kwarteng / Blue Team Security Analyst
I keep critical infrastructure standing while most people are asleep. Three years on the watch floor, an M.Sc. in Data Science, and certification to IAT Level II. Top 3% on TryHackMe.

[ 01 ]Identify
My path into security did not start in a SOC. It started in Accra, where I studied Computer Engineering and spent my time fixing the things other people had given up on. That instinct followed me into network operations, and then into a master's in Data Science here in Germany, where I focused on IT security strategy.
I have always worked behind the scenes, securing devices, networks and critical infrastructure. Moving to Germany deepened that sense of responsibility: in articles, journals and boardroom conversations, CEOs, COOs and industry stakeholders kept returning to digital sovereignty and resilience. Hearing it that often sharpened my tenacity. It shaped a thesis that bridges IT security and data analytics, and the moment I finished it in February 2025 I went straight into hands-on training and the certifications that followed.
SOC operations, SIEM correlation in Splunk, ELK and Microsoft Sentinel, and detection tied to MITRE ATT&CK. I take an alert from first triage to a clean incident write-up.
Three years of round-the-clock monitoring across critical national infrastructure. I held 99.99% availability and closed 95% of incidents within SLA, without escalation.
An M.Sc. in Data Science focused on IT security strategy, plus Python and PowerShell automation. I turn noisy telemetry into decisions that scale.
Microsoft Entra ID for more than 200 users, mapped to NIST CSF, ISO 27001, GDPR, NIS2 and DORA. Certified to IAT Level II under DoD 8570.01-M.
[ 02 ]Scope
From 24/7 monitoring of critical national infrastructure to data-driven security operations. Real responsibility, outcomes I can put a number on, and all of it current practice · ready from day one.
TryHackMe · Freelance, Remote
Danquah Institute, Ghana
National Information Technology Agency (NITA), Ghana
Metro TV, Ghana
[ 03 ]Background
Focus: IT Security Strategy
University of Europe for Applied Sciences, Potsdam, Germany
Thesis: a robust cybersecurity framework leveraging GDPR and Zero Trust Architecture. A multi-jurisdictional governance framework applicable to NIS2, DORA, and ISO 27001 compliance.
View degree certificateFoundations in systems, networks & hardware
Ghana Communication Technology University (formerly GTUC), Accra, Ghana
View degree certificate[ 04 ]Evidence
Each capability carries its proof and the context it was earned in. If it can't be evidenced, it isn't listed.
[ 05 ]Evidence
Six certifications, IAT Level II compliant. Each card links to the verifiable credential.
[ 06 ]Proving ground
TryHackMe is where theory meets a real keyboard. Every badge here was earned under pressure.
TryHackMeTop 3% globally. Earned through consistent advanced labs in SOC operations, SIEM analysis, and adversarial simulation.
TryHackMeAdvanced tier recognition for mastery across offensive and defensive security challenges.
TryHackMeIntermediate skill validation across network security, web exploitation, and cryptography.
TryHackMeCompleted the dedicated SOC analyst path: alert triage, threat hunting, and SIEM operations.
TryHackMeAn unbroken 90 day streak. Proof that I show up every single day, not only when it is convenient.
[ 07 ]Case files
Where data-protection law meets never-trust-always-verify.
My master's research designed a cybersecurity framework that brings GDPR compliance together with Zero Trust Architecture. The applied work covered detection logic, access control, and secure data handling across multiple jurisdictions.
Defence-in-depth, modelled on AWS.
A cloud computing project designing a secure, segmented AWS architecture with IAM least privilege, VPC segmentation, security groups, and CloudTrail logging, all documented with a threat model and a risk assessment.
Turning raw data into decisions.
An applied data science and business project: analysing a dataset end to end and turning the findings into a structured report with KPIs and recommendations for stakeholders. It is the same instinct I bring to security metrics.
Product thinking, validated.
An entrepreneurship project that took an idea from a shortlist of 30 down to one pitched concept, with market research, a business model, and an investor deck. Proof that I understand the business security exists to protect.
[ 08 ]Resolution
Whether you're staffing a 24/7 watch floor, a SOC analyst seat, or an incident response team, let's talk about how I can defend your organisation from day one.
// case closed · recommend immediate engagement