01 EXPERIENCE

work experience

Four years spanning GRC automation, threat research, and open-source detection engineering.

  1. Jun 2026 – Present
    Remote • New York City

    Community Ambassador & Contributor

    Wazuh

    • Validated Wazuh v5.0 beta2, reverse-engineered JSON-compiled decoder schemas and breaking API changes, and modernized 19 integrations, a few being GitHub, Cortex XDR, AWS, Tenable, Microsoft 365, Slack, Cloudflare, etc., for updated logging mechanisms and deprecated components in v4.14.6, v4.14.7, v5.0beta2 and v5.0beta4 (done internally).
    • Developed and open-sourced a Caddy web server detection integration for Wazuh v4.14.6 and v5.0.0 beta, including custom detection rules and Suricata, Snort, and Zeek integrations for threat detection and correlation; both versions were merged upstream and are now included in Wazuh.
  2. May 2023 – Jul 2025
    Hybrid • New Delhi

    Threat Research, GRC Engineer

    Safe Security

    Received a full-time offer with a highly competitive package but could not accept it, since I was coming to NYU for my MS in Cybersecurity. Also received a strong letter of recommendation from the Director of Risk and Security.

    • Engineered GRC automation tooling that transformed key processes (Access Recon, Access Check), slashing operational time from 5 weeks down to 15 hours: a >98% reduction.
    • Reviewed and assessed vendor security posture using SOC 2 reports, ISO 27001 certifications, CAIQ and SIG questionnaires, and NIST 800-53 controls, informing risk tiering across the vendor ecosystem.
    • Spearheaded AI integration for Third-Party Risk Management (TPRM), boosting AI vendor response accuracy from 0% to 95%.
    • Co-led the "TPRM Reimagine" project, collaborating directly with Directors and the CISO.
    • Executed the entire Q2-2025 company-wide Access Reconciliation for all 3rd-party vendors and automated SSPM controls to scale and secure the vendor ecosystem.
    • Co-deployed and co-maintained a multi-node Wazuh XDR/SIEM deployment on AWS EC2, onboarding endpoints and improving threat monitoring and alert visibility.
    • Developed and repaired data ingestion scripts for key security platforms (Halcyon AI, Wiz, JPCERT, CSIRT-IE), ensuring a continuous and reliable intelligence pipeline.
    • Enhanced Cyber Threat Intelligence (CTI) capabilities by analyzing 2,500+ threat events, mapping IOCs and actor TTPs using MITRE ATT&CK (certification earned) and STIX 2.1 frameworks.
    • Profiled 200+ threat actors, from nation states to hacktivists, based on event/log patterns, IOCs, and IAMs.
    • Co-designed the company's AI Policy as part of a CISO-level initiative.
    • Documented RiskLens after its acquisition by Safe Security, completing the project in half the allotted time and establishing the baseline for future release notes.

    Certifications earned on the job: ISO 27001:2022, MITRE ATT&CK.

  3. Jun 2022 – Aug 2022
    Jaipur, India

    Web Development Intern

    LUSIP

    • Led a team of four in Front End Web Development; collaborated across teams to deliver solutions.
    • Applied analytical skills and research to inform decisions and improve outcomes.
    • Tech stack: built interfaces using HTML and CSS.