Security Engineer specializing in endpoint security, cloud governance, and application security. Experienced in strengthening data protection, improving compliance rates, and implementing security hardening across enterprise environments.
A Model Context Protocol server that turns an LLM into a vulnerability triage analyst. Eight tools pull live data from NIST NVD, FIRST EPSS, CISA KEV, Exploit-DB, and MITRE ATT&CK β CVE lookup, exploitation scoring, active-exploitation checks, public-exploit search, single and bulk triage, remediation guidance, and CWE-to-technique mapping.
Triage fans out four concurrent API calls per CVE and applies rule-based decision logic in plain Python, so every verdict is reproducible and auditable rather than model-generated. Bulk triage returns a prioritized patch list for up to 50 CVEs in a single call.
Developed and implemented an enterprise security program for an ed-tech startup, ensuring strong cybersecurity. Managed Incident Response for a phishing attack, swiftly mitigating threats and minimizing damage. Developed a security plan and roadmap integrating SIEM, IDS, firewalls, and compliance with NIST, ISO, and cyber laws.
Led the development and implementation of an integrated security solution using IPS, IDS, and EDR technologies. Performed network security assessments, identified vulnerabilities, deployed endpoint security, and enforced DLP strategies. Implemented SOAR tools for efficient incident response and disaster recovery.
Comprehensive cloud security implementation covering IAM, AWS GuardDuty, WAF configurations, and security hardening across AWS and Azure environments. Focused on cloud security compliance and best practices.
Hands-on penetration testing projects covering web application exploitation, network attacks, privilege escalation, and post-exploitation techniques using industry-standard tools.
Implementation of secure coding practices, vulnerability analysis, and building secure applications. Focus on preventing common vulnerabilities like SQL injection, XSS, and CSRF.
Low-level binary exploitation, reverse engineering, and vulnerability research in C programs and Unix systems. Includes buffer overflow, format string exploits, and return-oriented programming.
Network security implementations including packet analysis, intrusion detection, firewall configurations, and network-based attacks and defenses.
Comprehensive exploration of security tools and frameworks used in information security, including SIEM, vulnerability scanners, and security automation.
Security analysis and exploitation of embedded systems, IoT devices, and hardware security including firmware analysis and hardware hacking techniques.
Both files come out of the same eight-tool MCP server: NVD lookup β EPSS score β KEV check β Exploit-DB β verdict.