M.Eng in Cybersecurity from the University of Maryland (3.9 GPA), with hands-on experience supporting enterprise infrastructure for 120+ users on Cisco, Palo Alto, and Meraki equipment — plus a fully independent, real-hardware lab project built from the ground up. CCNA in progress.
Focus: Networks & Protocols, Network Security, Security Tools & Information Assurance, Penetration Testing
Focus: Cloud Security, Cloud Computing, Linux System Administration, Virtualization & Containerization
Certified
Certified
Certified
In progress
A multi-factor authentication security device, developed and published during network research work at Geethanjali College of Engineering.
Two flagship builds below, both on real hardware end to end. Additional applied work and what's next follow after.
A segmented enterprise network for a fictional healthcare organization — designed, built, and hardened end-to-end on real, physical Fortinet and Cisco hardware. Full command reference and troubleshooting log in the GitHub repo.
Every device, model number, and technology actually used in the build — not a simulated topology.
| Device | Model | Role |
|---|---|---|
| Firewall / Core Router | FortiGate 60E (FortiOS 7.4.11) | Perimeter firewall, inter-VLAN policy, SSL-VPN, RIP |
| Core Switch | Cisco Catalyst 3560E-24PD-S (PoE) | VLAN trunking, 4-zone segmentation |
| Branch Router | Cisco 1921 ISR (IOS 15.x) | Site-to-site routing, Branch LAN gateway |
| HQ Access Point | Cisco AIR-CAP3702I-A-K9 (Autonomous) | Dual-SSID wireless — Trusted / Guest |
| Spare AP | Cisco AIR-LAP1142N-A-K9 | Backup / spare unit |
| Branch AP (attempted) | Cisco AIR-CAP3502I-A-K9 | Diagnosed as Lightweight/CAPWAP firmware, unrecoverable secondhand credentials — documented, substituted |
| Branch WiFi (deployed) | TP-Link Archer AX21 | Practical substitute for the Branch AP, per above |
| Homelab Host | Lenovo T14 | Runs Proxmox VE — all monitoring & automation containers |
| Layer | Technology |
|---|---|
| Virtualization | Proxmox VE, Debian 12 LXC containers |
| Metrics collection | Prometheus v2.53.0 |
| Dashboards | Grafana |
| SNMP polling | SNMP Exporter v0.26.0, SNMPv2c |
| Host metrics | Node Exporter v1.8.2 |
| Public site delivery | Cloudflare Tunnel (cloudflared), nginx |
| Dynamic DNS | DuckDNS |
| Remote access | FortiGate SSL-VPN, FortiClient |
| Automation | Bash, cron, SSH (Ed25519 / RSA-2048) |
| Routing protocol | RIPv2 |
A passive 802.11 site survey of the Plainsboro Public Library — a three-storey, 46,500 sq ft public building — conducted with permission. Full RF analysis extracted directly from the survey database rather than read off a heatmap. Full write-up, raw data, and findings in the GitHub repo.
Every measured location met the −67 dBm design threshold — no dead zones anywhere. The real problem was eight access points competing with each other for airtime on an unbalanced channel plan.
| Metric | Result | |
|---|---|---|
| Measurement points | 67 across two floors | |
| Network observations | 1,523 individual beacon readings | |
| Access points identified | 8, grouped from 94 distinct BSSIDs by radio prefix | |
| Coverage vs. −67 dBm threshold | 100% of points, both floors | |
| Instrument | Moto G Stylus 5G (2024) — Wi-Fi 5, 1×1, dual-band |
| Finding | Severity | Summary |
|---|---|---|
| F-01 | High | 5 of 8 APs share 2.4 GHz channel 6 — co-channel contention |
| F-02 | High | 6 of 8 radios crowded into 5 GHz UNII-3 at mismatched widths |
| F-03 | Medium | AP density exceeds coverage requirement — confirmed by client link rate at 1/5 of device ceiling |
| F-05 | Medium | Coverage propagates freely between floors through the central atrium |
Applied infrastructure and cloud work from the UMD assistantship, plus what's next in the lab.
Designed and deployed network infrastructure using Cisco routers/switches, Palo Alto firewalls, and Meraki access points for 120+ users. Implemented segmentation and security zones; optimized performance with OSPF routing and QoS policies; used Wireshark to identify and resolve latency issues.
Applied AWS core services (EC2, VPC, S3, IAM) through coursework tied to the Graduate Certificate in Cloud Engineering, covering cloud networking, security, and Linux-based virtualization.
Python + Netmiko/NAPALM — multi-vendor config auditing and compliance checking.
Suricata on a mirrored switch port — real detection and alert triage practice.
Open to Network Engineer, Network Analyst, Network Architect, and Wireless Engineer roles.