02Technical Expertise
◉
Security Operations & Monitoring
Designing and operating security monitoring capabilities using SIEM, IDS, endpoint telemetry, and cloud logs to improve visibility, accelerate detection, and support effective incident response.
▲
Detection Engineering & Incident Response
Developing detection logic, correlation rules, IOC-driven analytics, and MITRE ATT&CK-aligned alerting while investigating security events through structured triage and forensic analysis.
◇
Application Security & Threat Modeling
Assessing applications from design through deployment using STRIDE threat modeling, architecture reviews, OWASP methodologies, and risk-driven security assessments.
☁
Cloud & Infrastructure Security
Securing cloud and hybrid environments through identity management, infrastructure hardening, centralized logging, container security, and least-privilege access control.
⚙
Security Automation & DevSecOps
Building automation that integrates security into engineering workflows, enriches security findings, streamlines analyst operations, and reduces response time through repeatable playbooks.
✦
AI Security & Security Research
Exploring adversarial machine learning, malware behavior, firmware security, and emerging attack techniques to strengthen defensive strategies and improve cyber resilience.
OpsShield: Secure Multi-Tenant Application Security Platform
COMPLETED
Contributed as a Cybersecurity Engineer on a cross-functional capstone project alongside Application, DevOps, and Cloud teams to deploy and secure a live multi-tenant SaaS platform. Led Wazuh SIEM detection engineering, manual penetration testing, GitHub Actions security validation, software supply chain security, vulnerability management, and security documentation. Designed and validated detection rules mapped to the MITRE ATT&CK framework while assessing authentication, authorization, webhook security, session management, and application resilience through structured penetration testing.
Wazuh SIEM
Detection Engineering
MITRE ATT&CK
Penetration Testing
Application Security
GitHub Actions
DevSecOps
OWASP
Docker
Software Supply Chain Security
Vulnerability Management
SecOpsAI: AI-Powered Behavioral Threat Detection Platform
COMPLETED
Served as the DevOps Engineer while contributing to the Security Architecture team for an enterprise-scale AI-powered behavioral threat detection platform. Designed and maintained the Docker-based infrastructure, supported CI/CD integration, developed threat modeling documentation, and collaborated across four engineering teams to deliver a Security-by-Design platform integrating machine learning, detection engineering, monitoring, and automated response.
Docker Compose
Kafka
FastAPI
PostgreSQL
MLflow
Prometheus
Grafana
GitHub Actions
STRIDE
MITRE ATT&CK
DevSecOps
FireOps: Enterprise Security Monitoring Platform
COMPLETED
Designed and deployed a centralized enterprise security monitoring
platform providing visibility across endpoints, network traffic,
and AWS infrastructure. Integrated SIEM, IDS, cloud monitoring,
custom detection rules, and automated incident response workflows.
Wazuh
Suricata
Docker
AWS CloudTrail
MITRE ATT&CK
Incident Response
ShieldFlow: AppSec Pipeline & SOAR Automation
COMPLETED
Built an automated application security pipeline integrating
static analysis, dependency scanning, DAST, secret detection,
CVE enrichment, and automated SOAR playbooks to reduce
Mean Time to Triage from hours to minutes.
Python
Semgrep
Trivy
OWASP ZAP
GitHub Actions
SOAR
Project Ghostwire: Adversary Simulation & Network Hardening
COMPLETED
Simulated covert data exfiltration techniques, conducted
packet-level forensic analysis, and designed kernel-level
firewall controls that successfully blocked all simulated
attack scenarios while preserving legitimate traffic.
tcpdump
iptables
Linux
Packet Analysis
Threat Detection
Network Security
WannaCry Malware Behaviour Analysis
COMPLETED
Executed and analysed WannaCry ransomware within an isolated
laboratory environment to investigate process execution,
registry modifications, file encryption workflow,
attacker behaviour, and Indicators of Compromise.
Procmon
Regshot
Wireshark
Malware Analysis
Digital Forensics
IoT Firmware Reverse Engineering & Vulnerability Assessment
COMPLETED
Reverse engineered TP-Link firmware to identify hardcoded
credentials, insecure configurations, outdated software,
and missing exploit mitigations while documenting
realistic attack paths and remediation guidance.
Binwalk
Firmwalker
John the Ripper
checksec
Firmware Analysis
DVWA Web Application Penetration Testing
COMPLETED
Conducted a controlled penetration test against the Damn Vulnerable Web Application (DVWA), identifying exploitable web vulnerabilities, validating exploitation with Metasploit, and documenting remediation recommendations to improve application security.
DVWA
Metasploit
Web Security
OWASP
Vulnerability Assessment
Remediation
ModSecurity WAF Defense Validation
COMPLETED
Evaluated and validated ModSecurity Web Application Firewall protections using OWASP ZAP attack simulations, confirming successful detection and blocking of malicious web requests while preserving legitimate application functionality.
ModSecurity
OWASP ZAP
Web Application Firewall
Apache
Defense Validation
OWASP
Cowrie SSH Honeypot Threat Monitoring
COMPLETED
Deployed and monitored a Cowrie SSH honeypot to capture real-world reconnaissance activity, analyze attacker behavior, and investigate captured network traffic through packet analysis and incident reporting.
Cowrie
Honeypot
Wireshark
Packet Analysis
Threat Intelligence
Incident Response
Cybersecurity Operations & DFIR Labs — VA Cybersecurity Mentorship
COMPLETED
Completed a portfolio of hands-on SOC, SIEM, network analysis, digital forensics, incident response, and GRC investigations during the VA Cybersecurity Mentorship Programme. Work included Splunk-based brute-force investigation, Windows event analysis, PCAP investigation, SOC triage, disk and memory forensics, MITRE ATT&CK mapping, incident escalation, breach reconstruction, and risk assessment.
Splunk
Wireshark
Windows Event Logs
Digital Forensics
Incident Triage
MITRE ATT&CK
Incident Response
GRC