๐ M.S. Cybersecurity & Information Assurance
University of Central Missouri (Expected May 2026)
๐ก๏ธ SOC Analyst | Application Security | Cloud Security | DevSecOps
I'm a cybersecurity professional with experience across Security Operations Center (SOC), Application Security, Cloud Security, and DevSecOps.
My background includes monitoring enterprise environments, investigating security incidents, performing vulnerability assessments, integrating security into CI/CD pipelines, and securing cloud workloads across AWS and Azure.
I enjoy building security labs, automating security workflows, documenting technical research, and continuously improving offensive and defensive security skills.
- Security Operations Center (SOC)
- Threat Detection & Incident Response
- Application Security
- Cloud Security
- DevSecOps
- Detection Engineering
- Threat Hunting
- Advanced Threat Hunting
- Detection Engineering
- Microsoft Sentinel
- Splunk ES
- Malware Analysis
- Kubernetes Security
- Advanced Cloud Security
- HTB CPTS Labs
- Splunk SIEM
- Splunk SOAR
- CrowdStrike Falcon
- Snort IDS/IPS
- Proofpoint
- ServiceNow
- Qualys
- Recorded Future
- MITRE ATT&CK
- Threat Hunting
- Incident Response
- Vulnerability Assessment
- Checkmarx (SAST)
- Burp Suite Professional (DAST)
- Snyk (SCA)
- Secure Code Review
- Threat Modeling
- OWASP Top 10
- OWASP ASVS
- GuardDuty
- CloudTrail
- Security Hub
- IAM
- Defender for Cloud
- Azure AD
- Key Vault
- Jenkins
- Azure DevOps
- Git
- Docker
- Secure CI/CD Pipelines
- Python
- PowerShell
- Bash
- Java
- NIST 800-53
- PCI-DSS
- SOX
- MITRE ATT&CK
- STRIDE
Enterprise Active Directory lab covering:
- AD Enumeration
- Privilege Escalation
- Kerberoasting
- Lateral Movement
- BloodHound Analysis
- Evil-WinRM
- PowerView
Tools
- BloodHound
- PowerView
- Impacket
- Evil-WinRM
- CrackMapExec
Built a SOC lab for monitoring and investigating security events.
Topics include:
- Log Analysis
- Threat Detection
- Alert Investigation
- Windows Event Logs
- Incident Triage
Tools
- Splunk
- Sysmon
- Windows Event Viewer
- Sigma Rules
Performed enterprise-style vulnerability assessments.
Topics:
- Asset Discovery
- Vulnerability Prioritization
- Risk Assessment
- Remediation Validation
Tools
- Qualys
- Nessus
Hands-on AppSec testing covering:
- SAST
- DAST
- Dependency Scanning
- OWASP Top 10
Tools
- Burp Suite Professional
- Checkmarx
- Snyk
AWS & Azure security monitoring and hardening.
Topics:
- IAM Best Practices
- CloudTrail Analysis
- GuardDuty Findings
- Azure Defender
- Key Vault Security
- โ CompTIA Security+
- ๐ฏ Preparing for:
- GIAC GCIH
- AWS Security Specialty
- Microsoft AZ-500
- Security Research
- Detection Rules
- Sigma Rules
- SOC Playbooks
- Blue Team Labs
- Cloud Security Projects
- Application Security Labs
- Python Security Automation
๐ง Email
hiteshmark04@gmail.com
๐ผ LinkedIn
https://www.linkedin.com/in/hitesh-bandaru
๐ป GitHub
https://github.com/hiteshus816
"Security isn't about finding vulnerabilitiesโit's about understanding how systems fail, defending them effectively, and continuously improving resilience."