About
IT Security Engineer with 2+ years of experience securing hybrid Azure and AWS environments, managing SIEM-based threat monitoring and incident response, and leading ISO 27001:2022 and SOC 2 (Type I & II) compliance audits. Skilled in identity and access management, network security, and integrating security into CI/CD pipelines through DevSecOps practices. Looking to bring a security-first mindset and hands-on cloud and infrastructure expertise to a growing security team.
Skills & Expertise (39)
Work Experience
IT Security Engineer
Emsphere Technologies
Aug 2024 - Present
Implemented MFA, Conditional Access, and DLP policies across Microsoft 365 and Active Directory for 125 users, reducing unauthorized access attempts by 90%. Strengthened identity governance through role-based access control, managing permissions for 125 users and groups. Administered Azure and AWS environments hosting 30+ VMs, configuring NSGs, firewalls, and load balancers for secure, scalable infrastructure. Designed VPC/VNet architectures with network segmentation across 2-5 subnets, reducing the attack surface for production workloads. Deployed Wazuh SIEM for centralized logging and threat detection across 175 endpoints, cutting average incident detection time by 50-70%. Implemented Dimension for network monitoring and anomaly detection, flagging 100-250 anomalies per month. Configured and managed 2 physical firewalls and Check Point Endpoint Security across 175 devices, and configured L2/L3 switches, VLANs, inter-VLAN routing, and ACLs across 4–8 sites for secure internal networking. Hardened 30 IIS servers and enforced SSL/TLS encryption across all hosted applications. Secured application deployments by applying OWASP best practices, reducing flagged vulnerabilities by 40%-60%. Implemented GitLab for version control, integrating it with Active Directory for authentication and role-based access control across 70 repositories. Deployed SonarQube for continuous code quality and security scanning linked with GitLab pipelines, flagging 200–800 vulnerabilities before deployment. Integrated both tools into CI/CD workflows to enforce secure development practices across 30-100 deployments per month. Led ISO 27001:2022 and SOC 2 (Type I & II) audits covering controls with zero major non-conformities. Conducted risk assessments across 150-300 systems and implemented mitigation controls, reducing identified risks by 40-60%. Implemented disaster recovery and backup strategies and improved incident management and SLA adherence using ITSM tools, raising on-time resolution rates to 95–99%.
Education
PG Diploma in IT Infrastructure, Systems and Security - CDAC – Sunbeam Infotech Pvt. Ltd.
- 2024 · Afghanistan
B.E. in Electronics and Telecommunication Engineering - Dr. D. Y. Patil College of Engineering, Akurdi
- 2023 · Afghanistan
Certifications
Cybersecurity Analyst
Udemy · 2026
QRadar: Data, Components, and Cybersecurity
Udemy · 2026
IP Addressing and Subnetting
Udemy · 2025
Fundamentals of Cloud Computing
Udemy · 2025
Executive Diploma in CIO (Chief Information Officer)
Udemy · 2025
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (39)
Click a skill to find developers with the same skill