Cybersecurity Engineer focused on SIEM/SOAR engineering and infrastructure automation.
Cybersecurity Engineer (B.Tech Computer Engineering, 2026) with 8 months of production experience in Security Operations, SIEM/SOAR engineering, and infrastructure automation. At CDAC Mumbai, I designed and deployed a SIEM/SOAR pipeline — Wazuh, Shuffle, TheHive, Cortex, and MISP — that automated detection and incident response. The platform was migrated to CDAC's production server and adopted as their internal reference prototype for a commercial SOAR product.
Experienced in Linux systems administration, Python/Bash scripting, and REST API integration.
- Architected a full SIEM/SOAR platform — Wazuh, Shuffle, TheHive, Cortex, MISP — containerised on Docker/Ubuntu, wired together with REST APIs for end-to-end automated incident response.
- Designed 7 automated security playbooks in Python and Bash; 4 validated end-to-end covering brute force detection, web attack detection, system integrity monitoring, and phishing email detection.
- Tuned Wazuh correlation rules and log analysis, cutting false positives by 50%+ — the platform was migrated to CDAC's production server and adopted as the internal reference prototype for a commercial SOAR product.
- Ran threat hunting, IOC enrichment, and vulnerability assessment across live endpoints; administered Ubuntu Linux access controls and network security monitoring.
- Led the ISEA cybersecurity awareness program — built training across 10+ security domains, delivered to 150–200 government and defence personnel across 5 locations, including INS Shivaji.
- Curated a labelled dataset of 1,000+ text articles and trained a CNN-based text classification model in PyTorch.
- Built feature-extraction pipelines and evaluated model performance using ROUGE-1 / ROUGE-2 metrics.
A Manifest V3 browser extension that blocks malicious URLs in ≤50ms using the Google Safe Browsing API — full-stack build with a Node.js backend and Firebase as the data/auth layer, continuously deployed to Vercel via Git. Validated across 500–750 real URLs with a 75%+ threat prevention rate.
Designed and deployed a self-hosted SIEM/SOAR platform at CDAC Mumbai — a full detect-to-respond pipeline built from Wazuh, Suricata, Shuffle, TheHive, Cortex, and MISP. The system detects an attack, enriches it with threat intelligence, opens a structured incident case, blocks the source, and notifies the analyst — engineered for detection-to-alert under 30 seconds and full pipeline resolution under 90 seconds, with no manual steps for common attack patterns.
| Test Category | Coverage | Status |
|---|---|---|
| SSH Brute Force | Hydra, multiple failures, off-hours/weekend login, PAM failures | ✔ Working |
| Web Attacks | SQL injection, directory traversal, Nikto scan, dirb, XSS | ✔ Working |
| System Integrity | File modified/deleted, new user, sudo group, package install, config change | ✔ Working |
| Phishing | TLD attack, brand impersonation, URL shortener, combined | ✔ Working |
| Network Scanning | Nmap SYN, version, OS, aggressive, UDP scans | ⚠ Partial |
| MITRE ATT&CK Technique | ID | Playbook |
|---|---|---|
| Brute Force | T1110 | Brute Force |
| Valid Accounts | T1078 | Brute Force |
| Exploit Public-Facing Application | T1190 | Web Attack |
| Data Manipulation | T1565 | System Integrity |
| Create Account | T1136 | System Integrity |
| Persistence via Cron | T1546 | System Integrity |
| Phishing | T1566 | Phishing |
| Active Scanning | T1595 | Network / Nmap |
Offensive-security testing used to validate the SOAR pipeline above before production.
A series of exercises run to stress-test detection and response before the platform went live — confirming the pipeline held up against real attack patterns, not just simulated ones.
| Attack Vector | Tool / Method | Outcome |
|---|---|---|
| Brute force | Hydra | Detected & contained |
| DoS / DDoS | Simulated load | Detected & mitigated |
| Phishing | GoPhish | Flagged & routed |
| Lateral movement | Manual simulation | Contained |
| Network recon | Nmap | Detected |
| Web application attacks | Nikto, dirb | Flagged |
| SQL injection | SQLMap | Detected |
| System integrity checks | Redamon | Verified |
| AI-assisted testing | HexStrike + Ollama (local LLM) | Evaluated |
Let's talk SOC, automation, or your next hire.
Immediate joiner — open to DevOps Engineer, Cloud Support Engineer, and SOC / SRE roles.