Resume

DevSecOps and application security engineer, currently reading for an M.Sc. in Digital Forensics and Information Security at NFSU. I have built a seven-stage GitLab CI pipeline where security scanning gates the deploy rather than following it, run Prometheus and Grafana over a container fleet across three sites, and built identity and remote-access infrastructure for a firm handling confidential client records. I came to it from the other side: VAPT against the same commercial security product a year earlier, and the full-stack systems I now audit before that.

Download PDF
jainvaibhav.mevaibhavjain@protonmail.comgithub.com/vaibhavjain2609

Experience

to

Ekvayu Tech Private LimitedDevOps and Network Security Intern

A second stint at Ekvayu Tech, on the build and network side. I owned the delivery pipeline — a seven-stage GitLab CI pipeline built as DevSecOps, where scanning gates the deploy instead of following it — along with monitoring for the container fleet and the firewall and segmentation work underneath it.

  • Built a seven-stage GitLab CI pipeline in which security scanning gates the deploy rather than following it: Gitleaks for committed secrets, Bandit and Semgrep for SAST, Checkov against Dockerfiles and Compose definitions, and Trivy across both the filesystem and the built image.
  • Fronted the pipeline with Ruff, mypy, and hadolint so a lint or type failure stops the run before anything is built, and extended it past the deploy with OWASP ZAP and smoke tests against the running service.
  • Standardised promotion from development through to production across three locations, applying the same gates to every environment rather than to production alone.
  • Stood up Prometheus and Grafana monitoring across 100+ Docker Compose containers running at three locations.
  • Found three critical defects in a core analysis subsystem that runs each submitted job in its own container: container names were drawn from a reused numeric sequence, so one name identified different jobs over time and neither metrics nor logs could be attributed to the run that produced them.
  • Configured and hardened perimeter firewalls, covering rule design and security policy configuration.
  • Designed and implemented VLAN segmentation to isolate network segments and limit lateral movement.

to

Praveen Aggarwal Chartered AccountantsIT Contractor

A chartered accountancy firm in New Delhi holding client financial records under statutory retention and confidentiality obligations. Engaged to build their identity, remote access, and backup infrastructure from nothing.

  • Architected an 80-user Active Directory environment from scratch and deployed a hybrid Active Directory and Entra ID integrated SSL VPN on a Sophos XGS firewall, with MFA and conditional access policies.
  • Minimized data loss risk in disaster scenarios by implementing automated backup policies to Azure Blob Storage, meeting 24-hour RTO and 4-hour RPO targets.
  • Reduced email infrastructure costs by 60% by migrating 20 mailboxes from Google Workspace to Microsoft 365.

to

Ekvayu Tech Private LimitedCybersecurity Analyst Intern

Ekvayu Tech is a Noida-based deep-tech cybersecurity company building email phishing detection, data protection, and threat monitoring products for enterprise and government customers. I worked the offensive side: testing their own tooling and hardening the infrastructure it was built on.

  • Discovered and reduced the attack surface of an internally developed security tool by remediating 15+ critical vulnerabilities via VAPT using Burp Suite and OWASP ZAP.
  • Secured code repository infrastructure by migrating a GitLab server while implementing configuration hardening, access controls, and least-privilege policies.
  • Resolved 10 vulnerabilities across production servers and internal applications through Nessus-based threat assessments.

to

Kendriya Karamchari Sehkari Grih Nirman Samiti LtdWeb Developer

A housing society in Noida with roughly 1,000 members, which had just won a long land dispute in the Supreme Court and needed member records it could actually query. I owned the site, the member database, and the hosting migration, and trained non-technical office staff to run all three.

  • Managed end-to-end migration of the existing website to a more cost-effective host, reducing annual expenditure by 40%.
  • Mapped records for 1,000 members and built custom PHP filters, letting leadership retrieve member information 80% faster.
  • Cut average member travel time by two hours by extending the database to store historical payment information, so members could access previous bills online.

to

Hoonar TekwurksSoftware Engineering Intern

A software development consultancy headquartered in Pune. I built the authentication layer for an internal project and the REST API behind it.

  • Raised an internal tool to OWASP ASVS Level 2 by building an authentication API with Java Spring Boot and Keycloak.
  • Delivered internal knowledge-sharing sessions on Log4j and debugging to a team of 8 engineers, getting structured logging into the team coding standard.

to

Woodstock SchoolInformation Technology Intern

An international residential school in Mussoorie, where I was also a student from 2010 to 2019. I built internal tooling on the Microsoft Power Platform for the maintenance, counselling, and security departments, and worked with the IT team on campus network and access control.

  • Saved 50 hours of manual work quarterly by building an invoice management system with Microsoft PowerApps and SharePoint.
  • Consolidated a 7-step manual student laptop-loan process into 1 automated flow with Power Automate, saving 12 hours weekly.
  • Proposed and implemented biometric check-in across 3 major campus locations, improving dormitory attendance tracking and campus access control.
  • Built a Power BI dashboard for the counselling department that contributed to a 20% increase in student counselling sessions.

Education

Skills

Databases

PostgreSQLSQLRedis

DevOps / DevSecOps

BashDockerGitGitLab CIAzureBanditCheckovCI/CD PipelinesContainer SecurityGitHub ActionsGitleaksGrafanaPowerShellPrometheusSAST & DASTSemgrepTrivy

Forensics

WiresharkAutopsyIncident ResponseMemory ForensicsStatic Malware AnalysisVolatility 3

Identity

Active DirectoryRole-Based Access ControlAuth0Entra ID (Azure AD)Keycloak

Infrastructure

Active DirectoryLinuxEntra ID (Azure AD)Sophos XGS Firewall

Languages

PythonBashJavaSQLTypeScriptC/C++PowerShell

Networking

Firewall ConfigurationNmapWiresharkNetwork SecurityOPNsenseSophos XGS FirewallVLAN Segmentation

Security

Burp SuiteFirewall ConfigurationNessusNmapOWASP Top 10OWASP ZAPRole-Based Access ControlThreat & Vulnerability AssessmentWeb Application Penetration TestingBanditCheckovContainer SecurityGitleaksIncident ResponseNetwork SecurityOPNsenseOWASP ASVSSAST & DASTSemgrepTrivy

Web Development

FastAPINext.jsReactREST API DesignTypeScriptAuth0KeycloakSpring Boot

References

References available upon request. Get in touch →