Aditya Jain
Cybersecurity Engineer specializing in NGFW Architecture (Check Point, Fortinet) and Vulnerability Assessment & Penetration Testing with 3.5+ years of enterprise experience across government infrastructure (NIC/MeitY) and Critical National Infrastructure SOC operations (DAE/NFC). CNI-vetted.
Professional Summary
Cybersecurity Engineer & Firewall/VAPT Specialist with 3.5+ years of hands-on enterprise experiencein Next-Generation Firewall architecture, Web & Infrastructure Penetration Testing, and SIEM/EDR threat hunting. Currently managing large-scale cybersecurity operations at Ebix Technologies contracted directly to the National Informatics Centre (NIC, MeitY). Vetted for Critical National Infrastructure access (DAE/NFC).
Specializes in Check Point NGFW and Fortinet FortiGate perimeter security design (default-deny policies, NAT/ACL auditing, IPsec VPN tunnels) and conducting periodic VAPT assessments against government web portals, identifying and remediating OWASP Top 10 vulnerabilities with coordinated PoC exploit validation.
Equally adept at defensive SIEM/EDR engineering (SentinelOne, Wazuh, Blu Sapphire), DFIR triage (FTK Imager, Magnet RAM Capture, Disk2vhd), and physical Data Center Infrastructure Management (DCIM) including PACs, server racks, and VESDA fire safety systems.
Proven ability to automate regulatory auditing through custom PowerShell and Python frameworks, reducing overall audit cycles by 60% and successfully responding to national CERT-In security advisories.
🎯Open to Firewall Engineering, VAPT/Pentesting, SOC Leadership, and Purple Team roles — PAN India relocation and international H-1B sponsorship opportunities.
{
"name": "Aditya Jain",
"title": "Cybersecurity Engineer — Firewall & VAPT",
"exp": "3.5+ Years Enterprise SecOps & VAPT",
"focus": "NGFW • Web/Infra VAPT • SIEM/EDR • DFIR",
"clearance": "CNI Vetted (NIC/MeitY & DAE/NFC)",
"email": "adityasec32@gmail.com",
"contact": "+91 740 058 8896",
"studying": "MBA in Cybersecurity",
"pursuing": ["eJPT", "CEH v13", "CISSP"]
}Core Competencies
NGFW & Firewall Engineering
Check Point NGFW, Fortinet FortiGate (FCAC certified), Sophos, Cisco AnyConnect, Default-Deny rule design, NAT/PAT configuration, ACL auditing, IPsec/SSL VPN tunnels, TACACS+/RADIUS AAA, perimeter traffic inspection.
VAPT & Offensive Security
Web Application VAPT (OWASP Top 10), Infrastructure Pentesting, Active Directory Security Assessments (Kerberoasting, Pass-the-Hash, DCSync, BloodHound, Impacket, Mimikatz), Burp Suite Pro, Metasploit, Nmap, PoC Exploit Development.
SIEM/EDR, DFIR & SOC Operations
Wazuh SIEM, Blu Sapphire, SentinelOne EDR, Trend Micro Deep Security, Kaspersky EDR, Splunk (familiar), Microsoft Sentinel, Snort IDS, 24x7 CNI SOC. DFIR: FTK Imager, Magnet RAM Capture, Disk2vhd, Autopsy, CERT-In IR.
Infrastructure, Automation & Compliance
KACE UEM (750+ endpoints), PXE Boot imaging, State Data Centre DCIM (PACs, racks, patch panels, VESDA fire safety, rodent repellers), Python/PowerShell/CMD/Bash automation (120+ checks), WinSCP, Git, Ollama RAG LLM chatbots, CERT-In/CDAC/NIST CSF compliance.
Professional Experience
Security Administrator
- Firewall Architecture & Perimeter Hardening: Designed and enforced default-deny security policies on Check Point NGFW across Bihar SDC and NKN offices; configured NAT/PAT rules, audited ACLs, and managed IPsec VPN tunnels for secure inter-district government communications.
- Web Application & Infrastructure VAPT: Conducted 15+ vulnerability assessments and penetration tests against government-facing web portals; identified and remediated 50+ critical/high OWASP Top 10 vulnerabilities (Open Redirect, XSS, SQLi); validated closures via PoC exploits coordinated with NIC-CERT.
- Enterprise EDR Deployment: Architected and managed SentinelOne and Trend Micro Deep Security across 750+ regional offices, tuning behavioral detection policies to neutralize emerging ransomware and fileless attack vectors.
- Enterprise Intranet & AI Portal (10.133.22.8): Independently designed and deployed an AI-assisted organization-wide NOC portal (http://10.133.22.8), integrating an offline RAG LLM Chatbot (Ollama), custom tool hyperlink directory, district router telemetry, and automated outage alerts.
- DFIR & CERT-In Incident Response: Primary CERT-In responder; performed live memory triage (Magnet RAM Capture, FTK Imager, Disk2vhd), host forensics, and authored PoC exploits to validate vulnerability closures. Achieved 100% closure rate on CERT-In advisories within SLA.
- Compliance Automation: Built PowerShell and Python frameworks automating 120+ CDAC/CERT-In regulatory checks across 750+ endpoints via KACE UEM — cutting audit effort by 60%.
- Data Center Infrastructure Management (DCIM): Oversaw State Data Centre (SDC) physical security and environmental controls including Precision Air Conditioning (PACs), server rack optimization, patch panel routing, ultrasonic rodent repeller systems, and VESDA fire safety compliance.
Self-Directed Security Research & MBA Prep
- Enrolled in MBA in Cybersecurity (Chitkara University) while completing intensive self-directed offensive security lab practice on Hack The Box (Active Directory exploitation, Pro Hacker rank) and VulnLab (multi-forest AD pivots, Domain Controller compromise).
- Deepened expertise in Active Directory attack chains (Kerberoasting, Pass-the-Hash, DCSync, Unconstrained Delegation) and VAPT methodologies in preparation for eJPT certification.
SOC Analyst — Threat Hunter
- CNI SOC Operations: SME for threat hunting and incident response in a 24x7 nuclear-sector SOC (Department of Atomic Energy — DOE-equivalent sensitivity), monitoring enterprise telemetry via Blu Sapphire SIEM.
- Sandbox & Malware Analysis: Reproduced adversary exploit signatures in isolated lab environments; performed behavioral malware analysis with Kaspersky EDR to reverse-engineer TTPs.
- Detection Engineering: Tuned SIEM correlation rules and EDR behavioral rules, yielding a 35% improvement in true-positive detection rates while eliminating alert fatigue.
SOC Analyst — IDS & Signature Development
- IDS Engineering: Authored and deployed custom Snort and Wazuh IDS signatures to capture novel attack patterns in a 24x7 SOC environment.
- Threat Intelligence: Automated AbuseIPDB threat feed ingestion for real-time perimeter firewall IP blocklisting.
- Telemetry Analysis: Analyzed bandwidth and network traffic logs to identify routing loops and anomalies.
Technical Support Executive (Microsoft Account)
- Delivered Tier-2 Microsoft enterprise support; maintained SLA compliance and documented internal security knowledge bases.
Key Security Projects
CDAC/CERT-In Compliance Engine
Engineered a PowerShell & Python framework executing 120+ automated system configuration checks mapped to NIST standards across 750+ government nodes via KACE UEM.
Enterprise AI & NOC Portal (10.133.22.8)
Sole architect of a full-stack intranet portal deployed at 10.133.22.8 for the organization. Features an integrated AI-assisted RAG Cybersecurity Chatbot (Ollama LLM), custom tool hyperlink directory, 38-district live router telemetry, and automated outage alerting.
Real-Time Network Alert Dashboard (10.133.22.8/alert/)
Solely engineered real-time ping monitoring and packet loss analysis dashboard for enterprise core routing units. Integrates custom outage alerting, noise filters, and live telemetry log feeds.
Cyber Free Rice Initiative
Interactive education platform featuring a stunning macOS-inspired UI. User quiz scores are simulated to feed directly into food charity initiatives (FreeRice concept).
JumpStreet Trading Infrastructure
Engineered low-latency algorithmic trading infrastructure providing sub-millisecond cloud VMs and high-availability 5G redundancy nodes for quantitative traders.
Certifications & Training
Completed Credentials
Targeted Roadmap
Education
Master of Business Administration (MBA) in Cybersecurity
Chitkara University, India
B.Tech in Computer Science & Engineering
Manipal University Jaipur, India
Diploma in Computer Science & Engineering
Hindu College of Engineering, India
Establish Connection
Get in Touch
Open to Firewall Engineering, VAPT/Pentesting, SOC Leadership, and Purple Team roles — PAN India relocation and international opportunities.
Secure Communications
To securely share logs, endpoints, or project briefs, import my PGP public key directly: