About Me
I am a recent Master’s graduate with four years of hands-on experience in SOC operations, application security, and DevSecOps. Throughout my career, I have developed expertise in threat detection, secure code review, CI/CD pipeline security, and automation. I have a proven track record of reducing vulnerabilities and enhancing the security posture across complex environments.
I am highly skilled in collaborating across teams to drive cross-functional initiatives and deliver secure, scalable solutions. My technical proficiency includes programming in Python, PowerShell, C, SQL, and Bash, along with extensive experience using security tools such as Elastic SIEM, Metasploit, Burp Suite, and Palo Alto Firewall.
I have worked with cloud and DevSecOps platforms including AWS, Azure, Docker, Kubernetes, Terraform, Jenkins, and SonarQube. I am also knowledgeable in compliance frameworks such as NIST 800-53, ISO 27001, HIPAA, MITRE ATT&CK, and OWASP Top 10. I hold certifications including CompTIA Security+ and CySA+.
In my recent role as an Application Security Engineer, I conducted secure code reviews, implemented SAST scanning, and remediated numerous vulnerabilities. I have built secure data transfer services and enhanced authentication protocols using advanced technologies like SPIFFE-based mTLS and JWT authorization.
My internship experiences have strengthened my skills in log analysis, threat hunting, automation scripting, and incident response. I have contributed to improving alert fidelity and automating security workflows, which accelerated investigation processes and enhanced threat response capabilities.
I am passionate about continuous learning and have engaged in academic projects involving malware analysis, reverse engineering, SIEM and SOC home labs, forensic analysis, and secure CI/CD pipelines. I actively volunteer in cybersecurity communities, supporting event coordination and fostering professional networking.
I am eager to leverage my skills and experience to contribute to a forward-thinking organization focused on advancing security operations and protecting critical assets.
Skills
PythonSQLJavaScriptKubernetesDockerAzureJiraTerraformAgileAutomationTCP IPC
Experience
Conducted secure code reviews and implemented SAST with Semgrep, scanning 15K+ lines of Python and C++ code; remediated 40+ vulnerabilities and reduced critical findings by 35%. Implemented SmartChain QUIC enhancements (Python, aioquic) to enable passwordless SmartID authentication, encrypted policy distribution, and low-latency TLS 1.3 communication. Built a Secure Data Transfer Service with SPIFFE-based mTLS and JWT authorization, enabling user-consented document exchange while ensuring compliance and privacy.
Ingested and analyzed security logs from Palo Alto firewalls and Docker containers for File Integrity Monitoring (FIM) using Elastic SIEM’s FileBeat and MetricBeat, enhancing incident response and threat identification. Created and tuned 20+ correlation rules in Elastic SIEM (KQL) to detect threats (e.g., lateral movement, credential abuse), improving alert fidelity by 40%. Developed a Python script to automate parsing and enrichment of log data from Elastic SIEM, reducing manual effort in daily investigations and accelerating initial triage workflows by 30%.
Developed applications in Python and JavaScript with unit and integration tests, applying OWASP practices (input validation, encryption) and integrated OWASP ZAP/SonarQube into CI/CD to reduce vulnerabilities. Engineered and deployed a Threat Hunting Content Pack on Cortex XSOAR using Python, automating incident retrieval, playbooks, and dashboards for analysis. Resolved 300+ Jira issues and collaborated with cross-functional teams to enforce NIST, HIPAA, GDPR; contributed to Agile ceremonies and peer code reviews, achieving 100% compliance in quarterly audits.
Developed secure apps with JavaScript, Node.js, and Python; used Semgrep for static code analysis to fix XSS and SQL Injection vulnerabilities. Supported security reviews and research. Integrated Rubrik, Bitsight, and Flashpoint with Cortex XSOAR to automate workflows and enhance threat response using Python and REST API, automating security workflows and enhancing threat response capabilities. Conducted threat research and documented recurring vulnerabilities and secure coding practices aligned with the OWASP Top 10, building reusable knowledge bases that accelerated future security assessments.
Education
Master of Science in Cybersecurity
3.91 GPA; Relevant Coursework: Malware Analysis, AI/ML for Cybersecurity, Mobile Forensics, Automation with Python; ISC2 Graduate Scholarship Winner (2024) for academic excellence; CTF – NCL 2025: Ranked 171/600
Bachelor of Engineering in Computer Science
Relevant Coursework: Operating Systems, Computer Networks, Database Systems, OOP, Data Structures and Algorithms
This professional hasn’t added portfolio projects yet.
This professional hasn’t listed any services yet.