🎓 M.S. Cybersecurity & Information Assurance, University of Central Missouri (Expected May 2026) 🛡️ SOC Analyst | Application Security | Cloud Security | DevSecOps
✅ Active Directory Attack Lab — CORP.LOCAL — Domain Admin compromise via BloodHound-guided Kerberoasting (done)
Cybersecurity professional with experience across SOC, Application Security, Cloud Security, and DevSecOps — monitoring enterprise environments, investigating incidents, running vulnerability assessments, and securing CI/CD pipelines and cloud workloads across AWS and Azure.
SOC | Threat Detection & Incident Response | Application Security | Cloud Security | DevSecOps | Detection Engineering | Threat Hunting
Advanced Threat Hunting • Detection Engineering • Microsoft Sentinel • Splunk ES • Malware Analysis • Kubernetes Security • HTB CPTS Labs
Security Operations: Splunk SIEM/SOAR, CrowdStrike Falcon, Snort IDS/IPS, Proofpoint, ServiceNow Threat Intel & Vuln Mgmt: Qualys, Recorded Future, MITRE ATT&CK, Threat Hunting, Incident Response Application Security: Checkmarx (SAST), Burp Suite Pro (DAST), Snyk (SCA), Threat Modeling, OWASP Top 10/ASVS Cloud Security: AWS (GuardDuty, CloudTrail, Security Hub, IAM) | Azure (Defender for Cloud, Azure AD, Key Vault) DevSecOps: Jenkins, Azure DevOps, Git, Docker, Secure CI/CD Programming: Python, PowerShell, Bash, Java Frameworks: NIST 800-53, PCI-DSS, SOX, MITRE ATT&CK, STRIDE
🔹 SOC Detection Lab — Log analysis, alert investigation, and incident triage using Splunk, Sysmon, and Sigma rules against Windows Event Logs.
🔹 Vulnerability Management Lab — Enterprise-style asset discovery, vulnerability prioritization, and remediation validation with Qualys and Nessus.
🔹 Application Security Lab — Hands-on SAST/DAST/SCA testing and OWASP Top 10 coverage using Burp Suite Pro, Checkmarx, and Snyk.
🔹 Cloud Security Lab — AWS & Azure hardening and monitoring: IAM best practices, CloudTrail analysis, GuardDuty findings, Azure Defender, Key Vault security.
✅ CompTIA Security+ 🎯 Preparing for: GIAC GCIH, AWS Security Specialty, Microsoft AZ-500
Detection Rules • Sigma Rules • SOC Playbooks • Blue Team Labs • Cloud Security Projects • Python Security Automation
📧 hiteshmark04@gmail.com | 💼 LinkedIn | 💻 GitHub
"Security isn't about finding vulnerabilities—it's about understanding how systems fail, defending them effectively, and continuously improving resilience."