I’m a cybersecurity professional interested in understanding how systems operate, how security weaknesses emerge, and how technical findings can be translated into practical risk-reduction decisions.
My interests span SOC operations and incident response, cloud identity and monitoring, network defense, web and API security, digital forensics, embedded and IoT security, OT security fundamentals, hardware security, and governance.
- 🎓 M.S. in Technology, Cybersecurity & Policy
- 🔐 Interested in technical security and risk-based decision-making
- 📚 Currently strengthening my Splunk, cloud, SOC, and incident-response skills
- ✍️ Writing about cloud security, privacy, third-party risk, and data breaches
- 🎤 Outside cybersecurity, I enjoy Bollywood singing
| Area | Current Focus |
|---|---|
| 🔍 SOC & Incident Response | Splunk, log analysis, alert triage, MITRE ATT&CK, YARA, security monitoring |
| 🕵️ Digital Forensics | FTK Imager, Autopsy, Volatility, disk imaging, file carving, timeline analysis |
| ☁️ Cloud Security & IAM | Azure, Entra ID, RBAC, managed identities, Key Vault, Log Analytics, KQL |
| 🌐 Network Security | pfSense, VLANs, Snort, Wireshark, firewalls, routing, switching |
| 🛡️ Web, Application & API Security | Burp Suite, Postman, OWASP ZAP, OAuth, SAST/DAST, OWASP Top 10 |
| 📡 Embedded, IoT & OT Security | BLE, ESP32-C3, firmware security, SPI/UART, SCADA, Modbus, IEC 62443 |
| 🖥️ Hardware & Systems | PC assembly, BIOS/UEFI, Secure Boot, TPM, system hardening, Active Directory |
| 📋 GRC & Privacy | NIST CSF, NIST Privacy Framework, ISO 27001, GDPR, CCPA, SOC 2 |
A digital-forensics case study demonstrating:
- Acquisition of an approximately 256 GB physical storage device
- Creation of 76 segmented E01 evidence files
- MD5 and SHA-1 integrity verification
- Analysis of allocated, unallocated, and slack-space entries
- File carving, keyword searching, and timeline reconstruction
- FTK Imager, Autopsy, PhotoRec, Plaso, YARA, and Linux imaging workflows
Repository links will be added as additional project documentation becomes available.
🔍 SOC Operations, Detection & Incident Response
Investigated authentication activity, system events, network traffic, endpoint behaviors, and access-control issues to practice structured alert triage and root-cause analysis.
Tools and concepts: Splunk, Windows Event Logs, Wireshark, YARA, MITRE ATT&CK, alert triage, escalation, incident documentation
Used Splunk searches, dashboards, and data analysis to identify patterns in security and customer activity and support simulated fraud and incident investigations.
Tools and concepts: Splunk, SPL, dashboards, log analysis, event correlation, security monitoring
Practiced incident notification, information gathering, containment, escalation, recovery, and security-awareness communication in a simulated enterprise environment.
Focus: Incident handling, communication, documentation, containment, recovery
🕵️ Digital Forensics
Deleted Data Recovery & Forensic Image Analysis — Published
Created and verified segmented forensic images, examined filesystem artifacts in Autopsy, reviewed unallocated and slack-space entries, and generated a filesystem activity timeline.
Tools: FTK Imager, Autopsy, PhotoRec, Plaso, YARA, Kali Linux, dd
Analyzed a forensic disk image in Autopsy, searched for sensitive keywords, tagged relevant Office and email files, and identified evidence in carved files, unallocated space, and file slack.
Tools: Autopsy, keyword search, file carving, metadata analysis, hash reporting
Explored memory-forensics and incident-reconstruction techniques for identifying processes, system artifacts, and suspicious activity.
Tools: Volatility, timeline analysis, process examination
☁️ Cloud Security, IAM & Monitoring
Built an Azure environment with a Linux VM, Storage Account, and Key Vault. Implemented least-privilege RBAC, Entra ID groups, managed identities, secure data-transfer settings, and KQL monitoring for privilege and secret-access activity.
Tools: Microsoft Azure, Entra ID, Key Vault, RBAC, Managed Identities, Log Analytics, KQL
Researched and demonstrated user and group management, role assignments, policy enforcement, monitoring, auditing, and access-control testing in Microsoft Azure.
Focus: IAM, RBAC, cloud governance, least privilege, access-control risk
🌐 Network Security & Monitoring
Built a pfSense lab with separate user, server, and management VLANs. Applied default-deny inter-VLAN policies, validated permitted and blocked traffic with Wireshark, and configured Snort IDS monitoring.
Tools: pfSense, VLANs, Wireshark, Snort, managed switching, firewall rules
Configured routers and switches with VLANs, DHCP, NAT, WPA2, static and dynamic addressing, and controlled network access. Used packet analysis and simulation to identify connectivity and configuration issues.
Tools: Cisco Packet Tracer, Wireshark, routers, switches, DHCP, DNS, NAT
Developed a Java-based link-state routing project using sockets, threading, neighbor communication, routing-database exchange, and shortest-path calculation.
Tools: Java, sockets, threading, authentication, encryption, routing protocols
🛡️ Web, Application & API Security
Built vulnerable application environments and tested web and API endpoints for SQL injection, cross-site scripting, authentication weaknesses, authorization flaws, and insecure data exposure.
Tools: Burp Suite, OWASP ZAP, Postman, Nmap, Docker, DVWA, OWASP Top 10
Assessed third-party APIs for authentication weaknesses, authorization flaws, token-handling risks, and insecure data exposure. Researched OAuth attack techniques and mapped findings to the OWASP API Security Top 10.
Tools and concepts: Burp Suite, Postman, OAuth, API authorization, OWASP API Security Top 10
Conducted reconnaissance and controlled exploitation against exposed FTP, SSH, Telnet, HTTP, and database services. Documented attack paths and applied firewall and authentication improvements.
Tools: Kali Linux, Nmap, Metasploit, UFW, service enumeration
📡 Embedded, IoT & OT Security
Assessed the security of a BLE-connected ESP32-C3 device, examining pairing, encryption, firmware behavior, and low-level communication interfaces.
Created data-flow diagrams, reviewed software components, scored vulnerabilities, and explored fuzzing approaches for memory-corruption and denial-of-service risks.
Tools and concepts: BLE, ESP32-C3, IDA Pro, SPI, UART, DFDs, SBOM, CVSS, fuzzing
Explored secure boot, firmware security, hardware interfaces, low-level communication protocols, and risks affecting connected and embedded devices.
Focus: Secure Boot, BIOS/UEFI, firmware updates, SPI, I2C, UART, BLE, Zigbee
Studying the security considerations of industrial environments, including network segmentation, legacy protocols, asset availability, safety requirements, and the differences between enterprise IT and operational technology.
Focus: SCADA, PLCs, HMIs, Modbus, DNP3, industrial segmentation, IEC 62443 fundamentals
🖥️ Hardware, Systems & Security Baselines
Assembled and troubleshot computer systems, configured Secure Boot, TPM, boot order, firmware settings, and POST behavior, and resolved component-detection and startup issues.
Created a repeatable macOS security baseline covering FileVault, Gatekeeper, firewall and stealth mode, automatic updates, login security, privacy controls, validation, and rollback guidance.
Investigated simulated service failures, permission errors, disk-utilization problems, and resource exhaustion using Linux logs, processes, and administrative utilities.
Built and tested Ethernet cables using the TIA-568B standard and diagnosed physical-layer faults involving pinouts, crimping, continuity, and damaged conductors.
📋 Governance, Risk, Compliance & Privacy
Evaluated privacy-policy options using the NIST Privacy Framework, GDPR, and CCPA. Compared regulatory, operational, cost, and innovation considerations to develop risk-based recommendations.
Focus: Privacy risk, data classification, policy evaluation, GDPR, CCPA
Evaluated phishing and social-engineering risk, identified departments requiring targeted support, and designed security-awareness recommendations and procedural improvements.
Focus: Phishing, security awareness, risk communication, mitigation planning
A hands-on exploration of Microsoft Azure access controls covering IAM, user and group management, RBAC, policy configuration, monitoring, auditing, and least-privilege security.
Managing Privacy Risks in the Digital Age: An Analysis of the NIST Privacy Framework and Future Policy Directions
A policy-focused analysis of the NIST Privacy Framework, GDPR, CCPA, adoption challenges, privacy impact assessments, and risk-based approaches to protecting personal data.
An analysis of a reported data breach involving sensitive corporate information, third-party exposure, regulatory obligations, and the organizational consequences of inadequate data protection.
An examination of third-party cloud risk, breach response, continuous monitoring, API security, access governance, encryption, and practical recommendations for affected customers and organizations.
- CompTIA CySA+
- CompTIA Security+
- CompTIA A+
- ISC2 Certified in Cybersecurity (CC)
- Cisco Endpoint Security
- Cisco Cyber Threat Management
- Cisco Network Support and Security
University of Colorado Boulder M.S. in Technology, Cybersecurity & Policy GPA: 3.9/4.0
Visvesvaraya Technological University B.E. in Computer Science and Engineering
- Strengthening Splunk search, detection, and SOC investigation workflows
- Expanding cloud identity, access-control, and monitoring labs
- Practicing digital-forensics and incident-response techniques
- Developing network monitoring and segmentation scenarios
- Exploring embedded, firmware, IoT, and OT security
- Connecting technical security findings to practical business risk
I’m interested in connecting with cybersecurity professionals across SOC operations, cloud security, network defense, application security, digital forensics, embedded security, OT, and governance.