Cyber Security Engineer
Current• Leveraged advanced vulnerability scanning solutions like Rapid 7 to identify critical infrastructure vulnerabilities and devised comprehensive remediation plans to mitigate associated risks• Partnered with the infrastructure team to tackle and resolve the critical Remote Code Exploit (CVE-2023-36710), impacting 16 Windows 2016 servers. This action halted privilege escalation prevented NTLM credential theft, and thwarted potential relay attacks, improving overall security by 38%.• Achieved a 25% improvement in system security and operational efficiency by proficiently managing Azure Active Directory (AD) permissions, ensuring stringent access control through detailed configuration and permissions• Contributed to the Bugcrowd Bounty program by reviewing vulnerability disclosure reports from external third-party security researchers, focusing on assessing critical to low vulnerabilities in the MSK infrastructure.• Conduct validation of threats and attacks utilizing Attack IQ to ensure robust security measures.