Open to cyber security opportunities

Ria Karakasis

Cyber Security Analyst · Sydney, Australia

I help teams find and fix security weaknesses before they become incidents. Network and endpoint analysis, detection engineering and vulnerability triage, backed by clear reporting that gets remediation moving.

Ria Karakasis, cyber security analyst, smiling in a black blazer

About

Curious by default, careful by design.

I'm a cyber security analyst in Sydney with a Bachelor of Cybersecurity (Distinction) from Macquarie University. Today I work in a technical support and analysis role at 3D Safety Systems, where I identify and triage security vulnerabilities across web and mobile applications, investigate incidents and risks through to root cause, and administer access and configuration across a production platform that construction sites rely on every day.

Along the way I've monitored Microsoft Defender alerts, tightened Google Workspace identity and access, set up DMARC and DKIM, hardened a customer-facing website and CRM, and run phishing simulations that fed straight into awareness training. Before that I spent a year assessing the Wi‑Fi privacy of a live university campus, capturing more than 80,000 802.11 frames and showing how everyday devices leak enough to be tracked.

What ties it together is a habit of turning technical findings into decisions people can act on. Whether it's an executive who needs a risk rating or a site manager who needs their access fixed before the morning toolbox talk, I care about being clear, accurate and easy to work with. I speak English and Greek, and I'm currently building a SIEM from scratch to understand detection from the inside.

What I do

What I bring to a security team.

Six things I do well, proven across a live network assessment, a production support function and self-directed lab work.

Security analysis & threat detection

Capturing and analysing network traffic and endpoint telemetry to spot anomalous activity, privacy leakage and exploitable weaknesses, then building detection logic that maps observed behaviour to MITRE ATT&CK techniques.

Frameworks, policy & governance

Assessing control coverage against the ASD Essential Eight and CIS Critical Security Controls, rating likelihood and impact, and turning framework requirements into policy, standards and remediation roadmaps that owners can actually action.

Incident handling & procedural discipline

Triaging, investigating and resolving defects, incidents and risks in a live production environment, with disciplined handling of sensitive data and accurate, auditable documentation at every step.

Automation & tooling

Python and PowerShell scripts for log collection, parsing security events and querying large datasets for indicators of compromise, plus isolated virtual labs across Windows, Linux and macOS for controlled testing.

Communication & reporting

Formal assessment reports, dashboards and presentations that give leadership visibility and support risk-informed decisions, alongside front-line experience explaining policy to people who don't speak security.

Adaptability & problem solving

Comfortable picking up unfamiliar tooling, adjusting as scope and priorities shift, and coordinating vendors, internal teams and external stakeholders until the outcome is delivered.

Experience

Where I've put it to work.

From a live campus network assessment to a production platform used across construction sites.

  1. → present

    Construction safety technology · Sydney

    System Support Analyst 3D Safety Systems

    3D Safety Systems builds site induction, compliance and workforce management software for construction. I identify, triage and document security vulnerabilities and defects across its web and mobile apps, act as the escalation point for incidents and risks, and administer access and configuration for incoming projects, with sensitive workforce data handled to a regulated standard.

    • Vulnerability triage
    • Incident escalation
    • Access administration
    • Root cause analysis
    • Vendor coordination
    Full detail
    • Identify, triage and document security vulnerabilities and defects across web and mobile applications, assessing exploitability and business impact and tracking remediation through to closure.
    • Serve as an escalation point for incidents, issues and risks raised by clients and internal stakeholders, prioritising by severity and maintaining an auditable record of investigation and resolution.
    • Administer application configuration and user access for incoming construction projects, provisioning accounts and permissions and maintaining accurate change records.
    • Reproduce and investigate reported issues across web, mobile and Windows environments, using application logs and user activity records to establish root cause.
    • Handle sensitive workforce and site compliance data on behalf of construction clients, applying disciplined data handling and record keeping in a regulated industry.
    • Coordinate with third-party vendors and delivery partners across concurrent projects, tracking dependencies and translating technical status for non-technical audiences.
  2. Consumer goods · fitness supplements

    Cyber Security Analyst Loaded Candy

    Hands-on security for a growing consumer brand: monitoring Microsoft Defender detections across endpoints, tightening Google Workspace identity and access, authenticating outbound mail with DMARC and DKIM, hardening the website and CRM, and running phishing simulations that fed targeted awareness training.

    • Microsoft Defender
    • Google Workspace IAM
    • DMARC / DKIM
    • Phishing simulation
    • Attack surface reduction
    Full detail
    • Monitored Microsoft Defender alerting across endpoints, triaging detections and escalating or remediating as required.
    • Supported administration of Google Workspace, maintaining identity and access management policies and least-privilege permissions across user accounts.
    • Configured and maintained DMARC and DKIM records to authenticate outbound email and reduce the risk of domain spoofing and business email compromise.
    • Hardened the company website and secured the CRM platform, reviewing configuration and access controls to reduce the external attack surface.
    • Designed and ran simulated phishing campaigns across the employee base, using the results to target follow-up training and ongoing cyber awareness communications.
  3. PACE industry internship · School of Computing

    Cyber Security Analyst Macquarie University

    An end-to-end Wi‑Fi security assessment of the live campus network, from scoping the engagement with the project sponsor to a formal technical report and stakeholder presentation. The full write-up is in the case studies below.

    • Wireshark
    • Kismet
    • Aircrack-ng
    • Bettercap
    • WiGLE API
    • Essential Eight
    • CIS Controls
    • ATT&CK
    Full detail
    • Delivered the engagement end to end against the live Macquarie University campus network, scoping the assessment and agreeing objectives with the project sponsor.
    • Captured and analysed over 80,000 IEEE 802.11 frames using Wireshark, Kismet, Aircrack-ng and Bettercap across Kali Linux and Raspberry Pi platforms.
    • Identified SSID probe request leakage and device fingerprinting weaknesses, using the WiGLE API to geolocate broadcast SSIDs and demonstrate that roughly 1 in 6 observed devices lacked MAC address randomisation.
    • Assessed likelihood and impact of each finding and mapped mitigations to the ASD Essential Eight, CIS Critical Security Controls and MITRE ATT&CK.
    • Recommended practical controls including enforced MAC address randomisation, SSID broadcast hygiene and targeted user awareness guidance.
    • Produced a formal technical report and delivered a stakeholder presentation setting out findings, risk ratings and a prioritised remediation roadmap.
  4. Retail & events

    Sales & Customer Service Officer Loaded Candy

    Where I learned to explain things clearly to people who don't care about the technical detail. Built customer and stakeholder relationships that drove repeat business, secured product placement in Chemist Warehouse, and sold out pop-up inventory at the Australian Fitness Expo in Sydney and Wollongong.

    • Stakeholder relationships
    • Customer service
    • Brand activations

Case studies

Selected work.

Two pieces of work that show how I think: a live network assessment and a SIEM built from scratch.

Case study 01 · 2024

Campus Wi‑Fi privacy assessment

  • Client Macquarie University
  • Scope Live campus network
  • Role Analyst, end to end

Wi‑Fi devices are chatty. When a phone looks for networks it has joined before it can broadcast their names, and if its hardware address never changes, anyone listening can follow it around. I was asked to find out how much of that was happening on a live university campus, and what to do about it.

Working from Kali Linux on a Raspberry Pi with Wireshark, Kismet, Aircrack-ng and Bettercap, I captured over 80,000 IEEE 802.11 frames and pulled apart the probe requests. Using the WiGLE API I geolocated the SSIDs devices were broadcasting, showing how a leaked network name can place a person at a home, a workplace or a gym. Roughly one in six devices observed was not randomising its MAC address at all.

Each finding was rated for likelihood and impact and mapped to the ASD Essential Eight, CIS Critical Security Controls and MITRE ATT&CK. The engagement closed with a formal technical report, a presentation to the project sponsor and a prioritised roadmap: enforced MAC address randomisation, SSID broadcast hygiene and targeted user awareness.

Capture summary Kali Linux · Raspberry Pi

Frames
80,000+ · IEEE 802.11
Tools
Wireshark · Kismet · Aircrack-ng · Bettercap
Enrichment
WiGLE API geolocation
Rating
Likelihood × impact per finding

1 in 6 observed devices (16.6%) were not randomising their MAC address.

  • SSID probe request leakage → SSID broadcast hygiene
  • Devices without MAC randomisation → Enforce randomisation
  • Broadcast SSIDs geolocatable via WiGLE → User awareness

Case study 02 · 2026

Ria's SIEM: detection from the ground up

  • Type Proof of concept
  • Stack Python · Flask · SQLite
  • Source GitHub

The best way to understand a SIEM is to build one. Ria's SIEM is a small but complete pipeline: a Windows agent that collects Security, System and Application event logs, a Flask API that ingests and indexes them into SQLite, and a web dashboard for querying and visualising what comes in.

The query layer supports filtering and full-text search across source host, Event ID, log type, severity and time range, which is enough to work real detection use cases: failed logon activity, new process creation and service installation.

I also documented what it would take to trust it in production, because a proof of concept that pretends to be finished is a liability. There is no authentication, no TLS, no input validation hardening, no rate limiting and no log integrity verification, and the README spells out exactly which controls close those gaps.

Architecture Agent → API → store → dashboard

Ria's SIEM architecture Windows agents send event logs over HTTP as JSON to a Flask API server, which stores them in SQLite and serves a web dashboard for querying. Detection use cases include failed logon activity, new process creation and service installation. Windows agents Security · System · Application event logs HTTP / JSON Flask API server /api/logs · /api/stats · /api/hosts SQLite store Indexed by host, event ID and time Web dashboard Filters · full-text search · statistics Failed logon New process New service

Projects

Shipped to GitHub.

Pulled live from github.com/ria-kara. Every card links straight to the source.

Connecting to GitHub…

Ria's SIEM dashboard showing event statistics and a filtered log table

Ria's SIEM

Ria's SIEM is a lightweight Python-based Security Information and Event Management (SIEM) proof of concept that collects Windows Event Logs, stores them in a central database, and provides a web dashboard for querying and visualising security events. Built for educational purposes to demonstrate core SIEM concepts and log monitoring.

Updated Sept 2026

Python

Skills

Tools I reach for.

Grouped the way they show up in a working day: what I analyse with, what I measure against, and what I build with.

Security tools

  • Wireshark
  • Kismet
  • Aircrack-ng
  • Bettercap
  • WiGLE API
  • Microsoft Defender

Frameworks

  • ASD Essential Eight
  • CIS Critical Security Controls
  • MITRE ATT&CK

Programming & scripting

  • Python
  • PowerShell
  • SQL
  • Java
  • JavaScript
  • TypeScript
  • React
  • HTML
  • CSS

Platforms & systems

  • Windows 10 / 11
  • Linux (Kali)
  • macOS
  • Raspberry Pi
  • SSH
  • Google Workspace

Collaboration

  • Jira
  • Confluence
  • Microsoft 365
  • Teams

Education

Credentials.

2022 – 2025

Bachelor of Cybersecurity

Macquarie University, Sydney

Graduated with Distinction. Included a PACE industry internship delivering a live Wi‑Fi security assessment for the university's own campus network.

Distinction

2021

Higher School Certificate

Ryde Secondary College

ATAR of 98.5, placing in the top two percent of the state.

ATAR 98.5

Contact

Let's talk.

Hiring for a security analyst, want a second pair of eyes on a problem, or just keen to talk detection and Wi‑Fi privacy? My inbox is open.

Based in Sydney, Australia · open to cyber security roles