Professional Summary
Cybersecurity Analyst and Penetration Tester (HackTheBox "Pro Hacker") with 2+ years across SOC Incident Response and Offensive Security. Builds Python automation that cuts false-positive alert volume and runs red team simulations mapped to MITRE ATT&CK and OWASP. Now pursuing dedicated offensive security roles, with hands-on depth in Windows Internals, Kernel Debugging, Active Directory exploitation, and C2 infrastructure across AWS/Azure environments.
Technical Skills
Offensive Security & Red Teaming: Penetration Testing, Vulnerability Assessments (VAPT), C2 Frameworks, Active Directory Exploitation, Kernel Debugging, Windows Internals, Burp Suite, Metasploit, Kali Linux.
Defensive Security & SOC: L2 SOC Operations, Incident Response (IR), Microsoft Sentinel, Splunk, Chronicle SIEM, XDR (SentinelOne, Cortex, Defender), KQL, Malware Analysis, Digital Forensics.
Engineering & Cloud: Python, Rust, C, JavaScript, Bash, Assembly, Docker, Kubernetes, DevSecOps, AWS, Azure, Git, REST APIs.
AI & Frameworks: Machine Learning, Convolutional Neural Networks (CNN), TensorFlow, Pandas, Flask, MITRE ATT&CK, NIST, OWASP.
Professional Experience
- Maintain 100% SLA compliance across L2 SOC Incident Response for P1 enterprise threats, with zero missed critical escalations.
- Triage 50+ alerts weekly via Microsoft Sentinel, Splunk, and multi-platform XDR (SentinelOne, Cortex), mapping adversary behavior to MITRE ATT&CK to cut Mean Time to Triage.
- Run penetration tests and red team simulations against AWS/Azure infrastructure, closing critical gaps that lifted network compliance by 15%.
- Built Python automation for log parsing and Threat Intel integration, removing manual IOC extraction and cutting false-positive alert volume by 20%.
- Lead endpoint forensics and malware analysis engagements to isolate root cause and neutralize Advanced Persistent Threats (APTs) in hybrid environments.
- Ran digital forensic investigations combining memory forensics, log review, and chain-of-custody evidence recovery.
- Authored vulnerability assessment reports and mitigation strategies presented directly to senior technical stakeholders.
- Completed intensive hands-on training in proactive security monitoring and defensive SOC workflows.
Projects
- Solved all 12 real-world attack scenarios in the Wiz Cloud Security Championship CTF, ranking #30 globally, spanning AWS misconfigurations, Kubernetes privilege escalation, CI/CD pipeline compromise, and IAM exploitation.
- Documented full attack chains and corresponding defensive mitigations for each challenge, published as a public research reference.
- Shipped a bare-metal hardware orchestration dashboard (v0.1.1) in Rust and Tauri for Linux, with real-time telemetry and dual-module GUI/CLI execution.
- Tuned NVIDIA PRIME offloading to eliminate input latency during concurrent GPU monitoring sessions.
- Built a Python SOC triage tool that bulk-scans file-hash IOCs against multi-source Threat Intelligence platforms.
- Added API rate-limiting logic and automated Excel reporting, removing a manual triage bottleneck from the IR workflow.
- Publish advanced CTF walkthroughs and red teaming cheatsheets via a Jekyll site hosted on GitHub Pages.
- Maintain a public repository documenting penetration testing methodologies and Active Directory exploitation techniques.
- Built a Flask + CNN web application detecting agricultural anomalies with 95% accuracy.
- Found and remediated a critical file-upload-to-RCE vulnerability via adversarial testing, adding magic-number verification and deep content inspection to close a MIME-spoofing gap.
Education & Certifications
Sant Gadge Baba Amravati University | CGPA: 9.16