// CYBERSECURITY PROFESSIONAL

SANKETH SUBHAS

SOC Analyst  ·  GRC  ·  Threat Detection

Results-driven Cybersecurity professional with 3.5+ years of experience in enterprise security operations, incident response, and threat mitigation. M.S. Cybersecurity, Pace University (GPA: 3.92). CompTIA Security+ & ISO 27001 Certified.

sanketh@portfolio:~$
whoami
Sanketh Subhas — Cybersecurity Analyst

cat location.txt
📍 New York, NY

cat education.txt
M.S. Cybersecurity — Pace University (GPA: 3.92)
B.E. Engineering — Dayanand Sagar College

ls certifications/
CompTIA Security+
ISO 27001 Internal Auditor
Google Cybersecurity Professional
EC-Council CEH
Linux System Administration (IBM)

Technical Arsenal

▸ Security Operations
SIEM (Splunk)IDS/IPS MITRE ATT&CKIncident Response NessusOpenVAS
▸ GRC & Compliance
NIST CSFISO 27001 CIS BenchmarksIAM PII ProtectionFERPA
▸ Offensive Security
Ethical HackingKali Linux NmapWireshark ScapySQLi/CSRFOSINT
▸ Cloud & DevSecOps
AWS (EC2, S3, IAM)CloudWatch JenkinsGrype AnsibleCI/CD Security
▸ Tools & Languages
PythonPowerShell SQLSplunk ServiceNowLinuxGitHub

Work History

Cybersecurity Analyst Oct 2024 – Present
Community Dreams Foundation · Remote
  • Executed vulnerability scans using Nessus and OpenVAS, reducing attack surface by 25%.
  • Implemented Principle of Least Privilege (PoLP) across user access protocols.
  • Conducted security audits aligned with NIST CSF and ISO 27001.
  • Mapped adversary tactics using the MITRE ATT&CK framework.
Data Management Associate – Information Governance Mar 2025 – Present
Harlem Children's Zone · New York, NY
  • Managed lifecycle of sensitive participant data with 100% accuracy and FERPA compliance.
  • Enforced PoLP by managing user permissions and database access controls.
  • Performed recurring QA audits on digital records to detect anomalies.
Security Software Engineering Intern Jun 2024 – Oct 2024
Shoptaki Inc. · New York, NY
  • Optimized Smartchain platform security architecture for blockchain-based data transfers.
  • Achieved 30% increase in system performance through code reviews and usability testing.
  • Integrated AI-driven fraud detection and Quantum-Safe Cryptography.
Audit & Compliance Focal – Security GRC Sep 2021 – Aug 2022
Kyndryl (IBM) · Bengaluru, India
  • Directed vulnerability assessments across 675+ enterprise servers using Ansible.
  • Achieved 100% compliance across consecutive bi-annual audits.
  • Primary SPOC for internal and external auditors.
Global SME – Linux Security (Tier-3 IR Lead) Sep 2019 – Sep 2021
IBM · Bengaluru, India
  • Spearheaded Incident Response lifecycle for global Linux desks as Tier-3 lead.
  • Directed and mentored a team of 12 security professionals.
  • Engineered advanced Linux security protocols, earning global recognition.
Technical Representative Oct 2018 – Sep 2019
IBM · Bengaluru, India
  • Resolved 25+ complex technical tickets daily, maintaining 100% CSAT for 11 months.
  • Identified and mitigated infrastructure vulnerabilities for global clients.

Research & Projects

LIVE PROJECT
Personal Project · 2025
Log Analyzer & Threat Detector

Python tool that parses Apache and Windows auth logs, detects threats like brute force attacks, port scans, and SQLi attempts, and maps them to MITRE ATT&CK techniques with severity-rated reports.

PythonMITRE ATT&CK Log AnalysisSOCBlue Team
⌥ View on GitHub
LIVE PROJECT
Personal Project · 2025
Automated CIS Benchmark Compliance Checker

Cross-platform Python tool that audits Linux and macOS systems against CIS Benchmark controls — 36 checks across account policy, SSH hardening, file permissions, network security, and logging. Auto-detects OS and generates scored compliance reports with remediation guidance.

PythonCIS Benchmarks GRCLinuxmacOSCompliance
⌥ View on GitHub
LIVE PROJECT
Personal Project · 2025
Phishing Email Analyzer

Python tool that analyzes .eml email files for phishing indicators — validates SPF/DKIM/DMARC, detects From/Reply-To mismatches, URL shorteners, suspicious TLDs, and credential requests. Scores risk 0–100 with color-coded verdict and remediation guidance.

PythonEmail Security PhishingSOCThreat Analysis
⌥ View on GitHub
LIVE PROJECT
Personal Project · 2025
Network Scanner & Vulnerability Reporter

Multithreaded Python network scanner that identifies open ports, maps services to a built-in vulnerability database, and generates MITRE ATT&CK aligned risk reports. Supports single hosts and CIDR network ranges with JSON export for SIEM integration.

PythonNetwork Security MITRE ATT&CKVulnerability AssessmentBlue Team
⌥ View on GitHub
LIVE PROJECT
Personal Project · 2025
MITRE ATT&CK Threat Mapping Dashboard

Threat intelligence tool that maps attack indicators, log events, and IOCs to MITRE ATT&CK tactics and techniques. Visualizes kill chain coverage across all 14 tactics with 35+ techniques, severity scoring, and built-in ransomware, APT, and web attack scenarios.

PythonMITRE ATT&CK Threat IntelligenceSOCThreat Hunting
⌥ View on GitHub
LIVE PROJECT
Personal Project · 2025
Honeypot & Attacker Intelligence System

Lightweight honeypot simulating SSH, HTTP, and FTP services to capture attacker activity. Logs credentials attempted, detects brute force and port scanning, maps all events to MITRE ATT&CK, and generates attacker intelligence reports with IP profiling.

PythonHoneypot Threat IntelligenceMITRE ATT&CKBlue Team
⌥ View on GitHub
Pace University · 2024
Cloud & Container Security – DevSecOps Capstone

Engineered a secure CI/CD pipeline using Jenkins and Grype for automated container vulnerability scanning. Architected AWS infrastructure (EC2, S3, IAM) with real-time CloudWatch monitoring.

JenkinsGrype AWSCloudWatchDevSecOps
Pace University · 2022–2024
Advanced OSINT & Threat Intelligence Research

Identified exposed assets and attack vectors using Shodan and Maltego. Analyzed datasets to produce actionable threat intelligence reports.

ShodanMaltego OSINTThreat Intel
Pace University · 2024
Data Breach Analysis & Impact Assessment

Evaluated root causes of high-profile breaches and delivered a formal remediation strategy to faculty and (ISC)² industry experts, receiving top honors for technical depth.

Risk AnalysisIncident Response Remediation

Credentials

🛡️
CompTIA Security+
● Active
🛡️
ISO 27001 Internal Auditor
● Active
🛡️
Google Cybersecurity Professional
● 2026
🛡️
EC-Council CEH
● Certified
🛡️
Linux System Administration
● IBM

Get In Touch

Open to new opportunities in SOC analysis, threat detection, GRC, and related cybersecurity roles. Feel free to reach out.

status.sh
./check_availability.sh

[ ] Status: Open to Opportunities
[ ] Role: SOC Analyst / GRC / Threat Detection
[ ] Type: Full-time / Contract
[ ] Location: Remote / New York

Response time: < 24 hours