Aditya Jain
Cybersecurity Engineer | Vulnerability Management & DevSecOps | VAPT • SIEM/EDR • Security Automation
Results-driven Cybersecurity Engineer with 4+ years in Vulnerability Management, remediation orchestration, and security automation for government and Critical National Infrastructure (CNI). Proven record in vulnerability discovery, validation (PoC), and de-duplication; risk-based prioritization (CVSS + threat intelligence + asset criticality); and automating 120+ compliance baselines as policy-as-code across 750+ endpoints, cutting audit effort by 60%.
Technical Skills & Defense Toolchains
Hands-on mastery across Palo Alto/Fortinet NGFW, Active Directory red teaming, enterprise EDR/SIEM, compliance orchestration, and agentic AI OPSEC.
Critical Infrastructure Portals & Engineering Systems
Production monitoring platforms, synthetic diagnostic suites, and automated compliance engines built for government and enterprise operations.
DevSecOps CI/CD Security Pipeline (Lab)
Multi-stage automated CI/CD security pipeline built on GitHub Actions integrating Semgrep (SAST), Trivy (container/SCA), Checkov (IaC), and OWASP ZAP (DAST) for automated pull-request vulnerability triage.
State NOC Admin Portal (NIC Bihar)
Enterprise network operations dashboard monitoring 38 regional district nodes with live traceroute diagnostics, automated outage alerting, and an on-premise Ollama voice-enabled RAG chatbot.
Real-Time Network Alert Dashboard
Sub-second packet loss and ping outage tracking across 293 core routing units with Indian English Web Speech broadcast alarms, severity filtering, and device grid visualization.
Unified NOC Monitoring Suite (NIC Bihar)
In-house observability platform delivering video-conferencing (VC) health monitoring, district WAN speed-tests, and automated portal availability checks across 38 districts with severity-tiered alerting.
LAN Asset Management Portal
Locally-hosted Python/Bash asset management infrastructure enabling silent PXE OS provisioning, hardware inventory tracking, and cryptographic internal software distribution.
CDAC / CERT-In Compliance Automation Engine
Automated PowerShell & Python framework validating 120+ regulatory baselines, USB lockouts, SMBv1 deprecation, and registry hardening across 750+ endpoints via KACE UEM.
CyberKarma & JumpStreet Triad Ecosystem
Gamified educational trivia platform converting cybersecurity quizzes into real stray animal meals in Patna + statistical arbitrage quantitative trading architecture (Orca6).
Enterprise SecOps Experience (4+ Years)
Security Administrator & NGFW Architect
- NGFW & Network Hardening: Architect and enforce default-deny policies across Palo Alto and Check Point NGFW clusters; audit public IP exposure and secure Linux rack servers across the Bihar State Data Centre (SDC).
- Enterprise EDR/SIEM Deployment: Manage SentinelOne, Trend Micro Deep Security, and Wazuh/Splunk deployments across 750+ regional government endpoints; tune correlation rules against emerging attack vectors, reducing false-positive fatigue by 30%.
- Incident Response & Compliance: Serve as primary CERT-In incident responder; automate compliance reporting (120+ CDAC/CERT-In checks via KACE UEM), cutting manual audit effort by 60%.
- VAPT & AD Security: Lead coordination with NIC-CERT to remediate critical web vulnerabilities (authoring PoC exploits) and conduct Active Directory attack-path analysis to secure district-level nodes.
- Unified NOC Monitoring Suite: Engineered an in-house observability platform delivering video-conferencing (VC) health monitoring, WAN speed/latency probing, and automated portal availability checks across 38 districts; reduced outage detection time and produced SLA evidence for FMS teams.
- Security Training: Deliver specialized training on NGFW, EDR, and CERT-In compliance to 60+ district-level Facility Management System (FMS) teams.
Independent Security Researcher
- Executed advanced Active Directory exploitation labs (Hack The Box, VulnLab multi-forest environments), mastering Kerberoasting, DCSync, and Domain Controller compromise techniques.
- Pursued MBA (Cybersecurity) coursework and aligned certification trajectories (eJPT, CEH) to bridge defensive architecture with offensive red-team methodologies.
SOC Analyst – Threat Hunter
- CNI SOC Operations: Operated as SME for threat hunting in a 24/7 Critical National Infrastructure SOC, monitoring enterprise telemetry via Blu Sapphire SIEM and Splunk.
- Detection Engineering: Engineered and tuned SIEM correlation rules and EDR policies, achieving a 35% improvement in true-positive detection rates.
- Malware Analysis: Performed behavioral malware analysis and sandbox payload reproduction to reverse-engineer TTPs and update detection signatures.
SOC Analyst – IDS & Signature Development
- Authored and deployed custom Snort and Wazuh IDS signatures, improving detection coverage against novel attack patterns in a 24/7 SOC environment.
- Automated AbuseIPDB feed ingestion for real-time perimeter IP blocklisting, significantly reducing inbound malicious traffic and routing anomalies.
Technical Support Executive (Microsoft Enterprise)
- Delivered Tier-2 Microsoft enterprise product support, maintaining strict SLA compliance and contributing to internal knowledge base documentation.
Hands-On Security Labs & Academic Coursework
Offensive Security Labs
- 01Hack The Box: Active Directory exploitation, Kerberoasting, privilege escalation & network pivoting.
- 02VulnLab Multi-Forest Labs: Forest trust abuse, DC shadow attacks, DCSync, and full Domain Controller compromise.
- 03OPSEC & Anonymity: Tor network research and threat intelligence infrastructure for defensive early-warning feeds.
Academic Security Coursework
- 01Security Management & Governance: Royal Holloway, University of London — Enterprise risk matrices & policies.
- 02Introduction to Network Security: University of London — Cryptographic key exchanges, packet filters & TLS.
- 03Mathematical Foundations for Cryptography: University of Colorado — Asymmetric ciphers, hashing, and discrete log.
Professional Certifications & Ongoing Roadmap
Degrees & Cybersecurity Qualifications
MBA in Cybersecurity
Postgraduate studies in enterprise cybersecurity risk governance, compliance frameworks, and defensive/offensive purple team alignment.
B.Tech — Computer Science & Engineering
Undergraduate degree in CSE with extensive coursework in Network Security, Operating Systems, Cryptography, and Distributed Systems.
Diploma — Computer Science & Engineering
Core engineering diploma covering computer networking, system administration, C/C++ programming, and digital electronics.
Technical Write-Ups & Defense Blueprints
Sanitized threat hunting methodology, Active Directory attack chain reproductions, and compliance automation scripts.
Kerberoasting → DCSync: Chaining AD Attacks in a Multi-Forest Lab
Deep-dive analysis on requesting TGS tickets for SPN accounts, cracking RC4/AES hashes with Hashcat, escalating through nested delegation groups, and executing DCSync via Impacket secretsdump.
Automating 120+ CERT-In Checks with PowerShell & KACE UEM
How we engineered a scalable PowerShell & Python framework across 750+ government endpoints, reducing manual security audit cycles by 60% while hardening critical CIS/NIST baselines.
Tuning Wazuh + Splunk: Cutting False Positives by 30% in CNI SOC
Practical detection engineering guide on optimizing correlation rules, establishing contextual noise baselines, and increasing true-positive threat hunting efficacy in a 24x7 nuclear SOC environment.
Beyond Security — The Triad Ecosystem
Social Impact • Animal WelfareCyberKarma — Free Rice Charity Game
cyberkarma.meGamified cybersecurity and trivia education platform where correct answers generate ethical ad revenue to feed real street animals in Patna.
Quantitative • High FrequencyJumpStreet Quant Platform (Orca6)
jumpstreet.techStatistical arbitrage quantitative trading architecture with real-time market data streaming, automated risk parameter execution, and embedded high-speed Orca6 VT100 terminal.
Executive Profile & Philosophy
Cybersecurity Engineer & NGFW Architect at Ebix Technologies (Client: NIC, MeitY Govt. of India), architecting default-deny NGFW estates (Palo Alto, Check Point, Fortinet) and managing SentinelOne, Deep Security, and Wazuh deployments across 750+ regional government endpoints.
Primary CERT-In Incident Responderwith hands-on proficiency in Active Directory attack-path analysis (Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, Delegation Abuse), web & infrastructure VAPT, and digital forensics.
Prior 24x7 CNI SOC Threat Hunter at Nuclear Fuel Complex (DAE), conducting proactive threat hunts, reverse-engineering malware payloads, and tuning SIEM correlation rules to boost true-positive rates by 35%.
Pursuing an MBA in Cybersecurity (Chitkara University), B.Tech CSE (Manipal University Jaipur), holding Fortinet FCA and EC-Council SOC, with target completion for eJPT, CEH v13, CISSP, and OSCP.
Let's Connect
Open for high-impact Cybersecurity Engineer, Purple Teamer, and SOC Lead roles.