A Arthur Henrique

Senior Incident Response Analyst

Arthur Henrique

Senior Incident Response Analyst

Incident Response • DFIR • Cloud IR • Detection Engineering • SOAR Automation

IR Enterprise incident response and SecOps coordination
DFIR Evidence collection, timeline analysis and investigation support
Hunt Threat hunting guided by TTPs, telemetry and hypotheses
SOAR Automation workflows, APIs and operational engineering

About

Technical investigation with operational discipline.

I am a cybersecurity professional focused on enterprise Incident Response, SOC operations, DFIR support, cloud and identity investigations, threat hunting, detection engineering and SOAR automation.

01

Incident Response

Incident validation, scope, containment priorities, evidence preservation and coordination across security operations.

02

Cloud and Identity IR

Investigations across identity, SaaS and cloud telemetry with attention to access paths, abuse patterns and exposure.

03

Threat Hunting

Hypothesis-led hunts mapped to adversary behavior, abnormal activity, persistence, lateral movement and exfiltration signals.

04

Detection Engineering

Turning investigation findings into detections, queries, dashboards and measurable improvements to response workflows.

Experience

Senior Response Analyst focused on response quality and automation.

Wabtec Corporation Current focus

Senior Response Analyst

Incident Response, SOAR automation, cloud and identity investigations, detection engineering, DFIR support, threat intelligence and security operations metrics.

Previous roles SOC

Response Analyst and Cybersecurity Operations Intern

Hands-on experience with SIEM, EDR/XDR, alert triage, case management, evidence collection and operational security workflows.

Selected Impact

Measured improvements and public contribution.

75%

Less manual triage effort

Reduced manual triage effort through SOAR automation and evidence enrichment.

30%

Faster response SLA

Improved Incident Response SLA through automated evidence collection, enrichment and alert correlation.

DBIR

Public research contribution

Active contributor to the Verizon Data Breach Investigations Report, DBIR 2026.

Ops

Operational visibility

Designed dashboards and metrics to improve visibility into cyber defense operations.

Skills

Security operations, investigation and engineering toolkit.

Incident Response SOC Operations DFIR Cloud IR Threat Hunting Threat Intelligence Malware Triage Detection Engineering SOAR Automation SIEM EDR/XDR Splunk Splunk ES Splunk SOAR Microsoft Defender Microsoft Defender for Endpoint Entra ID AWS CloudTrail GuardDuty GCP Logs MISP ServiceNow SecOps Power BI Python REST APIs SPL KQL Sigma YARA MITRE ATT&CK

Labs & Tools

Hands-on environments and investigation tooling.

KL

Kali Linux

Security lab environment for analysis, validation and offensive awareness.

HTB

Hack The Box

Practical scenarios for adversary behavior, exploitation paths and defense perspective.

THM

TryHackMe

Structured practice across fundamentals, SOC workflows and cyber defense topics.

Education

B.S. in Computer Science

PUC Minas, 2021 - 2027.

Languages

Portuguese and English

Portuguese: Native/Bilingual. English: Full Professional.

Contact

Open to conversations about DFIR, SecOps and security automation.

The public contact channel for this portfolio is GitHub.