Application - Cyber Defence Analyst - PwC New Zealand

Built to detect,
trained to investigate,
ready to grow.

I have spent the past year building a genuine foundation in security operations and cyber defence - learning the craft of monitoring, analysis, and incident response from the ground up.

Security Operations Incident Response Threat Analysis MITRE ATT&CK Network Forensics Security+ Booked 26 Jun NZ Permanent Resident

Why this role, why this team

What draws me here

PwC's Managed Cyber Defence team works on meaningful security challenges for some of New Zealand's largest organisations. The identity-led managed defence model, the client-facing nature of the work, and the explicit commitment to training people who are passionate about growing - that combination is exactly what I am looking for. I am not applying here as a fallback. This is the team I want to build my career in.

What I bring

Strong analytical skills and genuine attention to detail, the ability to identify trends and indicators of compromise across complex data sets, and the communication skills to provide clear technical guidance to non-technical stakeholders. I document everything meticulously - every investigation on my GitHub shows how I think, how I structure analysis, and how I communicate findings. That discipline maps directly to PwC's client-facing model.


Technical skills

Cyber defence and operations

  • Security event monitoring and analysis
  • Incident response and triage
  • Threat analysis and hunting
  • IOC identification and data analysis
  • MITRE ATT&CK framework
  • SIEM fundamentals (Splunk, ELK)
  • EDR concepts (Sentinel, CrowdStrike)

Forensics and investigation

  • Wireshark and network forensics
  • Windows event log analysis
  • Sysmon process tree analysis
  • Log correlation and pattern analysis
  • Persistence mechanism detection
  • Phishing payload analysis
  • Identify trends in security data

Systems and automation

  • Windows internals and Active Directory
  • Windows Defender concepts
  • PowerShell scripting and automation
  • Python for process automation
  • Microsoft 365 and Entra ID
  • Cloud services (Azure)
  • Written and verbal communication

SOC investigation work

All investigations documented with methodology, evidence, and findings - github.com/Aryaghaem/tryhackme-scripts-labs

Threat Detection

Command and Control detection

Identified C2 beaconing patterns and active communication channels in network traffic - isolating callback intervals and mapping the active channel to attacker infrastructure.

MITRE ATT&CK - T1071 Application Layer Protocol
Persistence

Registry run keys and startup persistence

Detected malicious registry modifications and startup folder entries used to maintain access across reboots - tracing the full persistence chain from execution to re-launch.

MITRE ATT&CK - T1547 Boot or Logon Autostart Execution
Persistence

Malicious services and scheduled tasks

Investigated attacker-created Windows services and scheduled tasks, distinguishing malicious entries from legitimate system activity through event log correlation and timestamp analysis.

MITRE ATT&CK - T1053 Scheduled Task/Job
Network Forensics

DNS tunneling detection

Used Wireshark to identify DNS exfiltration - analysing query entropy, subdomain length patterns, and query frequency to surface the data leakage channel and reconstruct exfiltrated content.

MITRE ATT&CK - T1048 Exfiltration Over Alternative Protocol
Network Forensics

Log4Shell exploitation detection

Identified Log4j RCE exploitation attempts in network traffic - JNDI lookup strings, outbound callback patterns, and post-exploitation indicators of compromise including reverse shell activity.

MITRE ATT&CK - T1190 Exploit Public-Facing Application
Initial Access

Phishing payload analysis via Sysmon

Traced phishing-delivered malware through Sysmon process creation events, network connections, and file drop artefacts - reconstructing the full execution chain from email to persistence.

MITRE ATT&CK - T1566 Phishing
Discovery

Internal reconnaissance and trend analysis

Identified post-compromise discovery activity by analysing trends in command execution patterns - net commands, whoami, ipconfig abuse - correlating events to map the attacker's enumeration phase.

MITRE ATT&CK - T1087 Account Discovery

How I map to what you need

Monitor and analyse security events, identify trends

20+ documented investigations covering event monitoring, data analysis to identify trends and indicators of compromise, and threat analysis across Windows and network environments.

Provide technical guidance to client organisations

Every lab investigation is written up with clear findings communicated for a non-technical audience. My current IT support role involves providing technical guidance to business clients daily.

Python, PowerShell, and process automation

Working knowledge of PowerShell for scripting and system administration, and Python basics for data analysis and process automation - both used in lab investigations and IT support work.

Windows internals, Defender, Active Directory

Practical hands-on experience with Windows environments from both an investigation and administration perspective - understanding the systems PwC's clients run from the inside out.

Certifications and study

CompTIA Security+

Booked 26 Jun

Exam booked - 26 June 2026 - threats, cryptography, IAM, network security, risk management

TryHackMe SOC Level 1

Target July 2026

20+ labs completed - SOC operations, threat detection, incident response, network forensics

Google Cybersecurity Certificate

Completed

Coursera - Dec 2025 - coursera.org/account/accomplishments/specialization/CTLYS2V86SFL

Information Technology - Unitec

Graduating June 2026

Networking, system administration, information security, Windows Server


Professional background

Feb 2026 - Present

Remote, part-time

Junior IT Support Technician

Whizz-IT Ltd
  • Monitoring systems and triaging technical incidents across Windows environments - identifying root causes and documenting findings
  • Providing technical guidance to client organisations - translating complex technical findings into clear written and verbal communication
  • Managing user identities and access in Active Directory and Entra ID with security best practices
  • Supporting patch management and security hygiene across multiple client environments
Dec 2025 - Feb 2026

Hybrid, Auckland

IT Apprentice

Pacific Net Ltd - Cloud Services Provider
  • Supported Microsoft 365, Azure-based cloud services, and enterprise IT operations
  • Assisted engineers with system configuration, infrastructure monitoring, and security hygiene
  • Developed understanding of enterprise environments, workflows, and documentation standards

Let's talk about the role.

I am applying for the Cyber Defence Analyst position at PwC New Zealand and would welcome the opportunity to discuss how I can contribute to your Managed Cyber Defence team.