Available for cybersecurity opportunities

Turning security signals into stronger systems.

I’m Henil Gandhi, a cybersecurity engineer focused on practical defense: security operations, vulnerability management, and risk-aware security programs.

4
Professional certifications
6
Industry recognitions
SOC + GRC
Hands-on security focus
Portrait of Henil Gandhi
NOW FOCUSED ONSecurity operationsDetection · Response · Resilience
RECOGNIZED BYMicrosoft · Apple

Built around real-world security practice

SECURITY OPERATIONSVULNERABILITY MANAGEMENTGRCSECURITY RESEARCH

01 / About

Strategy-minded,
hands-on by nature.

I’m a Master’s graduate in Cyber Forensics & Security from the Illinois Institute of Technology. I help organizations improve their security posture through security operations, governance, risk and compliance, and vulnerability management.

My work combines a foundation in vulnerability assessment and penetration testing with an interest in practical, measurable defense—from alert triage and incident response to risk assessment, control validation, and remediation.

Let’s work together
01

Security operations

Detection, triage, threat hunting, and incident response.

02

Risk & compliance

Security controls aligned to NIST, ISO 27001, and business risk.

03

Vulnerability management

Prioritization, validation, remediation, and continuous improvement.

02 / Expertise

My security arsenal.

Every tool and framework below is carried forward from the live portfolio, organized into a stronger visual system.

01 / DEFEND

Security Operations

  • SOC Monitoring
  • SIEM
  • Endpoint Detection & Response (EDR)
  • Threat Hunting
  • Incident Response
  • Alert Triage
  • Log Analysis
  • Detection Engineering
  • MITRE ATT&CK
  • IOC Analysis
02 / GOVERN

Governance, Risk & Compliance

  • NIST RMF
  • NIST SP 800-53 Rev. 5
  • NIST CSF
  • ISO 27001
  • PCI DSS
  • HIPAA
  • SOX
  • Risk Assessment
  • Risk Management
  • Control Gap Analysis
  • Security Control Validation
  • Compliance Documentation
  • Audit Readiness
  • Continuous Monitoring
03 / PRIORITIZE

Vulnerability Management

  • Vulnerability Assessment
  • Vulnerability Scanning
  • CVE Prioritization
  • Patch Validation
  • Remediation Tracking
  • OWASP Top 10
  • Penetration Testing
04 / CONTROL

Identity & Access Management

  • Access Reviews
  • Least Privilege
  • Identity Governance
  • Privileged Access Management
</>
05 / AUTOMATE

Programming & Automation

  • Python
  • Bash
  • KQL
  • C/C++
  • Security Automation
  • SOAR Concepts
06 / INVESTIGATE

Security Tools

  • Splunk
  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • IBM QRadar
  • Wireshark
  • Burp Suite
  • Nessus
  • Nmap
  • Power BI
  • Jira
  • ServiceNow
07 / BUILD

Cloud & Systems

  • AWS
  • Microsoft Azure
  • Google Cloud Platform (GCP)
  • Windows
  • Linux
  • TCP/IP
  • DNS
  • HTTP
  • SMB
  • SSH

03 / Selected work

Security work with real-world context.

Threat Remediation and Risk Tracking Lab dashboard

GRC / RISK MANAGEMENT

Threat Remediation & Risk Tracking Lab

Simulated enterprise threat-remediation workflows using findings from vulnerability assessments, penetration testing, and security reviews.

  • Developed Power BI remediation tracking dashboards and risk templates
  • Tracked milestones, compensating controls, exception requests, and risk-acceptance decisions
  • Created remediation playbooks and workflow documentation aligned with NIST CSF and NIST SP 800-53
Power BINIST CSFNIST SP 800-53
Home SOC Lab dashboard

SOC LAB / AUTOMATION

Home SOC Lab

Designed a production-grade SOC and EDR lab with centralized detection, automated response, and incident case management.

  • Centralized endpoint telemetry and monitoring
  • Automated alert enrichment and response workflows
Wazuh SIEMShuffle SOARIRIS
Vulnerability Management and Risk Prioritization Lab dashboard

SECURITY PROGRAM

Vulnerability Management & Risk Prioritization Lab

Enterprise-style vulnerability management across Windows, Linux, and web applications.

  • Prioritized CVEs and risk-scored findings
  • Validated patches through rescanning and tracking
NessusQualysBurp Suite
Phishing Detection and Email Security Analysis Lab dashboard

INVESTIGATION LAB

Phishing Detection & Email Security Analysis

Investigation workflows for suspicious emails, spoofed domains, malicious URLs, and attachments.

  • Analyzed headers, domains, URLs, and file hashes
  • Created repeatable triage and escalation playbooks
Defender XDRThreat intelligence
CyberHunt penetration testing toolkit

OPEN SOURCE

CyberHunt

A penetration-testing toolkit for streamlined reconnaissance, vulnerability assessment, and security testing workflows.

  • Automated repeatable reconnaissance tasks
  • Supported practical vulnerability discovery
PentestingSecurity Tools
Web Application Security in Web 2.0 research paper

RESEARCH PAPER

Web Application Security in Web 2.0

Research examining common web application weaknesses and practical security best practices.

  • Mapped common risks to defensive practices
  • Presented accessible web-security guidance
Web SecurityOWASP

04 / Credentials

Built on continuous learning.

Microsoft certification badge

Microsoft

SC-200

Jan 2026
CompTIA Security Plus badge

CompTIA

Security+

Aug 2025
SecOps certification badge

SecOps Group

Certified AppSec Practitioner

Jan 2024
IBM Cyber Security Analyst badge

IBM

Cyber Security Analyst

Mar 2022

05 / Recognition

Responsible research, recognized impact.

Honored for responsibly disclosing security vulnerabilities and contributing to a safer digital ecosystem.

Lenovo certificate of appreciation
Oct 2022

Certificate of Appreciation — Lenovo

LG letter of appreciation
Oct 2022

Letter of Appreciation — LG

06 / Writing

Notes from the security field.

Practical observations, career reflections, and hands-on cybersecurity work.

Cybersecurity internship blog post cover

CAREER / MEDIUM

Landing My First Cybersecurity Internship in USA

From rejections to results: the journey to landing a first cybersecurity internship in the United States.

Read on Medium
Home SOC and EDR Automation Lab blog post cover

TECHNICAL / MEDIUM

Home SOC & EDR Automation Lab

Designing a real-world SOC and EDR automation lab with Wazuh, Shuffle SOAR, and IRIS.

Read on Medium

07 / Contact

Let’s make security more resilient.

I’m open to cybersecurity opportunities and conversations about security operations, vulnerability management, GRC, and applied security research.