alois.beyou()

Aloïs Beyou

Network, Telecommunications & Cybersecurity Engineer

Graduate from the University of Technology of Troyes (UTT). Specialized in Blue Teaming, vulnerability management, and defensive operations (SOC/SIEM). Currently implementing Security by Design practices to build resilient systems.

Paris, FranceUTT Engineer

Technical Projects

AI-Driven SOC Alert Triage Tool

Code

Development of an AI-integrated application to analyze, process, and contextualize raw security alerts.

PythonAI APIAutomation

Azure Honeypot Architecture & SIEM SOC

Code

Creation of a hybrid security laboratory connecting an Azure cloud Honeypot to an on-premise SIEM via a Tailscale VPN.

AzureWazuhTailscaleSIEM

Linux VM Network Architecture

Design and configuration of a local network of Linux virtual machines using exclusively Bash scripts.

LinuxBashVirtualization

Professional Experience

Security by Design Consultant - InternshipCurrent

HeadMind Partners

  • Risk assessment and threat modeling to define security requirements right from the design phase.
  • Supporting technical teams on the implementation of Security by Design to ensure compliance.
  • Integrating security milestones into the project lifecycle, with validation of deliverables prior to production deployment.
February 2026 — July 2026

Systems and Networks Security Engineer - Internship

Goûters Magiques

  • Deployment of WithSecure Vulnerability Management, ensuring compatibility with EDR for continuous detection.
  • Implementation of a network monitoring stack using Prometheus and Grafana, improving infrastructure visibility.
  • Coordinating patch management with the IT Infrastructure team to enforce security standards.
  • Managing security projects via SuitePro-G, ensuring precise task tracking and cross-team communication.
July 2024 — December 2024

Certifications & Credentials

Cisco CCNA

Certified

Cisco

Cisco Certified Network Associate (CCNA 200-301) covering IP networking, security fundamentals, automation, and routing & switching.

Category: NetworkingIssued: 2024

Hack The Box CDSA

In Progress

Hack The Box

Certified Defensive Security Analyst (CDSA) focused on SOC operations, SIEM detection engineering, digital forensics, incident response, and threat hunting.

Category: Cybersecurity

ISC2 CC

In Progress

ISC2

Certified in Cybersecurity entry-level credential validating foundational knowledge in security principles, business continuity, access controls, and network security.

Category: Cybersecurity

C1 Advanced (CAE)

Certified

Cambridge English

Cambridge English Advanced (C1 Level) certifying high-level operational proficiency in professional and technical English environments.

Category: Languages

DELE C1

Certified

Instituto Cervantes

Diploma de Español como Lengua Extranjera (C1 Level) certifying operational fluency in spoken and written Spanish.

Category: Languages

Education

Engineering Degree in Networks & Telecommunications

University of Technology of Troyes (UTT)

Specialization: Cybersecurity and system architectures

2021 — 2026

Academic Exchange Semester

Aalto University (Helsinki, Finland)

Focused on advanced networking, malware analysis, and international collaboration

Jan 2025 — June 2025

French Baccalaureate

Lycée Français de Valence (Spain)

Complete schooling in a trilingual and multicultural environment (French, Spanish, English)

Graduated 2021

Security Lab & Infrastructure

Blue Team / Telemetry

Hybrid Threat Hunting & Detection Lab

Blue Team / SOC Lab Environment

Proxmox VEpfSenseActive DirectoryWazuh SIEM

Virtual enterprise network running an Active Directory domain, automated attack simulation, and centralized telemetry collection through Wazuh SIEM and Elastic Stack.

Lab Network Topology & Telemetry FlowProxmox VE Hypervisor
Attack Emulation Zone

Kali Linux / Caldera

Atomic Red Team TTPs

pfSense & Corporate Subnet

Windows Server 2022 AD

Sysmon + PowerShell Logging

Ubuntu Workstation

Wazuh Agent & Auditd

SOC Telemetry Stack

Wazuh Manager

Rule Engine & Alerting

Elasticsearch + Kibana

Dashboards & Threat Maps

Simulated Threats
Encrypted Logs (TLS)
Sigma / Wazuh Detections

Architecture Overview

  1. Edge Security & Routing (pfSense): Isolates the attack generation network, corporate LAN, and management VLAN.
  2. Identity & Directory (Windows Server 2022 AD): Configured with audit logging (Sysmon + PowerShell Script Block logging) enabled.
  3. Attack Emulation (Kali / Atomic Red Team): Simulates TTPs mapped to the MITRE ATT&CK matrix (Credential Dumping, Lateral Movement, Persistence).
  4. Telemetry & Detection (Wazuh / Elastic SIEM): Real-time event ingestion, rule tuning, and custom Sigma rule testing.

Interests & Hobbies

Capture The Flag (CTF)Threat Hunting Lab BuildingMusic (Drums, Guitar and DJing)Scripting & AutomationBasketball