Triage Security Engineer 1 — Arctic Wolf

Muhammad Khas

Security engineer working across endpoint, network, and identity threats — from first alert to root cause.

I spend my days triaging real incidents under time pressure, then spend the time after asking why the process let them get that far — and fixing that part too.

BASED_IN Minnesota
FOCUS Detection & incident response
EXPERIENCE 6 years, security & IT

About

I got into security the way most people in this field do — by getting curious about how things break, and then getting stubborn about fixing them properly instead of just patching the symptom. That's carried through a B.S. in Cybersecurity from George Mason, a handful of AWS and CompTIA certifications, and three roles that moved me from general IT support into dedicated security work.

At Arctic Wolf, I triage endpoint, network, and identity alerts for customers who are often in the middle of a bad day. I try to leave every ticket in better shape than I found it — clear evidence, a real explanation, and a fix that holds up. When I notice the same gap causing repeat problems, I write it up and push it through as a process or product fix rather than solving it quietly one ticket at a time.

Outside the queue, I care a lot about the people I work alongside. I've mentored more than half of the Tier 1 team at various points, and I lead cultural and community events at work — Diwali, Lunar New Year, Eid, and others — because I think a team works better when people actually know each other. I was recognized company-wide with Arctic Wolf's Golden Wolf award for that work.

Journey

2024 — Present
Triage Security Engineer 1
Arctic Wolf Networks
2022 — 2024
Security Analyst
Bridgewater Bank
2019 — 2021
System Administrator
Canary Consulting
2016 — 2022
Patient Service Representative
Patient First

Expertise

Detection & response

Alert triage Incident response Threat containment OSINT investigation Packet analysis

Tooling

Wireshark Nmap Elastic / Kibana Microsoft Defender for Endpoint Active Directory

Cloud & infrastructure

AWS Azure Unix / Linux Python

Projects

CASE-04 Account takeover detection quality fix
Traced a pattern of customers getting alerted on multiple account takeovers when only one valid account actually existed — wasted effort and eroded trust on their end. Wrote a formal escalation documenting the gap and expected behavior, which led to a tracked product fix to the correlation and alerting logic.
CASE-03 Alert triage dashboard workflow fix
Noticed analysts were accidentally triggering customer alerts during high-urgency triage because of a confirmation pop-up sitting too close to the "Alert Customer" button. Submitted the service improvement request that got it relocated, cutting down accidental clicks during the moments that matter most.
CASE-02 Triage metrics & collaboration reform
Flagged that hourly individual performance tracking on the triage dashboard was quietly discouraging analysts from helping each other on alerts, since it hurt personal numbers. Raised it with Tier 1 management and proposed a measurement change that rewards collaboration instead of penalizing it.
CASE-01 Practice in Security — hardened LAMP environment
Built a LAMP stack in an Ubuntu VM, attacked it from a Kali Linux VM, then hardened the stack post-infiltration using OWASP Top 10, DISA STIG, and NIST SP 800-53 controls — an ongoing personal lab for testing attack and defense hands-on.

Contact