Post Job Free
Sign in

Cybersecurity Analyst & Security Engineering Candidate

Location:
Pittsburgh, PA
Posted:
October 04, 2026

Contact this candidate

Resume:

NITHIN PASILETI

+1-984-***-**** **************@*****.*** Pittsburgh, PA LinkedIn GitHub Portfolio PROFESSIONAL SUMMARY

Cybersecurity analyst and security engineering candidate with hands-on experience in Windows penetration testing, endpoint hardening, EDR validation, vulnerability remediation, and NIST SP 800-53-aligned compliance; holds an MS in Cybersecurity Management. Tested privilege-escalation paths, triaged 12+ critical vulnerabilities, authored six evidence-based reports, and coordinated verified patch and firewall remediation. Built a Python-based intrusion detection model achieving 94%+ accuracy and reduced false positives by 30%, supporting stronger threat detection and SIEM triage. PROFESSIONAL EXPERIENCE

Verzeo August 2022 - October 2022

Cybersecurity Analyst Intern Hyderabad, India

• Analyzed TCP/IP traffic and attack surfaces across 3 environments with Nmap and Burp Suite, triaging 12+ critical vulnerabilities through SOC monitoring, threat analysis, incident response, and containment.

• Conducted authorized Windows penetration tests using Metasploit and exploitation frameworks, investigating 5+ privilege-escalation paths and documenting CVSS-ranked remediation for POA&M updates, OS hardening, EDR validation, and risk management.

• Authored 6 evidence-based security reports detailing findings, technical specifications, and prioritized mitigations; established NIST SP 800-53-aligned vulnerability management baselines supporting information security compliance, audits, and control reviews.

• Executed organization-wide phishing simulations using SET and SocialPhish, identifying employee awareness gaps and delivering targeted training, briefings, escalation procedures, and incident-response exercises to strengthen cybersecurity behaviors.

• Documented network topology, DNS dependencies, and asset inventories across client environments, supporting vulnerability tracking, risk assessment, ITGRC, PCI-DSS, SOX, ISO, and CCPA compliance reporting.

• Coordinated Jira remediation tickets with internal IT staff, validating patch and firewall-rule changes through security-control testing and closing requests to strengthen evidence tracking, audit readiness, and stakeholder coordination. PROJECTS & OUTSIDE EXPERIENCE

WordPress Plugin Vulnerability Scanner April 2024 - Present

• Developed a Python/Django SaaS cybersecurity scanner that assessed 50+ WordPress plugins as web applications, integrated REST APIs and web services, and generated JSON/XML vulnerability evidence for e-commerce risk assessments.

• Automated vulnerability-management workflows across GRC, SOAR, firewall rules, patch sequencing, plugin allowlists, access management, CI/CD, and ticketing, reducing estimated attack surface by 60% while supporting DevOps operations.

• Validated AWS configurations through Linux operating-system audits, RMF-style authorization evidence, STIG-equivalent checks, and Terraform-aligned configuration management; delivered patch plans and repeatable reports supporting federal frameworks, eMASS documentation, continuous monitoring, and SOC 2. ML-Based Network Intrusion Detection System October 2023 - Present

• Monitored Kibana and Splunk dashboards across Linux/UNIX systems, analyzed TCP/IP trends, triaged and escalated threats, and performed Tier 1 troubleshooting against documented detection KPIs.

• Engineered Python and Scikit-learn models to classify anomalous network traffic across five labeled attack categories, achieving 94%+ accuracy and strengthening practical threat identification.

• Applied Six Sigma and data analytics to optimize detection features and alert logic, reducing false positives by 30% while improving SIEM triage, severity assessment, alert-health reviews, and risk measurement.

• Correlated network traffic and database activity using SQL and cryptography concepts to validate model outputs, guide EDR-informed threat hunting, and report actionable threat and vulnerability findings. EDUCATION

Anderson University August 2026

Master of Science (MS), Cybersecurity Management GPA: 3.8 Institute of Aeronautical Engineering May 2024

Bachelor of Science (BS), Cybersecurity GPA: 3.4

SKILLS

Skills: RMF, POA&M development, STIG checklist review, Vulnerability assessment, CVSS scoring, Patch management, Python, Scikit-learn, Django, SQL, Bash, TCP/IP, OSI model, Network traffic analysis, Packet inspection, Wireshark, Nmap, Metasploit, Burp Suite, BloodHound, Mimikatz, Kali Linux, MITRE ATT&CK, OWASP Top 10, Incident response playbooks, CVE analysis, Penetration testing, Security automation, Machine learning, Feature engineering, Model tuning, Network intrusion detection, Phishing simulations, Social engineering testing, Attack-surface analysis, Privilege escalation testing, Security reporting, Risk-ranked vulnerability reporting, Remediation planning, Firewall rule integration, Patch sequencing, Plugin allowlist policies, Network topology documentation, Asset inventory management, Compliance reporting, Security analysis, Incident response planning, Digital forensics, Risk management, Vulnerability tracking, Security training, Technical writing, Cross-functional collaboration, PowerShell, Java, C++, Ruby, Lambda, DynamoDB, Linux, SIEM, Azure, macOS, EDR, JavaScript, PHP, SOC 2, HIPAA, ServiceNow, CCPA, scripting language, secret clearance, Top Secret clearance, NIST SP 800-53 / 800-171, ISO 27001, EDR/XDR, PMP, COTR, COR, USAJobs, GSA, operating systems, firmware, forensics, customer service, ServSafe, TIPS, food handler permit, alcohol certification, CPR, security controls, information systems, Microsoft Excel, automation, API, information security, GCP, Google Cloud Platform, ISACA, Power BI, Tableau, CompTIA Security+, CompTIA CySA+, OAuth, malware analysis, Agile, Jira, Confluence, Intrusion Detection and Prevention Systems, Service Level Agreements, Linux/UNIX, AJAX, SANS, Active Directory, CEH, Nessus, Qualys, Rapid7, SIEMs, Perl, ERP system, business strategy, Lockheed Martin’s Cyber Kill Chain, Security+, Network+, CISSP, CISM, CFE, Risk Management Framework (RMF), DoD Secret security clearance, DoD cybersecurity experience, CompTIA Security+ CE, content development, threat and vulnerability management, vulnerability scanning, NIST 800-series, FISMA, OMB guidance, U.S. citizenship, SSPs, Top Secret/SCI, DoD 8570.11- IAT Level II, ICD 503, RMF/ATO, DISA STIGs, Tenable/Nessus, DoD, ACAS, Kubernetes, Grafana, Datadog, Nginx, OpenStack, Go, cloud security, CLI, reverse engineering, Swift, CAD, offensive security, identity services, Golang, SCI, TS/SCI, DoD 8570.01-M, TS/SCI with a Polygraph, ISSE, COTS, Visio, PowerPoint, Secret security clearance, proxy, Splunk SIEM platform, US Citizen, Excel, DCSA, CI Cyber, SDR, SCA, GitHub, SAST, ASPM, container security, GitLab, Azure DevOps, threat modeling, DAST, GitHub Actions, Jenkins, NIST 800, DFARS, Zero-Trust, IoT, CMMC, Zero Trust, identity and access management, SSO, OpenID Connect, RBAC, MFA, scripting, Google Cloud, Git, continuous integration, version control, NDA, DoD 8140 certification, NIST 800-53, Trellix ESS, DISA STIG, compliance reports, data reporting, founder, Microsoft Intune, Jamf Pro, Microsoft Endpoint Configuration Manager, endpoint hardening, Microsoft Defender for Endpoint, Microsoft security technologies, CIS Benchmarks

CERTIFICATIONS

Practical Web Application Security and Testing — TCM Security (Sep 2026) Practical Ethical Hacking — TCM Security (Jul 2025) Fortinet Certified Associate Cybersecurity (FCA) — Fortinet (Jun 2025) Fortinet Certified Fundamentals Cybersecurity (FCF) — Fortinet (Jun 2025) Microsoft Security, Compliance & Identity Fundamentals (SC-900) — Microsoft (May 2025) Ethical Hacker — Cisco Networking Academy (Apr 2025) Incident Response & Digital Forensics — IBM (Dec 2022)



Contact this candidate