I (***)-***-Sonia **** • # Rostami **************@*******.***
Education
City University of New York (CUNY) New York, NY
B.S. in Computer Science & Information Security (Cybersecurity) 2023–2025 Relevant Coursework: Object-Oriented Programming, Cryptography, Operating Systems, Computer Security & Forensics, Network Security & Forensics, Advanced Topics in CS, Probability & Statistics I, Calculus II, Databases and Data Mining, Linux System Admin & Security
A.A.S. in Computer Network Technology 2021–2023
Dean’s List All Semesters.
Relevant Coursework: Operating Systems, UNIX, Network Security, Database Systems, Telecommunications Networks Technical Skills
Cybersecurity & Forensics: Kali Linux, Autopsy, Wireshark, Snort, pfSense, OWASP ZAP, Windows Defender Firewall
Programming & Scripting: Python, C++, Bash, SQL
Threat Detection & Response: Firewall rule configuration, IDS/IPS setup, simulated incident response, input sanitization techniques
Cloud Platforms: Currently completing AWS Cloud Practitioner Essentials (IAM, EC2, S3, shared responsi- bility model)
Security Frameworks: Studying MITRE ATT&CK for threat classification and detection mapping Systems & Platforms: Linux System Administration, Red Hat, UNIX, VirtualBox Data Analysis & Tools: pandas, NumPy, scikit-learn, Jupyter Notebook Research Interests
Machine Learning for Cybersecurity and Threat Detection Digital Forensics and Malware Analysis
Cryptography and Secure Communication Protocols
Network Intrusion Detection and Anomaly Detection Systems Privacy-Preserving Data Mining
Secure Software Engineering and Vulnerability Assessment Work Experience
Queensborough Community College
Tech Fee Intern / Research Assistant / Mentor Jan 2024 – May 2024
Developed C++ software for secure control systems and data acquisition.
Mentored over 10 students in system security and hands-on troubleshooting.
Proposed and implemented improvements for lab hardware automation and integration. Borough of Manhattan Community College
Supplemental Instruction Leader Jan 2024 – May 2024
Led weekly Linux Red Hat sessions focused on system administration, scripting, and security. Queensborough Community College
Physics/Math/Accounting Tutor Sep 2023 – Jan 2024
Delivered individual and group tutoring sessions to support student learning and clarify complex concepts. 1/2
Borough of Manhattan Community College
Physics Tutor Apr 2023 – May 2023
Created custom lesson plans and guided students through effective study strategies. Projects
Heart Attack Prediction Using Machine Learning (05/2025): Developed a predictive model to assess heart attack risk based on patient data using logistic regression and clustering techniques. Engineered features, handled data preprocessing (normalization, encoding), and evaluated model performance using classification metrics. Built end-to-end pipelines in Jupyter Notebook with scikit-learn and pandas to automate training and testing.
XSS Exploitation and Defense Simulation (05/2025): Led the exploitation phase of a team capstone project on Cross-Site Scripting (XSS). Demonstrated how attackers compromise user sessions via Stored and Reflected XSS in a custom-built web app. Researched real-world case studies (e.g., Discord, Alibaba, British Airways) and presented risk impacts. Collaborated on detection and prevention strategies using CSP, OWASP ZAP, and input sanitization methods.
Penetration Testing a pfSense Firewall (04/2025): Performed port scanning, vulnerability assessments, and DMZ security analysis using OpenVAS, nmap, and pfSense. Recommended firewall segmentation and authentication improvements.
Configuring VPN Server and Client with pfSense (04/2025): Set up IPsec and OpenVPN tunnels for secure communication between network segments. Verified encryption and tunneling behavior using Wireshark and PowerShell.
Designing Secure Network Topologies (04/2025): Planned and implemented segmented networks with VLANs, DMZ, and firewall rules using pfSense. Captured traffic to validate connectivity and security controls.
National Cyber League – Individual and Team Challenges (04/2025): Solved hands-on challenges in digital forensics, OSINT, cryptography, and log analysis using tools like Kali Linux, Autopsy, and Wireshark during Spring 2025 competition.
Advanced pfSense Firewall Configuration (04/2025): Configured LAN, WAN, and DMZ interfaces on pfSense. Implemented custom firewall rules for DNS, SSH, ICMP, and OpenVPN. Used packet captures to verify segmentation, routing, and rule behavior.
IntrusionDetectionandLogAnalysiswithSnort&Splunk (03/2025): Deployed Snort IDS on LAN/DMZ interfaces to detect simulated attacks. Integrated log forwarding to Splunk, then simulated a DMZ breach using Infection Monkey and analyzed alert quality, detection accuracy, and rule effectiveness. Multi-Task Linux Lab Simulation (03/2025): Completed system admin tasks in a sandboxed Linux VM. Documented solutions to troubleshoot errors and practiced shell-based problem-solving. Windows Defender Firewall Configuration (04/2025): Created and tested inbound/outbound rules for IIS and SQL Server using PowerShell and GUI. Validated access control and port filtering. RBAC Research Presentation (11/2024): Presented research on Role-Based Access Control in educational systems, focusing on secure user role assignment and access management. C++ Data Structures Suite (02–03/2024): Developed custom implementations of priority queues, general trees, and maps using C++ STL and templates. Emphasized efficient, secure data structure design. Photography Studio Database (10/2022): Designed and implemented a MySQL database for managing clients, services, and scheduling within a small business context. NYC Green Spaces Analysis (08/2022): Used QGIS to analyze spatial data showing the relationship between access to public green spaces and healthcare availability across NYC neighborhoods. HTML Personal Website (02/2022): Built and published a personal portfolio site using HTML to showcase projects, technical skills, and academic background. 2/2