01 EXPERIENCE
work experience
Four years spanning GRC automation, threat research, and open-source detection engineering.
-
Jun 2026 – PresentRemote • New York City
Community Ambassador & Contributor
- Validated Wazuh v5.0 beta2, reverse-engineered JSON-compiled decoder schemas and breaking API changes, and modernized 19 integrations, a few being GitHub, Cortex XDR, AWS, Tenable, Microsoft 365, Slack, Cloudflare, etc., for updated logging mechanisms and deprecated components in v4.14.6, v4.14.7, v5.0beta2 and v5.0beta4 (done internally).
- Developed and open-sourced a Caddy web server detection integration for Wazuh v4.14.6 and v5.0.0 beta, including custom detection rules and Suricata, Snort, and Zeek integrations for threat detection and correlation; both versions were merged upstream and are now included in Wazuh.
-
May 2023 – Jul 2025Hybrid • New Delhi
Threat Research, GRC Engineer
Received a full-time offer with a highly competitive package but could not accept it, since I was coming to NYU for my MS in Cybersecurity. Also received a strong letter of recommendation from the Director of Risk and Security.
- Engineered GRC automation tooling that transformed key processes (Access Recon, Access Check), slashing operational time from 5 weeks down to 15 hours: a >98% reduction.
- Reviewed and assessed vendor security posture using SOC 2 reports, ISO 27001 certifications, CAIQ and SIG questionnaires, and NIST 800-53 controls, informing risk tiering across the vendor ecosystem.
- Spearheaded AI integration for Third-Party Risk Management (TPRM), boosting AI vendor response accuracy from 0% to 95%.
- Co-led the "TPRM Reimagine" project, collaborating directly with Directors and the CISO.
- Executed the entire Q2-2025 company-wide Access Reconciliation for all 3rd-party vendors and automated SSPM controls to scale and secure the vendor ecosystem.
- Co-deployed and co-maintained a multi-node Wazuh XDR/SIEM deployment on AWS EC2, onboarding endpoints and improving threat monitoring and alert visibility.
- Developed and repaired data ingestion scripts for key security platforms (Halcyon AI, Wiz, JPCERT, CSIRT-IE), ensuring a continuous and reliable intelligence pipeline.
- Enhanced Cyber Threat Intelligence (CTI) capabilities by analyzing 2,500+ threat events, mapping IOCs and actor TTPs using MITRE ATT&CK (certification earned) and STIX 2.1 frameworks.
- Profiled 200+ threat actors, from nation states to hacktivists, based on event/log patterns, IOCs, and IAMs.
- Co-designed the company's AI Policy as part of a CISO-level initiative.
- Documented RiskLens after its acquisition by Safe Security, completing the project in half the allotted time and establishing the baseline for future release notes.
-
Jun 2022 – Aug 2022Jaipur, India
Web Development Intern
- Led a team of four in Front End Web Development; collaborated across teams to deliver solutions.
- Applied analytical skills and research to inform decisions and improve outcomes.
- Tech stack: built interfaces using HTML and CSS.