Cybersecurity Analyst — Community Dreams Foundation
Boston, MA · Oct 2025 – Jul 2026
- Improved compliance posture by 25% by implementing RBAC, MFA, and PKI/TLS controls while monitoring and triaging SOC alerts for threat detection and incident response across cloud environments
- Scaled secure cloud capacity by 60% by hardening infrastructure with Terraform-managed KMS encryption, TLS enforcement, VPC segmentation, and firewall controls aligned to CIS Benchmarks and NIST CSF
- Cut incident response time by 15% by developing and standardizing CSIRT procedures, IR playbooks, and SOPs for audit-ready security operations
- Surfaced a critical SSRF vulnerability and five high-severity findings by running a gray-box security assessment of the UpSkill platform (Lovable/Supabase), plus a 13-section reconnaissance report and RLS audit on two other production Supabase projects
- Eliminated a fragmented password-management process by deploying Vaultwarden via Terraform on GCP, after building the technical case against a proposed in-house alternative and authoring the org's password management policy
Security Analyst — Mobile Heartbeat
Boston, MA · Jan 2025 – Apr 2025
- Reduced risk exposure by 35% by triaging 25+ security incidents through behavioral analysis of anomalous activity in Azure Sentinel/Log Analytics (KQL) and EDR tooling, then driving remediation
- Strengthened security posture by 20% by threat hunting across the environment, surfacing 55+ previously unidentified risks and vulnerabilities
- Remediated 25+ non-compliant configurations by auditing 100+ Azure resources and prioritizing fixes for the top 3 root causes of security incidents
- Validated compliance across NIST CSF, GDPR, and HIPAA by correlating cloud configurations against all three frameworks and presenting remediation timelines to senior leadership
Software Developer Intern — Plus Delta
Vizag, AP, India · May 2022 – Jul 2022
- Increased platform security by 35% by performing vulnerability assessments and penetration tests across 80+ API endpoints and delivering remediation recommendations
- Accelerated vulnerability remediation by 25% by developing Python automation that integrated security findings directly into CI/CD pipelines