IVAN MAPANGA
Hyattsville, MD Tel: 240-***-**** Email: ********@***.*** https://www.linkedin.com/in/ivanmapanga/ Master of Engineering in Cybersecurity student with practical experience in network hardening, SIEM monitoring, cloud security, and threat detection. Proven ability to reduce attack surface, secure hybrid environments (AWS/Azure/GCP), and implement risk-aligned frameworks. Currently seeking 2026 summer IT/Cybersecurity internship. SKILLS
Operating Systems & Virtualization: Windows, Linux (Ubuntu/Kali), macOS, VMWare, Docker Programming & Scripting: Python, Bash, C, SQL, PowerShell (basic) Cloud & Identity: AWS, Azure, GCP, Active Directory, Microsoft Entra, Exchange Online Security & Monitoring: Elastic SIEM (ELK), Splunk, Snort, Wireshark, TheHive, Microsoft Defender Networking & Firewalls: Sophos XGS, Cisco, Mikrotik, Unifi, VLAN segmentation, IPS/IDS, TCP/IP Frameworks & Compliance: NIST CSF, MITRE ATT&CK, ISO 27001, Cyber Kill Chain Soft Skills: Analytical problem solving, cross-functional communication, initiative, attention to detail EXPERIENCE
Croco Holdings Group (www.crocoholdings.co.zw) Harare, ZW Assistant Group Network Administrator Jan/2024 – Aug/2025
• Conducted daily reviews of Entra ID sign-in logs and Exchange anomalies alongside user/group/license/MFA management; identified and responded to potential unauthorized access, achieving 30% incident reduction and 45% faster provisioning.
• Engineered Sophos XGS firewall rollout across six branches, replacing Mikrotik with AD-integrated identity controls and advanced Layer 7 threat intelligence; cut internal attack surface by 40% and enhanced threat visibility by 35%
• Responded to branch-site LAN outages, troubleshooting and reconfiguring switches, routers, and cabling with secure configurations; achieved average 2-hour resolution time and reduced recurring network outages by 35%
• Configured Cisco switches across branches with VLAN segmentation, port security and IOS upgrades, reduced network attack surface by 40% and improved security posture by closing critical CVEs.
•
IT Graduate Trainee Oct/2021 – Dec/2023
• Enforced Active Directory GPOs with strong passwords, monthly resets, three-failed lockouts, and restricted logons; lowered unauthorized access incidents by 35% and reduced privilege escalation exposure by 50%.
• Administered UniFi access points via portal with single-SSID, WPA3 security, and centralized rogue AP detection; reduced support tickets by 40% and improved Wi-Fi uptime by 25% with stronger wireless protection.
• Set up Mikrotik routers via Winbox with subnetting, DHCP pools, ACLs, QoS for critical apps, static IP mapping, bandwidth shaping, and hotspot authentication; reduced bandwidth misuse by 30% and increased uptime by 40%
• Deployed OneDrive for encrypted backup and SharePoint for role-based file sharing; enhanced data protection (40% risk reduction) and improved cross-team collaboration by 35% with version control and audit trails.
• Provided first-level technical support for Windows workstations, printers, Office 365 applications, and network connectivity issues, supporting 150+ users.
Projects
• AI-Driven Security Policy Copilot (RAG-Based Architecture) Jan/2026 Built a cybersecurity policy chatbot using Azure AI Foundry, Azure OpenAI and SharePoint. Structured and tagged policy data for retrieval-augmented generation (RAG), designed conversational and decision-tree guidance, and conducted prompt optimization and testing to deliver accurate, policy-aligned security support.
• Custom Network Threat Detection Engine (Python/Scapy) Dec/2025 Engineered a lightweight intrusion detection prototype capable of detecting SYN floods, ARP spoofing, and DNS manipulation. Simulated adversarial traffic using hping3 and tcpdump EDUCATION
UNIVERSITY OF MARYLAND College Park, MD
Master of Engineering in Cyber Security (PMCY) Sept/2025 – May/2027
• Courses (first year): Networks & Protocols, Hacking of C & Unix Binaries, Security Tools for Information Security, Cloud Security, Network Security, Penetration Testing UNIVERSITY OF ZIMBABWE Harare, ZW
BSc Honours Degree in Computer Science (Upper 2nd Class) Aug/2017 – Dec/2021 CERTIFICATIONS AND BADGES
CompTIA Security+ (in progress), Cisco Cyber Ops Associate, Cisco Network Security, Intro to Splunk, Network Traffic Analysis (LinkedIn), Threat Hunting and Hunting with Elastic (LinkedIn), Security Monitoring and SIEM Fundamentals
(LinkedIn)