Cybersecurity Analyst

Florian Roth Portfolio

Maintainer of Sigma, the open standard for writing SIEM detection rules (over 11,000 GitHub stars), plus signature-base and APTSimulator — a body of open-source detection engineering used across the SOC and threat-hunting community.

SIEMDetection EngineeringSigma RulesThreat Hunting

What makes it work

A breakdown of the choices that make this portfolio stand out.

1

An open standard, not just a personal tool

Sigma is a detection-rule format adopted broadly across the SIEM and SOC tooling ecosystem, not a one-off script — building shared infrastructure for an entire field is a rare and significant credential.

2

Multiple, complementary open-source projects around one theme

Sigma (detection rules), signature-base (YARA/IOCs), and APTSimulator (attack simulation) all address different angles of the same detection-engineering problem, showing a coherent research program rather than disconnected side projects.

3

Adoption visible through concrete numbers

Star and fork counts in the thousands across these repositories function as an inspectable adoption metric, doing more to establish credibility than any self-description could.

What Cybersecurity Analysts can take from this

Specific, actionable tips to apply to your own portfolio — no generic advice.

  • If you can generalize a personal tool into a shared format or standard others can adopt, that is a far stronger credential than a one-off script solving your own problem.

  • Build a family of related open-source projects around one theme rather than scattering unrelated repositories — coherence makes the body of work legible at a glance.

  • Let concrete, checkable numbers (stars, forks, downloads) demonstrate adoption instead of describing your tools as "widely used."

Ready to build your portfolio?

Follow the Cybersecurity Analyst roadmap — skills, projects, and timeline to get hired.

Cybersecurity Analyst Roadmap