< Resume >

// Work Timeline

< Experience >

// 01/2024 - Present

< myCyberQuest > |

// Founder & Cybersecurity Mentor

• Tutored aspiring cybersecurity professionals to achieve industry-recognized certifications including CompTIA Security+ and A+, leading to a high success rate among participants. • Organized and led study sessions for up to 30 people at a time, delivering in-depth lessons on network security, threat analysis, and vulnerability management, ensuring participants mastered key cybersecurity concepts.

// 04/2024

< Mastercard > |

// Cybersecurity Virtual Intern

Designed and deployed phishing emails using Gophish, LLMs, and HTML, simulating attack scenarios to assess employee response effectiveness.
Analyzed click rate data across 7 business divisions, identifying trends and potential vulnerabilities. Created targeted security awareness presentations to educate employees on phishing risks and preventive strategies.

June 2023Earned my GED
June 2024Earned my Bachelors in Cybersecurity
October 2024Graduate with Masters in cybersecurity at 20.
2025OSCP Through HTB Academy

// My Skills

< Skills >

Python Scripting & Automation

Experienced in automating a variety of tasks, from scraping web directory content to automating file conversions, streamlining processes, and enhancing workflow efficiency.

Vulnerability scanning & Analysis

Experienced with vulnerability scanning tools such as Nessus and Nmap through academic projects. Proficient in using CVSS scoring systems to analyze and prioritize security vulnerabilities, driving effective remediation efforts.

 

Digital Forensics & Incident Response

Learned from a insider threat case study where I had to analyze a bit-by-bit copy of a drive with Autopsy.

Risk Analysis and Remediation

Skilled at analyzing security risks, prioritizing vulnerabilities, and developing remediation timelines based on thorough risk analysis and industry best practices.

Network & Web Application Pentesting

Hands-on experience with web application security testing using tools like Burp Suite and manual testing techniques. Skilled in identifying vulnerabilities in code and applications, providing actionable remediation strategies.

Cloud Security and Secure Development

Designed and implemented secure cloud configurations to meet industry regulatory compliance requirements such as FISMA, PCI DSS, and NIST SP 800-53. Familiar with cloud security best practices, threat mitigation, and secure software development.

// My Skills

< Certifications >

// My Skills

< Projects>

Some (but not all) of the projects I have completed include:

// Secure Cloud Solutions Design and Implementation for SWBTL LLC Case Study

Assessed and addressed the cloud security needs for SWBTL LLC, a nationwide logistics company, during their migration from leased data centers to Microsoft Azure. Designed and implemented secure cloud configurations to meet compliance requirements such as FISMA, PCI DSS, and NIST SP 800-53. Configured Azure Resource Groups, Key Vaults, data encryption, and RBAC to ensure secure operations and regulatory adherence. Overhauled backup and recovery policies to meet specific RPO and RTO objectives, and conducted vulnerability scans to mitigate risks from advanced persistent threats.

// Network Vulnerability Assessment with Nessus:

Installed and configured Nessus to perform credentialed and non-credentialed network vulnerability scans. Conducted a Basic Network Scan on an intentionally vulnerable machine, identifying numerous critical and high-severity vulnerabilities. Customized scan policies, utilized advanced settings to reduce the risk of impacting systems, and leveraged Nessus plugins for in-depth analysis of specific vulnerabilities and CVEs.

// Web Application Security Testing and Vulnerability Remediation

Set up a local instance of OWASP Juice Shop on an Ubuntu VM for security testing. Conducted a thorough assessment using Burp Suite, Nikto, and manual penetration testing, discovering critical vulnerabilities like SQL injection, XSS, and more. Remediated identified issues by modifying source code, followed by verification using automated and manual testing tools to ensure patches were effective.

// Gophish Phishing Lab

Developed practical phishing skills using Gophish by setting up a phishing simulation. Created phishing emails and integrated LLMs to quickly recreate email templates, enhancing the effectiveness of the simulation.

More Info

Contact me here 👇

Quick Links

© 2024 Created with Royal Elementor Addons