About
GRC and Security Compliance Analyst with 3+ years of hands-on cybersecurity engineering experience spanning VAPT, cloud security (AWS/Azure), and SIEM-based monitoring, now focused on audit support, compliance assessments, and risk management. Proven track record supporting SOC 2 and PCI-DSS audits, leading evidence collection and control implementation, and conducting third-party risk assessments. Combines deep technical fluency (vulnerability assessment, IAM, encryption, security monitoring) with growing GRC expertise — a rare profile that lets me evaluate whether controls are not just documented, but actually working. Actively pursuing CISSP to formalize governance and risk management expertise.
Skills & Expertise (41)
Work Experience
Cybersecurity Engineer / Security Analyst
Innefu Labs
Jan 2022 - Jan 2025
Supported GRC activities including audit evidence collection, policy and control implementation, and audit coordination for compliance frameworks including SOC 2 and PCI-DSS — directly applicable to internal/external audit support. Conducted vendor and third-party risk assessments, reviewing security controls and responding to security questionnaires as part of TPRM processes — core experience for ongoing vendor compliance monitoring. Performed VAPT for web applications, networks, and REST APIs using Burp Suite, OWASP ZAP, Nessus, Metasploit, and Nmap, identifying and remediating critical vulnerabilities including SQL injection and Broken Object Level Authorization (BOLA). Improved AWS/Azure security posture by hardening IAM policies, network security groups, and encryption settings, and by expanding security monitoring and logging coverage — strengthening the technical controls auditors assess under PCI DSS Req. 1, 3, 7, 8, and 10. Monitored and triaged security events using Splunk and Microsoft Sentinel, supporting incident response and providing a practical foundation in log review and security monitoring — a key control area under PCI DSS Requirement 10. Integrated security checks (SAST, DAST, dependency scanning) into CI/CD pipelines, enabling earlier detection of application security issues and reducing the volume of vulnerabilities reaching production.
Education
Bachelor of Arts (BA) - IGNOU
- 2019 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Citizen
Relocation
Open to Relocation
Skills (41)
Click a skill to find developers with the same skill