SHAHIN MANKAR
IMMEDIATE JOINER — OPEN TO WORK
Hi, I'm Shahin Mankar

Cybersecurity Engineer focused on SIEM/SOAR engineering and infrastructure automation.

Cybersecurity Engineer (B.Tech Computer Engineering, 2026) with 8 months of production experience in Security Operations, SIEM/SOAR engineering, and infrastructure automation. At CDAC Mumbai, I designed and deployed a SIEM/SOAR pipeline — Wazuh, Shuffle, TheHive, Cortex, and MISP — that automated detection and incident response. The platform was migrated to CDAC's production server and adopted as their internal reference prototype for a commercial SOAR product.

Experienced in Linux systems administration, Python/Bash scripting, and REST API integration.

Shahin Mankar
SHAHIN MANKAR
● Immediate Joiner · Mumbai, India
B.Tech, Computer Engineering
Usha Mittal Inst. of Tech, SNDT University · 2026
ML Intern
Suvidha Foundation · Aug–Sep 2025
Cybersecurity & Networking Intern
CDAC Mumbai · Dec 2025–Jul 2026
Education
B.Tech, Computer Engineering
Usha Mittal Institute of Technology, SNDT University, Mumbai
2026
XII — Science (HSC)
Nahata College, Bhusawal
2022
X (SSC)
St. Aloysius High School, Bhusawal
2020
02 / EXPERIENCE
Where the work happened
Two internships, one thread — building systems that detect, decide, and respond faster than a human alone could.
Cybersecurity & Networking Intern — CDAC Mumbai
Dec 2025 – Jul 2026
  • Architected a full SIEM/SOAR platform — Wazuh, Shuffle, TheHive, Cortex, MISP — containerised on Docker/Ubuntu, wired together with REST APIs for end-to-end automated incident response.
  • Designed 7 automated security playbooks in Python and Bash; 4 validated end-to-end covering brute force detection, web attack detection, system integrity monitoring, and phishing email detection.
  • Tuned Wazuh correlation rules and log analysis, cutting false positives by 50%+ — the platform was migrated to CDAC's production server and adopted as the internal reference prototype for a commercial SOAR product.
  • Ran threat hunting, IOC enrichment, and vulnerability assessment across live endpoints; administered Ubuntu Linux access controls and network security monitoring.
  • Led the ISEA cybersecurity awareness program — built training across 10+ security domains, delivered to 150–200 government and defence personnel across 5 locations, including INS Shivaji.
↓ 50%+ false positives Detect-to-alert < 30s Full pipeline < 90s 0 unplanned downtime 5 locations trained
Machine Learning Intern — Suvidha Foundation
Aug – Sep 2025
  • Curated a labelled dataset of 1,000+ text articles and trained a CNN-based text classification model in PyTorch.
  • Built feature-extraction pipelines and evaluated model performance using ROUGE-1 / ROUGE-2 metrics.
03 / PROJECTS
Shipped, not just scoped
From a browser extension in production to a SOAR platform now running as CDAC's internal reference build.
SecureBrowser

A Manifest V3 browser extension that blocks malicious URLs in ≤50ms using the Google Safe Browsing API — full-stack build with a Node.js backend and Firebase as the data/auth layer, continuously deployed to Vercel via Git. Validated across 500–750 real URLs with a 75%+ threat prevention rate.

Node.jsFirebaseManifest V3 Google Safe Browsing APIVercel CI/CD
SOAR Automation Stack

Designed and deployed a self-hosted SIEM/SOAR platform at CDAC Mumbai — a full detect-to-respond pipeline built from Wazuh, Suricata, Shuffle, TheHive, Cortex, and MISP. The system detects an attack, enriches it with threat intelligence, opens a structured incident case, blocks the source, and notifies the analyst — engineered for detection-to-alert under 30 seconds and full pipeline resolution under 90 seconds, with no manual steps for common attack patterns.

Data Sourcesendpoints, network, feeds
→
Wazuh + Suricatadetection & collection
→
ShuffleSOAR orchestration
→
TheHive + Cortexcase mgmt & analysis
→
MISPthreat intelligence
→
Responseblock, isolate, notify
PLAYBOOK 01
Brute Force Detection
Trigger: SSH brute force, off-hours/failed logins
Parses the attacker IP, runs multi-source threat-intel enrichment, auto-blocks confirmed threats, and notifies the analyst.
PLAYBOOK 02
Web Attack Detection
Trigger: SQL injection, XSS, directory traversal, scanning
Reads web server logs, creates a structured alert, enriches the source IP, and blocks severe attacks automatically.
PLAYBOOK 03
System Integrity Monitoring
Trigger: File changes, new users, package installs
Classifies the event type, creates a tagged alert, and promotes high-severity events to a full case automatically.
PLAYBOOK 04
Phishing Email Detection
Trigger: Inbound email, scored in real time
A custom Python IMAP monitor scores inbound mail on TLD, brand impersonation, and SPF/DMARC signals — auto-creates high-severity alerts above threshold.
3 additional playbooks were designed but not fully validated end-to-end.
Engineering challenges solved
✕Diagnosed and resolved an Elasticsearch indexing conflict that was silently breaking the SOAR orchestration layer.
✕Fixed container-to-container networking failures between orchestration and analysis services.
✕Eliminated 38,000+ false-positive alerts generated by Docker's own internal noise through targeted rule tuning.
✕Root-caused and resolved stale-webhook alert delivery failures using log-level debugging.
Test CategoryCoverageStatus
SSH Brute ForceHydra, multiple failures, off-hours/weekend login, PAM failures✔ Working
Web AttacksSQL injection, directory traversal, Nikto scan, dirb, XSS✔ Working
System IntegrityFile modified/deleted, new user, sudo group, package install, config change✔ Working
PhishingTLD attack, brand impersonation, URL shortener, combined✔ Working
Network ScanningNmap SYN, version, OS, aggressive, UDP scans⚠ Partial
25 test cases run end-to-end in a lab environment prior to production migration.
MITRE ATT&CK TechniqueIDPlaybook
Brute ForceT1110Brute Force
Valid AccountsT1078Brute Force
Exploit Public-Facing ApplicationT1190Web Attack
Data ManipulationT1565System Integrity
Create AccountT1136System Integrity
Persistence via CronT1546System Integrity
PhishingT1566Phishing
Active ScanningT1595Network / Nmap
DockerWazuhSuricataShuffle TheHiveCortexMISPPythonBashREST APIs
Red Teaming & Security Testing

Offensive-security testing used to validate the SOAR pipeline above before production.

A series of exercises run to stress-test detection and response before the platform went live — confirming the pipeline held up against real attack patterns, not just simulated ones.

Attack VectorTool / MethodOutcome
Brute forceHydraDetected & contained
DoS / DDoSSimulated loadDetected & mitigated
PhishingGoPhishFlagged & routed
Lateral movementManual simulationContained
Network reconNmapDetected
Web application attacksNikto, dirbFlagged
SQL injectionSQLMapDetected
System integrity checksRedamonVerified
AI-assisted testingHexStrike + Ollama (local LLM)Evaluated
All outcomes validated in a pre-production lab environment; internal detection specifics are not disclosed.
ISEA Phishing & OSINT Simulation
Ran live QR-based phishing and OSINT simulations for the ISEA awareness program — credential harvesting via QR codes hit an 85%+ click rate across 150+ government and defence personnel, alongside a camera-based OSINT exercise extracting GPS metadata every 5 seconds to demonstrate real-world exposure.
GoPhishOSINTSocial Engineering
04 / SKILLS
The toolkit
Balanced across security operations and the infrastructure that runs it.
Security Operations
SIEMSOARIncident ResponseThreat Detection Threat HuntingLog AnalysisAlert TriageVulnerability Assessment Network Security MonitoringMITRE ATT&CKOWASP Top 10GRCRisk Assessment
SIEM / SOAR Tools
WazuhSuricataShuffleTheHiveCortex MISPWiresharkBurp SuiteMetasploitNmapGoPhish
DevOps & Automation
DockerDocker ComposeCI/CD ConceptsInfrastructure Automation Workflow OrchestrationLinux Administrationsystemdiptables / UFWShell Scripting
Programming & Integration
PythonBashREST API IntegrationThreat Intel APIs Git / GitHubJSONYAML
Cloud & Networking
Oracle Cloud Infrastructure (OCI)Azure FundamentalsTCP/IPDNS DHCPSubnettingFirewall ConfigurationVPN FundamentalsContainer Networking
Certifications
OCI Foundation — Oracle University
Certified AI Security Expert L1 — VCL Academy
Google Cybersecurity Certificate — in progress
Cisco Intro to Cybersecurity — in progress
Fortinet NSE 1, 2 & 3 — in progress
05 / CONTACT

Let's talk SOC, automation, or your next hire.

Immediate joiner — open to DevOps Engineer, Cloud Support Engineer, and SOC / SRE roles.