About Me

Hi I am Ayush Bajirao :wave:, a cybersecurity professional with 4+ years spanning SOC operations, incident response, vulnerability management, application security, and DevSecOps/cloud infrastructure automation. I’ve led incident response for a $30K BEC fraud attempt with zero financial loss, driven an 85% enterprise vulnerability backlog reduction, and deployed org-wide phishing-resistant YubiKey MFA. I hold CKA/CKS Kubernetes certifications and run a production-grade GitOps security platform (homelab docs) alongside a self-hosted SOC toolset, both built from scratch. Background also includes 100+ penetration tests across web, mobile, and API applications (see my CTF writeups), and a Master of Cybersecurity from Simon Fraser University. When I’m not securing systems, I like to jam on my guitar 🎸, binge anime 🍿 and read books 📚.

Programming & Scripting

Python

85%

Bash

75%

Golang

55%

SQL

70%

SIEM & Threat Detection

Microsoft Sentinel

85%

Microsoft Defender XDR

85%

Darktrace

70%

Splunk

65%

Wazuh

70%

Identity & Compliance

Microsoft Entra ID / Conditional Access

85%

FIDO2 / YubiKey MFA

80%

NIST CSF / ISO 27001 / SOC 2

70%

CIS Benchmarks

70%

Cloud & Infrastructure

AWS

80%

Kubernetes (CKA/CKS)

75%

Terraform / OpenTofu

70%

Azure

60%

Red Team / Pentesting

Burp Suite

75%

Metasploit

65%

NMAP

70%

Wireshark

70%

SQLMap

60%

Information Security Analyst, Concert Properties

December 2024 — Present

• Led incident response for a $30K vendor Business Email Compromise (BEC) fraud attempt, coordinating with the bank to fully reverse the transfer with zero financial loss.
• Own the organization's vulnerability management program end-to-end, reducing open vulnerabilities from 20,000+ to ~3,000 (~85%) over one year via Microsoft Defender XDR detection and Intune-driven remediation.
• Rebuilt a broken vulnerability reporting pipeline on Microsoft Fabric (bronze/silver/gold architecture), automating weekly executive reporting and SLA tracking.
• Led the migration from Proofpoint to Abnormal AI, cutting manual email security escalations from ~3/week to zero.
• Deployed YubiKey-based FIDO2 hardware MFA across the IT department and co-led a Conditional Access redesign supporting a Zscaler Internet Access rollout.

Cyber Security Architecture Co-op, BlackBerry Limited

September 2023 — December 2023

• Automated AWS infrastructure deployment with Terraform and architected a cross-account, multi-region highly available monitoring tool.
• Performed threat modeling and Security Risk Analysis (SRA) for new IT tools, informing risk mitigation and application security architecture decisions.
• Designed DLP rules in Digital Guardian and implemented Static Application Security Testing (SAST) in CI pipelines via GitHub Actions and SonarQube.
• Configured AWS Security Hub, AWS Inspector, and Wazuh XDR agents for proactive threat detection across EC2 instances.
• Managed Palo Alto Firewall rules integrated with Splunk SIEM for monitoring and alerting.

Security Analyst, Securitybulls Intelligence India Pvt. Ltd.

November 2020 — September 2021

• Discovered vulnerabilities across 100+ penetration tests of web, mobile (Android), and API applications, based on OWASP Top 10 and OWASP API Security Top 10.
• Led cross-functional remediation efforts, contributing to a 70% decrease in customer data breaches.
• Verified remediation of XSS, SQLi, CSRF, and SSRF vulnerabilities through source code review.
• Supervised a security audit project, leading a team of three interns through planning, execution, and reporting.

Graduate Teaching Assistant, Advanced Networking & Cyber Security, Simon Fraser University

September 2022 — August 2024

• Guided students through complex topics including remote procedure calls (RPC) and network security fundamentals.
• Led discussions on TCP, UDP, IP forwarding/routing, and advanced topics including software-defined networking (SDN).
• Clarified application-layer protocol principles (HTTP, DNS) and their hardening via web application firewalls, CDNs, and P2P systems.

Education

Master of Cybersecurity

Simon Fraser University, Burnaby, Canada

September 2022 – April 2024

B.Tech, Computer Science (Cyber Security)

Indian Institute of Information Technology, Sri City, India

July 2017 – May 2021

Certifications

Certified Kubernetes Security Specialist (CKS) Certified Kubernetes Administrator (CKA) Microsoft Certified: Azure Administrator Associate Microsoft Certified: Security, Compliance, and Identity Fundamentals Microsoft Certified: Azure Fundamentals CompTIA Security+ (SY0-701)

Achievements

3rd Place, CyberSci CTF 2022 Regionals, Vancouver