Bonaventure Orock
Bonaventure Orock

Product Security Analyst

Open to offers · Member since 8 Sep 2026
Message
Location
United States
Desired salary
Unspecified
Work preference
Remote Only
Experience level
Senior

About

Professional summary

I am a cybersecurity engineer with more than seven years of experience in vulnerability management, cloud security, application security, incident analysis, and security automation.

I validate security findings, assess exploitability and business impact, prioritize remediation, and provide clear technical guidance to engineering and security stakeholders. My work is grounded in OWASP Top 10, CVSS, NIST 800-53, CIS Benchmarks, and risk-based security principles.

I have hands-on experience securing AWS and Azure environments, including cloud configurations, identity and access controls, network exposure, encryption, logging, and secure deployment practices. I have used tools such as Qualys, Nessus, AWS Inspector, Microsoft Sentinel, Splunk, Defender for Cloud, and AWS Security Hub.

I build automation with Python, PowerShell, Bash, and REST APIs to improve evidence collection, vulnerability reporting, security validation, access reviews, and repeatable operational workflows.

I also bring strong investigation and communication skills from SOC and cloud security roles. I translate technical findings into concise remediation guidance, incident summaries, risk documentation, and validation evidence that supports timely issue closure.

Skills

31 capabilities

Tech stack & tools

Working toolkit

Development

Monitoring

Experience

Career history

Cloud Security Engineer Clarivate

Performed security assessments, threat modeling, vulnerability analysis, and technical design reviews for cloud-hosted applications and infrastructure. Documented exploitability, business impact, and remediation priorities.

Validated vulnerability and configuration findings from AWS Inspector, CSPM tooling, and penetration-test outputs. Coordinated remediation through ServiceNow and Git-based workflows while applying OWASP Top 10, NIST 800-53, CIS Benchmarks, and risk-based security principles.

Developed Python, PowerShell, Bash, and REST API automation for evidence collection, vulnerability reporting, security validation, and repeatable workflows. Produced technical documentation, remediation guidance, risk summaries, and security findings for stakeholders.

Security Engineer Cisco Corporation

Improved cloud security posture from 78% to 95% through attack-path analysis, Azure Policy, Defender for Cloud, Entra ID, RBAC, security reviews, and coordinated remediation.

Performed vulnerability analysis using Qualys and cloud-security telemetry, validated findings in technical context, prioritized issues by exploitability and business risk, and reduced high-risk vulnerabilities by 28%.

Reviewed application and cloud security controls across Azure environments and automated security validation, evidence gathering, access reviews, and reporting with PowerShell and Azure-native tooling.

Security & Cloud Engineer Micron Technology

Deployed and operated Nessus vulnerability scanning for critical systems, validated findings, coordinated remediation with technical owners, and eliminated 32% of high-risk configurations.

Analyzed AWS CloudTrail, CloudWatch, and Security Hub telemetry to investigate suspicious activity, access anomalies, configuration weaknesses, and cloud-security findings.

Provisioned standardized AWS infrastructure with CloudFormation, embedding IAM, encryption, logging, network controls, and secure configuration into repeatable deployment patterns. Reviewed Linux, Windows, network, and cloud configurations and produced remediation documentation.

SOC Analyst PNC Financial Services

Investigated and resolved more than 200 security events annually across over 3,000 endpoints using Microsoft Sentinel and Splunk. Analyzed evidence, determined incident scope and impact, and coordinated response actions.

Performed phishing, authentication, network, and endpoint investigations by correlating telemetry from multiple sources. Supported vulnerability-management workflows by validating findings, coordinating remediation, and tracking corrective actions.

Conducted root-cause analysis and produced incident summaries, technical findings, and remediation recommendations, contributing to an 18% reduction in repeat incidents.

Education

Learning history

Western Governors University (WGU)

Bachelor of Science, Cybersecurity and Information Assurance

Polytechnic

Associate Degree, Technology

This professional hasn’t added portfolio projects yet.

This professional hasn’t listed any services yet.

People also viewed

All talent ›
Jobs Talent AI Tools Salaries
Menu