Cybersecurity Analyst | Security Operations (SOC) & Threat Defense
B.Tech Computer Science & Engineering (Cyber Security Specialization) · Sri Sri University
Defensive security analyst with hands-on security operations center (CSOC) floor experience triaging multi-source security events, investigating IOCs/IOAs, and mapping threat activity to the MITRE ATT&CK framework. Experienced in SIEM correlation, network traffic analysis, ICS/SCADA security simulation, and security automation in Python. Focused on reducing dwell time and false positives through robust detection engineering.
| Domain | Tools & Technologies |
|---|---|
| Security Operations & SIEM | Wazuh SIEM, Splunk, Suricata IDS, MITRE ATT&CK, Alert Triage (TP/FP/TN/FN), Incident Response Lifecycle |
| Network Security & Forensics | Wireshark, PCAP Deep Packet Inspection, Nmap, Network Segmentation (VLANs, ACLs, DMZ), Cisco Packet Tracer |
| Infrastructure & Cloud | Linux Hardening, Syslog Forensics, AWS (EC2, S3, IAM), Docker, Jenkins CI/CD, Bash |
| Security Automation & Scripting | Python (Automation, Threat Scripting), REST APIs, SQL, MongoDB, VirusTotal API Integration |
| Specialized Focus | ICS/SCADA Security (Modbus/TCP, OpenPLC, FUXA), Threat Intelligence Enrichment |
February 2026 – March 2026
- Monitored real-time SOC feeds, performing initial alert triage, verification, and false-positive filtering across high-volume telemetry.
- Correlated multi-source logs using Wazuh SIEM to trace attack vectors and identify actionable Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
- Mapped adversary behaviors and detection rules against the MITRE ATT&CK framework to strengthen defensive coverage.
- Handled end-to-end incident lifecycle management: logging, triage classification, root-cause documentation, and escalation ticketing.
December 2024 – February 2025
- Automated and maintained containerized Jenkins CI/CD delivery pipelines on AWS (EC2, S3, ECR) with Docker.
- Reduced build and deployment turnaround times by ~25% through pipeline optimization and reusable workflow definitions.
- Provisioned reproducible infrastructure environments using AWS CLI and modular configuration scripts.
July 2026 – August 2026
- Designed and delivered full-stack web architecture with secure API endpoints and robust database schemas.
- Implemented state validation, authentication handling, and structured data flow on the MERN stack.
- Designed an automated phishing URL detection engine combining lexical feature engineering, machine learning classification, and heuristic rule checks.
- Integrated the VirusTotal API for real-time threat intelligence enrichment and automated reputation scoring.
- Built an administrative triage dashboard displaying categorized risk ratings and threat analysis metrics.
- Tech Stack: Python, Scikit-Learn, VirusTotal API, Flask, Threat Intelligence Feeds
- Deployed a virtualized industrial automation lab simulating an operational SCADA environment with OpenPLC and FUXA over Modbus/TCP.
- Analyzed ICS protocol vulnerabilities, simulating unauthorized register tampering, coil manipulation, and sensor spoofing.
- Configured Suricata IDS and Wazuh SIEM detection rules to capture anomalous industrial traffic and flag operational deviations in real time.
- Tech Stack: OpenPLC, Modbus/TCP, FUXA, Suricata IDS, Wazuh SIEM, Wireshark, Linux
- Architected a defense-in-depth enterprise banking network topology using Cisco Packet Tracer.
- Enforced strict micro-segmentation with isolated VLANs, perimeter Access Control Lists (ACLs), DMZ isolation, and port security.
- Configured redundant routing protocols and stateful firewall barriers to maintain high availability and prevent lateral threat movement.
- Tech Stack: Cisco Packet Tracer, VLANs, ACLs, STP, OSPF, NAT/PAT, Firewall Policies
- Developed a modular security automation prototype designed to ingest and pre-filter Tier-1 SIEM alerts.
- Programmed automated context queries against local threat intelligence databases and external reputation feeds to classify true vs. false positives.
- Generated formatted incident summaries with preliminary MITRE ATT&CK tactic mappings for human analyst review.
- Tech Stack: Python, Wazuh API, Threat Intel APIs, JSON, Security Orchestration
- Microsoft Certified: Fabric Data Engineer — Microsoft
- Forward Program: Leadership & Problem Solving — McKinsey & Company
- GenAI Financial Chatbot Development — BCG X
- Software Engineering & Feature Development — Electronic Arts
- Foundations of Artificial Intelligence — IBM SkillsBuild
- Data Processing & Visualization using Python — University of Michigan
- Email: aayush.n005@gmail.com
- LinkedIn: linkedin.com/in/aayushnanda
- GitHub: github.com/Maverickk96