Cybersecurity analyst and penetration tester focused on offensive security, cloud security, and AI-driven security operations.
I specialize in identifying and exploiting real-world security vulnerabilities across modern web applications, APIs, and cloud environments — then translating technical findings into actionable remediation strategies that improve security posture and reduce risk.
Experience
Cybersecurity Analyst | Penetration Tester | Microsoft 365 Administrator
Security Overview · Contract · Jul 2023 – Jul 2024 · Remote
- Conducted contract-based and quarterly penetration tests across web applications using REST APIs and GraphQL, applying the OWASP Top 10 to identify and assess 30+ server- and client-side vulnerabilities — XSS (DOM-based, stored, reflected), NoSQL injection, CSRF, open redirects, and access control flaws.
- Produced detailed penetration test reports outlining findings, risk levels, and remediation steps; followed up with clients to verify issues were resolved.
- Managed client endpoints and inboxes with Microsoft 365 (Entra ID, Intune, Exchange, SharePoint, OneDrive, Defender, Teams, Purview) and Apple Business Essentials. Strengthened IAM with SAML/SSO, MFA, and geo-restrictions; encrypted endpoints with BitLocker and FileVault.
- Developed and implemented compliance controls aligned with NIST, SOC, PCI-DSS, GDPR, ISO 27001, and CIS — supporting successful client audits and certifications.
Prompt Engineer
Koherent Incorporated · Internship · May 2023 – Sep 2024 · Remote
- Leveraged prompt engineering across AI models (GPT-4, DALL-E 2, Copilot, Llama, Stable Diffusion) to enhance application development, code quality, and vulnerability management.
- Participated in the Software Development Lifecycle within cross-functional teams; analyzed code for vulnerabilities, optimized functions, and ensured compliance with security standards.
- Built and developed applications using Python, Golang, and React Native.
Education
Woz U — Cybersecurity
Oct 2022 – Jun 2023 · 4.0 GPA · Director’s List
Comprehensive cybersecurity program with hands-on experience in penetration testing, cloud security, network security, vulnerability assessment, and secure systems administration. Built a home lab using pfSense with integrated Snort IDS/IPS for network monitoring, intrusion prevention, and TCP/IP traffic analysis. Created and competed in Capture the Flag (CTF) events, hosted workshops, and supported fellow classmates.
Certifications
- Practical Bug Bounty — TCM Security
- Maltego for Cybercrime Investigations — Maltego
- OpSec: Privacy for Security Professionals — Just Hacking Training
- Open-Source Intelligence — Basel Institute on Governance
- Combating Financial Terrorism — Basel Institute on Governance
- Certified in Cybersecurity Specialization — Coursera
- IBM Cybersecurity Analyst Specialization — IBM
- Security Analyst Fundamentals Specialization — IBM
- Google IT Support Specialization — Google
- Advent of Cyber 2023 — TryHackMe
- Level 1 Intelligence Analyst — Udemy
- The Complete Social Engineering, Phishing, OSINT & Malware — Udemy
Plus 20+ additional certificates spanning networking, cloud fundamentals, security operations, incident response, and technical support.
Skills & Tools
Offensive Security
Burp Suite · Nmap · Metasploit · GraphQL Voyager · Altair · InQL · Wireshark · Hydra · John the Ripper · Gobuster · FFuF · Maltego
Cloud & Microsoft 365
Entra ID · Intune · Exchange · Defender · Purview · Teams · SharePoint · OneDrive · Apple Business Essentials · Microsoft Sentinel · pfSense · Snort IDS/IPS
Development & Frameworks
Python · PowerShell · Golang · React Native · AI & prompt engineering · NIST · CIS · ISO 27001 · SOC 2 · PCI-DSS · GDPR · OWASP Top 10
