
Associate at Mandiant
Greater New York City Area

Associate at Mandiant
Greater New York City Area
(Privately Held; Computer & Network Security industry)
June 2009 — Present (10 months)
Work as an information security consultant on proactive services which include: penetration testing, vulnerability assessments, social engineering, threat analysis, etc.
(Educational Institution; Higher Education industry)
May 2008 — May 2009 (1 year 1 month)
Working on NSF funded medical records security and privacy project under Prof. Gene Spafford.
- Analyzed how auditing and logging is carried out in medical record systems by studying two open source medical record systems.
- Conducted a broad research on the different medical record systems, standard developing organizations, standards, etc pertaining to electronic medical records that are present in the market.
- Obtained privacy and security requirements for medical record systems after going through the HIPAA regulation (45CFR parts 160, 162, & 164)
(Educational Institution; Higher Education industry)
August 2007 — May 2009 (1 year 10 months)
M.S - Information Security
(Computer Software industry)
June 2008 — August 2008 (3 months)
Worked on SRB (Storage resource broker), a data grid management system, to help share project resources of a team between different geographical locations
(Educational Institution; 10,001 or more employees; Higher Education industry)
January 2008 — May 2008 (5 months)
Instructor of the lab for the course C&IT 267- Introduction To C++ Programming.
(Educational Institution; 10,001 or more employees; Higher Education industry)
September 2007 — December 2007 (4 months)
Investigated identity management life-cycle and the relationship between accounts and certificates.
(Public Company; 10,001 or more employees; CTSH; Information Technology and Services industry)
July 2005 — June 2007 (2 years )
• Analyzed Apache WSS4J (Web-services Security for Java), and proposed extension to support more functionality such as SSO using SAML
• Developed a bank website using Java/J2EE and Axis 2 web-services framework
• Secured the same website using WSS4J (Web-Services Security for Java)
• Attended workshop on IBM Tivoli Identity and Access Management Tools
• Tested (functional testing) the Security features and Identity Access Management of a well known Enterprise Portal tool.
• Extended Data Obfuscation Tool (DCipher) in J2EE-struts framework
• Played a key role (in a team of 7) as a coordinator and developer in developing a Healthcare Billing System, a Proof-of-Concept Project, using EAI tools
M.S , Information Security , 2007 — 2009
Bachelor of Engineering , Computer Science , 2001 — 2005
2001
Computer networking, Wireless networks, Network security, Secure programming, Malware and botnet analysis, Professional networking, Movies, Science-fiction, Wall/Rock climbing, Mountaineering, Skiing, Flying
Center for Education and Research in Information Assurance and Security (CERIAS), Association for Computing Machinery (ACM), Purdue Pilots Inc., Purdue Outdoor Club, Stallione Infotech (P) Ltd