About

Cybersecurity analyst and penetration tester focused on offensive security, cloud security, and AI-driven security operations.

I specialize in identifying and exploiting real-world security vulnerabilities across modern web applications, APIs, and cloud environments — then translating technical findings into actionable remediation strategies that improve security posture and reduce risk.

Experience

Cybersecurity Analyst | Penetration Tester | Microsoft 365 Administrator

Security Overview · Contract · Jul 2023 – Jul 2024 · Remote

  • Conducted contract-based and quarterly penetration tests across web applications using REST APIs and GraphQL, applying the OWASP Top 10 to identify and assess 30+ server- and client-side vulnerabilities — XSS (DOM-based, stored, reflected), NoSQL injection, CSRF, open redirects, and access control flaws.
  • Produced detailed penetration test reports outlining findings, risk levels, and remediation steps; followed up with clients to verify issues were resolved.
  • Managed client endpoints and inboxes with Microsoft 365 (Entra ID, Intune, Exchange, SharePoint, OneDrive, Defender, Teams, Purview) and Apple Business Essentials. Strengthened IAM with SAML/SSO, MFA, and geo-restrictions; encrypted endpoints with BitLocker and FileVault.
  • Developed and implemented compliance controls aligned with NIST, SOC, PCI-DSS, GDPR, ISO 27001, and CIS — supporting successful client audits and certifications.

Prompt Engineer

Koherent Incorporated · Internship · May 2023 – Sep 2024 · Remote

  • Leveraged prompt engineering across AI models (GPT-4, DALL-E 2, Copilot, Llama, Stable Diffusion) to enhance application development, code quality, and vulnerability management.
  • Participated in the Software Development Lifecycle within cross-functional teams; analyzed code for vulnerabilities, optimized functions, and ensured compliance with security standards.
  • Built and developed applications using Python, Golang, and React Native.

Education

Woz U — Cybersecurity

Oct 2022 – Jun 2023 · 4.0 GPA · Director’s List

Comprehensive cybersecurity program with hands-on experience in penetration testing, cloud security, network security, vulnerability assessment, and secure systems administration. Built a home lab using pfSense with integrated Snort IDS/IPS for network monitoring, intrusion prevention, and TCP/IP traffic analysis. Created and competed in Capture the Flag (CTF) events, hosted workshops, and supported fellow classmates.

Certifications

  • Practical Bug Bounty — TCM Security
  • Maltego for Cybercrime Investigations — Maltego
  • OpSec: Privacy for Security Professionals — Just Hacking Training
  • Open-Source Intelligence — Basel Institute on Governance
  • Combating Financial Terrorism — Basel Institute on Governance
  • Certified in Cybersecurity Specialization — Coursera
  • IBM Cybersecurity Analyst Specialization — IBM
  • Security Analyst Fundamentals Specialization — IBM
  • Google IT Support Specialization — Google
  • Advent of Cyber 2023 — TryHackMe
  • Level 1 Intelligence Analyst — Udemy
  • The Complete Social Engineering, Phishing, OSINT & Malware — Udemy

Plus 20+ additional certificates spanning networking, cloud fundamentals, security operations, incident response, and technical support.

Skills & Tools

Offensive Security

Burp Suite · Nmap · Metasploit · GraphQL Voyager · Altair · InQL · Wireshark · Hydra · John the Ripper · Gobuster · FFuF · Maltego

Cloud & Microsoft 365

Entra ID · Intune · Exchange · Defender · Purview · Teams · SharePoint · OneDrive · Apple Business Essentials · Microsoft Sentinel · pfSense · Snort IDS/IPS

Development & Frameworks

Python · PowerShell · Golang · React Native · AI & prompt engineering · NIST · CIS · ISO 27001 · SOC 2 · PCI-DSS · GDPR · OWASP Top 10