

I’m an engineer with a solid mix of cybersecurity and software development experience. I like digging into how systems work, spotting what could go wrong, and putting practical controls in place to reduce risk. I work well with dev teams to build secure, reliable applications and keep improving as new security issues show up.
• Worked with the BlackRock security team to define and roll out CIS Level 1 aligned MBSS for ChromeOS and Google Workspace MDM, turning benchmark controls into real endpoint and identity policies in Google Admin Console and Workspace MDM.
• Verified the ChromeOS and MDM baselines by running CIS benchmark assessment scripts (SCE scripts, typically PowerShell or Bash), reviewing the results for gaps or drift, and logging evidence, exceptions, and fixes with all validation artifacts tracked in Git.
• Wrote clear, prioritized findings and fixes mapped to OWASP ASVS, focusing on auth and authorization design, least privilege, sensitive data handling, secrets management, and logging and monitoring, and used a likelihood impact method to rank risk.
• Led CSR risk reviews for in house apps and third party tools by meeting with developers to understand the end to end user flow, data flow, integrations, trust boundaries, and the RBAC approval matrix, then threat modeled the design using DFD plus STRIDE to identify architecture level security gaps early.
• Led BIAs for multiple Reliance Industries business units by walking stakeholders through the process and documenting critical services and their supporting IT dependencies across applications, servers, databases, and network infrastructure.
• Converted BIA results into BC DR requirements by defining service level recovery targets (RTO and RPO) and coordinating with IT teams to ensure DR plans and coverage were set up and tracked for the underlying systems.
• Managed time bound security exceptions tied to go live decisions by documenting compensating controls, assigning remediation owners, setting expiry dates, and tracking closure to reduce residual risk without blocking delivery.
• Assisted in incident response activities related to application security breaches, ensuring prompt resolution.
• Added new DSA, OS, and Computer Networks question content to an Android coding app, and improved how it is structured and shown in the UI using Kotlin or Java and XML layouts.
• Built and polished core screens like question lists, topic navigation, and question detail pages, keeping UI state clean and scrolling fast for large datasets.
Application Security, Risk and Governance: Threat modeling, Secure design reviews, RBAC and data protection, IT governance, Risk management, Audit support, and TPRMs
Security Ops: Vulnerability Management Support, Incident response Coordination
Languages& Technologies: Java, Python, Go, Kotlin, JavaScript, SQL, Solidity, REST APIs, Git
3) Survey Collection App with Rewards System