Skip to main content
All government case studies & project demos are sanitized recordings & mock telemetry; zero live state infrastructure is exposed.
VULNERABILITY MANAGEMENT • DEVSECOPS • CNI SECOPS LEAD

Aditya Jain

Cybersecurity Engineer | Vulnerability Management & DevSecOps | VAPT • SIEM/EDR • Security Automation

Results-driven Cybersecurity Engineer with 4+ years in Vulnerability Management, remediation orchestration, and security automation for government and Critical National Infrastructure (CNI). Proven record in vulnerability discovery, validation (PoC), and de-duplication; risk-based prioritization (CVSS + threat intelligence + asset criticality); and automating 120+ compliance baselines as policy-as-code across 750+ endpoints, cutting audit effort by 60%.

Level 4 Decryption GatewaySHA-256 Signed
🛰️ View Key Projects
Recruiter Fast-Facts & MobilityAvailability: 60 Days (Negotiable)
Posting: On-site NIC (MeitY), Patna | Employer HQ: Noida
Relocation: Delhi NCR, Blr, Hyd, Pune, Mum, Jaipur (Family Base)
Global Markets: UAE, Singapore, UK, Germany (EU Blue Card), EU, US
Languages: English (Professional), Hindi (Native)
Verified Impact & Operational Metrics
750+
Endpoints Secured
60%
Audit Effort Reduced
+35%
True Positives Boost
38
District Core Nodes
60+
FMS Teams Trained
aditya@secops: ~/resume
BASH 5.2
aditya@secops:~# secure session initialized...
SEC_CORE: ACTIVE | 750+ ENDPOINTS HARDENED | NIC MeitY CNI
Type 'whoami', 'skills', 'projects', 'labs', or 'help' for commands.
aditya@secops:~$
01 // Core Competencies & Toolchains

Technical Skills & Defense Toolchains

Hands-on mastery across Palo Alto/Fortinet NGFW, Active Directory red teaming, enterprise EDR/SIEM, compliance orchestration, and agentic AI OPSEC.

03 // Key Security Projects & Planetary Matrix

Critical Infrastructure Portals & Engineering Systems

Production monitoring platforms, synthetic diagnostic suites, and automated compliance engines built for government and enterprise operations.

38 / 38
DHQ Loopbacks
293
Monitored IPs
0.01%
Firewall Drop
60%
Audit Time Cut
Filter Grid:
DevSecOps & CI/CDORBIT: SHIFT-LEFT-01

DevSecOps CI/CD Security Pipeline (Lab)

Impact: Embedded SAST, SCA, IaC & DAST automated security gates across build-test-deploy stages

Multi-stage automated CI/CD security pipeline built on GitHub Actions integrating Semgrep (SAST), Trivy (container/SCA), Checkov (IaC), and OWASP ZAP (DAST) for automated pull-request vulnerability triage.

#GitHub Actions#Semgrep#Trivy#Checkov#OWASP ZAP#Docker
Sanitized Demo
Live NOC SandboxORBIT: 38-DHQ-CORE

State NOC Admin Portal (NIC Bihar)

Impact: Monitors 38 district nodes with live traceroute & Ollama voice RAG LLM

Enterprise network operations dashboard monitoring 38 regional district nodes with live traceroute diagnostics, automated outage alerting, and an on-premise Ollama voice-enabled RAG chatbot.

#Next.js#Ollama LLM#PHP API#Three.js#RAG
Live TelemetryORBIT: 293-NODES

Real-Time Network Alert Dashboard

Impact: JavaScript/CSS Grid ping-monitoring tool for government routers with voice alerts

Sub-second packet loss and ping outage tracking across 293 core routing units with Indian English Web Speech broadcast alarms, severity filtering, and device grid visualization.

#JavaScript#Chart.js#Web Speech API#Glassmorphic
CNI ObservabilityORBIT: 38-DISTRICTS-SLA

Unified NOC Monitoring Suite (NIC Bihar)

Impact: Synthetic monitoring platform for VC health, WAN speed-tests & SLA reporting

In-house observability platform delivering video-conferencing (VC) health monitoring, district WAN speed-tests, and automated portal availability checks across 38 districts with severity-tiered alerting.

#Synthetic Probes#QoS Analysis#WAN Latency#SLA Engine
Run Diagnostics SuiteSanitized Demo
Deployment AutomationORBIT: PXE-DHCP-CORE

LAN Asset Management Portal

Impact: DHCP/PXE-based automated OS deployment & secure internal file distribution

Locally-hosted Python/Bash asset management infrastructure enabling silent PXE OS provisioning, hardware inventory tracking, and cryptographic internal software distribution.

#Python#Bash#DHCP/PXE#Asset Inventory#Linux RHEL
Sanitized Demo
SecOps AutomationORBIT: NIST-CSF-01

CDAC / CERT-In Compliance Automation Engine

Impact: Cut quarterly compliance audit time by 60% across 750+ endpoints

Automated PowerShell & Python framework validating 120+ regulatory baselines, USB lockouts, SMBv1 deprecation, and registry hardening across 750+ endpoints via KACE UEM.

#PowerShell#Python#KACE UEM#NIST CSF#CERT-In
Sanitized Demo
Karma & Quant TriadORBIT: SOCIAL-ALGO

CyberKarma & JumpStreet Triad Ecosystem

Impact: Free Rice animal welfare platform + Orca6 algorithmic trading platform

Gamified educational trivia platform converting cybersecurity quizzes into real stray animal meals in Patna + statistical arbitrage quantitative trading architecture (Orca6).

#Next.js#Web3/Charity#Algorithmic Quant#TypeScript
Explore cyberkarma.meSanitized Demo
04 // Professional Work History (4+ Years CNI)

Enterprise SecOps Experience (4+ Years)

Feb 2024 — Present Patna, Bihar, India

Security Administrator & NGFW Architect

Ebix Technologies (Client: National Informatics Centre - NIC, MeitY Govt. of India)
750+ EndpointsPalo AltoCheck PointSentinelOneDeep SecurityWazuhKACE UEM
  • NGFW & Network Hardening: Architect and enforce default-deny policies across Palo Alto and Check Point NGFW clusters; audit public IP exposure and secure Linux rack servers across the Bihar State Data Centre (SDC).
  • Enterprise EDR/SIEM Deployment: Manage SentinelOne, Trend Micro Deep Security, and Wazuh/Splunk deployments across 750+ regional government endpoints; tune correlation rules against emerging attack vectors, reducing false-positive fatigue by 30%.
  • Incident Response & Compliance: Serve as primary CERT-In incident responder; automate compliance reporting (120+ CDAC/CERT-In checks via KACE UEM), cutting manual audit effort by 60%.
  • VAPT & AD Security: Lead coordination with NIC-CERT to remediate critical web vulnerabilities (authoring PoC exploits) and conduct Active Directory attack-path analysis to secure district-level nodes.
  • Unified NOC Monitoring Suite: Engineered an in-house observability platform delivering video-conferencing (VC) health monitoring, WAN speed/latency probing, and automated portal availability checks across 38 districts; reduced outage detection time and produced SLA evidence for FMS teams.
  • Security Training: Deliver specialized training on NGFW, EDR, and CERT-In compliance to 60+ district-level Facility Management System (FMS) teams.
Aug 2023 — Jan 2024 Remote

Independent Security Researcher

Offensive Security & Active Directory Exploitation Focus
Active DirectoryHack The BoxVulnLabKerberoastingDCSyncPrivEsc
  • Executed advanced Active Directory exploitation labs (Hack The Box, VulnLab multi-forest environments), mastering Kerberoasting, DCSync, and Domain Controller compromise techniques.
  • Pursued MBA (Cybersecurity) coursework and aligned certification trajectories (eJPT, CEH) to bridge defensive architecture with offensive red-team methodologies.
Dec 2022 — Jul 2023 Kota, Rajasthan, India

SOC Analyst – Threat Hunter

RRG Engineering Tech (Client: Nuclear Fuel Complex - NFC / DAE Govt. of India)
24x7 CNI SOCBlu Sapphire SIEMSplunk+35% Detection BoostMalware TTPs
  • CNI SOC Operations: Operated as SME for threat hunting in a 24/7 Critical National Infrastructure SOC, monitoring enterprise telemetry via Blu Sapphire SIEM and Splunk.
  • Detection Engineering: Engineered and tuned SIEM correlation rules and EDR policies, achieving a 35% improvement in true-positive detection rates.
  • Malware Analysis: Performed behavioral malware analysis and sandbox payload reproduction to reverse-engineer TTPs and update detection signatures.
Aug 2022 — Oct 2022 Vellore, Tamil Nadu, India

SOC Analyst – IDS & Signature Development

E2E Networks Limited
Snort IDSWazuh SIEMAbuseIPDB FeedPerimeter Defense
  • Authored and deployed custom Snort and Wazuh IDS signatures, improving detection coverage against novel attack patterns in a 24/7 SOC environment.
  • Automated AbuseIPDB feed ingestion for real-time perimeter IP blocklisting, significantly reducing inbound malicious traffic and routing anomalies.
Dec 2021 — May 2022 Jaipur, Rajasthan, India

Technical Support Executive (Microsoft Enterprise)

Teleperformance
Tier-2 Enterprise SupportMicrosoft 365SLA Compliance
  • Delivered Tier-2 Microsoft enterprise product support, maintaining strict SLA compliance and contributing to internal knowledge base documentation.
05 // Credentials, Labs & Academic Coursework

Hands-On Security Labs & Academic Coursework

Offensive Security Labs

Red Team & AD Exploitation
  • 01Hack The Box: Active Directory exploitation, Kerberoasting, privilege escalation & network pivoting.
  • 02VulnLab Multi-Forest Labs: Forest trust abuse, DC shadow attacks, DCSync, and full Domain Controller compromise.
  • 03OPSEC & Anonymity: Tor network research and threat intelligence infrastructure for defensive early-warning feeds.

Academic Security Coursework

University Specializations
  • 01Security Management & Governance: Royal Holloway, University of London — Enterprise risk matrices & policies.
  • 02Introduction to Network Security: University of London — Cryptographic key exchanges, packet filters & TLS.
  • 03Mathematical Foundations for Cryptography: University of Colorado — Asymmetric ciphers, hashing, and discrete log.
05.1 // Verified Certifications Roadmap

Professional Certifications & Ongoing Roadmap

Fortinet
Fortinet Certified Associate (FCA)
Earned & Verified (Jan 2026)
EC-Council
In the Trenches: SOC
Earned & Verified
eLearnSecurity
eJPT (Junior Penetration Tester)
In Progress (Target: Q4 2026)
EC-Council
Certified Ethical Hacker (CEH v13)
In Progress (Target: 2026)
ISC2
CISSP (Information Systems Security)
Targeted (Q3 2027)
OffSec
OSCP (Offensive Security Certified)
Targeted (2027+)
HTB & VulnLab
Active Directory Multi-Forest Labs
Mastery Level
Chitkara University
MBA in Cybersecurity
In Progress (Expected Jul 2027)
05.2 // Academic Higher Education

Degrees & Cybersecurity Qualifications

Expected Jul 2027

MBA in Cybersecurity

Chitkara University • Punjab, India

Postgraduate studies in enterprise cybersecurity risk governance, compliance frameworks, and defensive/offensive purple team alignment.

In Progress (Active Coursework)
2019 — 2022

B.Tech — Computer Science & Engineering

Manipal University Jaipur • Rajasthan, India

Undergraduate degree in CSE with extensive coursework in Network Security, Operating Systems, Cryptography, and Distributed Systems.

Completed • B.Tech CSE
2013 — 2018

Diploma — Computer Science & Engineering

Hindu College of Engineering • Haryana, India

Core engineering diploma covering computer networking, system administration, C/C++ programming, and digital electronics.

Completed • Diploma CSE
07 // Technical Publications & Field Blueprints

Technical Write-Ups & Defense Blueprints

Sanitized threat hunting methodology, Active Directory attack chain reproductions, and compliance automation scripts.

Offensive Security / Active Directory7 min read

Kerberoasting → DCSync: Chaining AD Attacks in a Multi-Forest Lab

Deep-dive analysis on requesting TGS tickets for SPN accounts, cracking RC4/AES hashes with Hashcat, escalating through nested delegation groups, and executing DCSync via Impacket secretsdump.

Read Full Blueprint
SecOps / Compliance Automation5 min read

Automating 120+ CERT-In Checks with PowerShell & KACE UEM

How we engineered a scalable PowerShell & Python framework across 750+ government endpoints, reducing manual security audit cycles by 60% while hardening critical CIS/NIST baselines.

Read Full Blueprint
Detection Engineering / SIEM6 min read

Tuning Wazuh + Splunk: Cutting False Positives by 30% in CNI SOC

Practical detection engineering guide on optimizing correlation rules, establishing contextual noise baselines, and increasing true-positive threat hunting efficacy in a 24x7 nuclear SOC environment.

Read Full Blueprint
08 // Breadth & Engineering Diversity

Beyond Security — The Triad Ecosystem

CyberKarma - Play Free Quizzes, Feed Street Dogs
Social Impact • Animal Welfare

CyberKarma — Free Rice Charity Game

cyberkarma.me

Gamified cybersecurity and trivia education platform where correct answers generate ethical ad revenue to feed real street animals in Patna.

#Next.js#Free Rice Model#Gamified Learning#Ethical Ads#Direct Charity
JumpStreet - High-Frequency Quantitative Trading & Orca6 Bot
Quantitative • High Frequency

JumpStreet Quant Platform (Orca6)

jumpstreet.tech

Statistical arbitrage quantitative trading architecture with real-time market data streaming, automated risk parameter execution, and embedded high-speed Orca6 VT100 terminal.

#TypeScript#Algorithmic Arbitrage#Orca6 Engine#WebSocket Streaming#Risk Controls
09 // Professional Summary

Executive Profile & Philosophy

Cybersecurity Engineer & NGFW Architect at Ebix Technologies (Client: NIC, MeitY Govt. of India), architecting default-deny NGFW estates (Palo Alto, Check Point, Fortinet) and managing SentinelOne, Deep Security, and Wazuh deployments across 750+ regional government endpoints.

Primary CERT-In Incident Responderwith hands-on proficiency in Active Directory attack-path analysis (Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash, Delegation Abuse), web & infrastructure VAPT, and digital forensics.

Prior 24x7 CNI SOC Threat Hunter at Nuclear Fuel Complex (DAE), conducting proactive threat hunts, reverse-engineering malware payloads, and tuning SIEM correlation rules to boost true-positive rates by 35%.

Pursuing an MBA in Cybersecurity (Chitkara University), B.Tech CSE (Manipal University Jaipur), holding Fortinet FCA and EC-Council SOC, with target completion for eJPT, CEH v13, CISSP, and OSCP.

DIRECT_CONTACT // OPEN_TO_OPPORTUNITIES

Let's Connect

Open for high-impact Cybersecurity Engineer, Purple Teamer, and SOC Lead roles.

Open to relocation: India (Delhi NCR/Blr/Hyd/Pune/Mum/Jaipur) • UAE • Singapore • UK • Germany (EU Blue Card) • EU • US
security.txt Policy