Work Experience
Security Analyst I
Novacoast Inc., Wichita, KS (Nov 2024 – Present)
- Monitor and analyze security events across multiple SIEM platforms including Splunk Enterprise Security, IBM Qradar, CrowdStrike LogScale and LogRhythm.
- Perform threat hunting and IR using OSINT and IOC correlation.
- Investigate data loss prevention violations and implement preventive measures using Proofpoint and Forcepoint DLP.
- Create detailed documentation for incident investigations along with mitigation recommendations.
- Collaborate with team members on case reviews, and contribute to the improvement of security operations workflow.
Network Protocols & Security Tutor
DePaul University, Chicago, IL (Apr 2024 - Jun 2024)
- Guided over 40 students through networking and security topics.
- Diagnosed and resolved complex lab issues including misconfigured VPNs, ACLs, and IP setups.
Network Security Teaching Assistant
DePaul University, Chicago, IL (Jan 2024 - Mar 2024)
- Designed and implemented secure network architectures in lab environments using Cisco Modelling Labs.
- Developed automated grading scripts for evaluating student network configurations in Cisco Packet Tracer.
- Provided mentorship in network security protocols and network security principles
Graduate Assistant
Asset-Based Community Development Institute, Chicago, IL (Feb 2023 - Apr 2024)
- Implemented access controls on a shared drive for 40 members
- Monitored online community, detecting and responding to 3 malicious actors
- Trained 15 co-workers on security best practices, increasing awareness by 30%
Grapic Design team lead
Hope Organization, Coimbatore, India (Apr 2020 - Aug 2022)
- Led a 3-member graphic design team, managing marketing materials for fundraising events that raised over 500,000 INR
- Conducted local surveys to assess and address societal issues, informing organization’s initiatives
- Oversaw design and production of promotional materials for multiple successful fundraising events
- Collaborated with cross-functional teams to align graphic design with organizational goals and event themes
Office Administrator
Rajkot Machine Tools, Coimbatore, India (Dec 2020 - Jul 2022)
- Managed office administration, finance, and accounting tasks while maintaining company’s IT asset inventory
- Coordinated logistics for supply and delivery of industrial engineering equipment, ensuring timely shipments
- Assisted in industrial equipment installation by configuring Industrial Control Systems (ICS) including PLCs
- Streamlined administrative processes, improving overall office efficiency and productivity
Web Development Intern
Lakshmi Communications, Coimbatore, Tamil Nadu, India (Jul 2020 - Dec 2020)
- Collaborated on 10 successful web development projects as part of a 6-member team
- Translated client requirements into design concepts for 15+ projects, ensuring stakeholder satisfaction
- Led technical discovery phase for 5 projects, resulting in optimized web application solutions
- Gained hands-on experience in front-end and back-end web development technologies
Skills
- Offensive Security: Active Directory Exploitation (Pass-the-Hash, Golden Ticket, Kerberoasting), Web Application Penetration Testing, Privilege Escalation (Windows & Linux), Vulnerability Scanning, Network Traffic Analysis, Password Cracking, Reconnaissance.
- Programming: Python, C++, SQL, Bash
- Security Tools: Metasploit Framework, Nmap, Mimikatz, Hashcat, John the Ripper, Burp Suite, Wireshark, Nikto, Dirb, Responder, Msfvenom, Hydra, OWASP Amass, OWASP Zap, Nessus, OpenVAS, Snort, Suricata, Ettercap, LOIC (Low Orbit Ion Cannon).
- Systems & Platforms: Linux, Windows, MacOS, Cisco IOS, AWS (EC2, S3, VPC), Azure, Docker, VMWare Horizon
- Frameworks: NIST, SOX, HIPAA, GDPR, CIS, SCF, MITRE ATT&CK
- SIEM & DLP: Splunk ES, IBM QRadar, CrowdStrike LogScale, Exabeam, LogRhythm, Proofpoint, Forcepoint.
Education
- MS in Cybersecurity - DePaul University, Chicago (GPA: 3.97/4.0)
- BS in Computer Science - PSG College of Arts and Science, Coimbatore (CGPA 6.7/10.0)
Certifications
- Microsoft Certified: Azure Security Engineer Associate (In Progress)
- CompTIA Security+ CE (May 2024) (View Certificate)
- Google Cyber Security Certified Professional (Coursera) (Jul 2023) (View Certificate)
Courses
- Attack and Defend your DFIR lab, Antisyphon Training (View Certificate)
- SOC Core Skills, Antisyphon Training (View Certificate)
- Applied Python Cryptography, EC-Council (View Certificate)
Lab and Projects
Active Directory Penetration Testing Lab
- Simulated a domain compromise using multi-stage AD attacks with mimikatz.
- Captured and cracked Net-NTLMv2 hashes using Responder and Hashcat.
- Leveraged MS14-068 vulnerability to escalate privileges and extract the KRBTGT hash.
Web Application & Network Penetration Testing Lab
- Conducted comprehensive enumeration of web servers using Nmap, Dirb, and Nikto to identify vulnerabilities and misconfigurations.
- Identified and exploited a file upload vulnerability via HTTP PUT method to achieve RCE using a PHP webshell.
- Generated custom ELF payloads using msfvenom and maintained access via Meterpreter sessions.
- Escalated privileges to root on Linux systems using post-exploitation metasploit modules.
Offensive Security & Exploitation Lab (Windows & Linux)
- Utilized the Metasploit Framework to gain system-level access by exploiting the MS08-067 vulnerability on a Windows Server 2003 machine.
- Performed privilege escalation via token impersonation with incognito.
- Executed brute-force password attacks against FTP service using Hydra with custom wordlist.
- Dumped and cracked password hashes from Windows SAM and NTDS.dit files using Impacket-secretsdump and John the Ripper.
SCADA and IoT Security Lab
- Used Nmap and LOIC to enumerate and disrupt simulated SCADA processes.
- Executed ARP poisoning with Ettercap to intercept and modify ModBus traffic.
- Analyzed firmware with Binwalk and Firmwalker to extract secrets.
- Deployed Snort with custom rules to detect Nmap and DoS activity.
- Secured ModBus traffic using an IPSec VPN (StrongSwan with ESP in tunnel/transport mode).
Reports and Papers
- IoT Security Analysis and Penetration Testing (View Project Report)
- Cybersecurity Automation Operations (View Github Repo for script) | (View the NATAS level 0-15 Write-up)
- Capstone Project - Network Intrusion Detection System in Home Network (View Project Report)
- Computer Forensics Analysis of a suspect image with a malware (View Analysis Report)
- A Comprehensive review of Issues, Challenges, and Enhancements in Network Forensics (View Paper)
- A Comparative Analysis of Financial Cybersecurity Laws in the USA and Europe (View Paper)