Security Operations // Threat Intelligence

Zeynep Burcu Topaloglu

Senior Cybersecurity Defense Analyst — Threat Hunting & Threat Intelligence

I build hunting programs that turn adversary intelligence into detections — grounded in MITRE ATT&CK, run against real telemetry, and closed into standing coverage rather than one-off findings

01 — Profile

Building CTI and hunting capability from the ground up

Senior Cybersecurity Defense Analyst with 8+ years of experience specializing in Threat Hunting, Cyber Threat Intelligence, and Detection Engineering. I've established Cyber Threat Intelligence capabilities from scratch, defined the Priority Intelligence Requirements that keep them relevant, and led intelligence-driven hunting campaigns that translate adversary research into new detection coverage across Microsoft Sentinel and Defender XDR. Alongside the technical work, I mentor analysts and share hunting methodology as security operations teams mature.

02 — Log

Experience

Reverse-chronological, from first SOC role to current threat hunting leadership.

Apr 2025 —
Present

Senior Global Cybersecurity Defense Analyst — UL Solutions

Leading the evolution of the organization's Threat Hunting program: hunting methodology, detections informed by adversary TTPs, and mentoring analysts as the Cyber Defense team's capability matures.

Mar 2023 —
Apr 2025

Global Cybersecurity Defense Analyst — UL Solutions

Established and operationalized the organization's CTI capability — PIRs, strategic and tactical advisories, adversary profiling, and intelligence-driven hunting campaigns that fed directly into Sentinel detection improvements.

Oct 2022 —
Mar 2023

Digital Security Analyst — UL Solutions

Primary escalation point for Level 1 analysts; investigated incidents across Defender, Carbon Black, and ATA, and led post-incident reviews to improve response process.

Jun 2020 —
Aug 2022

Cybersecurity Analyst — SabanciDx

24/7 MSSP SOC — tuned SIEM detections against MITRE ATT&CK, managed log source onboarding, and led customer-facing reviews against client risk objectives.

Jul 2018 —
Jun 2020

IT Security Assistant Specialist — Aviva

Managed enterprise DLP, led vulnerability management, and coordinated penetration testing across international teams.

03 — Coverage

Expertise matrix

Organized the way I organize a hunt program: by capability area, not job title.

Threat Hunting

  • MITRE ATT&CK mapping
  • Hunting methodology design
  • Hypothesis-driven hunting
  • Adversary & actor research

Threat Intelligence

  • PIR development
  • Strategic & tactical advisories
  • Executive briefings
  • Threat actor profiling

Detection Engineering

  • Microsoft Sentinel
  • KQL
  • Defender XDR
  • Analytic tuning & automation

Incident Response

  • Phishing investigations
  • Post-incident review
  • Escalation & triage
  • Containment & remediation
04 — Playbook

From intelligence to hunt

The framework I use to turn a Priority Intelligence Requirement into a testable hunting hypothesis — and, when it succeeds, a standing detection.

PIR

Start from a business question, not a technique

"Let's hunt for lateral movement" is a topic, not a hypothesis. A Priority Intelligence Requirement — e.g. "are we likely to be targeted by ransomware affiliates using exposed RDP?" — keeps the hunt tied to real organizational risk.

MAP

Translate the PIR into adversary behavior via ATT&CK

Take a well-documented actor's known techniques — initial access, discovery, lateral movement, defense evasion — and map each to the PIR at hand.

HYPOTHESIZE

Write a hypothesis with three parts

The behavior, the expected telemetry, and the condition that would prove or disprove it. A testable hypothesis makes even a "nothing found" hunt informative.

BUILD

Graduate the hunt into a standing detection

A hunt that finds something once and is never operationalized is a missed opportunity. Successful hunts become tuned KQL analytics in production.

CLOSE

Log the outcome and the coverage delta

Document what was hunted, what was found, and what changed in detection coverage — the real measure of hunting maturity over time.

05 — Credentials

Certifications, languages & recognition

Certifications

CEH CTIA CSA IBM QRadar SIEM Foundation IBM Resilient SOAR Foundation CNSS — ICSI
CEO Award — UL Solutions

Recognized for outstanding contributions to cybersecurity initiatives, operational excellence, and organizational impact.

Languages

Turkish — Native English — Full Professional Korean — Limited Working

Education

BSc, Management Information Systems — Bogazici University