Om Parag Jadhav
I defend organizations by thinking like an attacker and engineering like a defender.
Cybersecurity professional focused on enterprise security, endpoint defense, cloud security, SOC operations, vulnerability management, penetration testing, and AI-enabled security workflows.
OPERATOR PROFILE
Cybersecurity analyst focused on enterprise security operations — triaging SOC alerts, defending endpoints, hardening Microsoft 365 and Azure environments, and supporting vulnerability management and penetration testing programs.
I work the full lifecycle: investigate signals across SIEM, EDR, identity, and email; partner with engineering to remediate; and translate technical findings into governance, policy, and executive-ready reporting. I also explore AI-assisted workflows to improve triage, reporting, and analyst efficiency without compromising controls.
- SOC operations & incident response
- Endpoint defense (Carbon Black · CrowdStrike · Defender)
- Microsoft 365 & Azure security
- Vulnerability management
- Penetration testing support
- Governance, policy & audit
- AI-enabled security workflows
/var/log/career.log
- INC-2025-137ACTIVE· 10/2023 — Present· NYC
Cybersecurity Analyst @ Semperon Systems
- ›Triage and investigate SOC alerts across SIEM, EDR, email security, identity, and endpoint platforms.
- ›Support enterprise endpoint security operations using Carbon Black, CrowdStrike, and Microsoft Defender for Endpoint.
- ›Administer and secure Microsoft 365 and Azure environments, including Entra ID, Conditional Access, email security, and security policy enforcement.
- ›Conduct phishing investigations, awareness campaigns, vulnerability assessments, and penetration testing support.
- ›Build executive-facing security dashboards and reports that translate technical findings into business risk.
- ›Support policy, procedure, compliance questionnaire, and security audit activities for client environments.
- ›Explore AI-assisted workflows to improve security operations, reporting, and alert triage efficiency.
- INC-2024-274RESOLVED· 06/2023 — 09/2023· NYC
Independent Security Consultant @ Com-Sec
- ›Led Virtual CISO engagements, cutting client cybersecurity incidents by 45%; supported compliance readiness across SOC 2, HITRUST, ISO 27001, HIPAA, and PCI-DSS aligned controls.
- ›Guided clients through SOC 2 and HITRUST audits to successful certification.
- ›Designed secure AWS architectures with VPC peering, PrivateLink, and Transit Gateway.
- ›Automated PCI-DSS, ISO 27001, and HIPAA controls using AWS Config Rules and Lambda.
- ›Resolved 75+ findings through pentests on AWS workloads, improving resilience by 30%.
- INC-2023-411RESOLVED· 05/2022 — 12/2022· NYC
Security Engineer Intern @ Lark Health
- ›Hardened VPCs, security groups, Route 53, S3, and databases across AWS workloads.
- ›Automated vulnerability management via AWS Inspector piped into the SIEM for centralized response.
- ›Configured multi-region CloudTrail logging shipped to Splunk for real-time monitoring.
- ›Built threat model and launched MDM for Windows fleet; supported HITRUST work on Drata.
- ›Revamped OpenBugBounty program, driving a 50% increase in bug submissions.
- INC-2022-548RESOLVED· 01/2022 — 05/2023· New York
MTA Program Assistant @ NYU Tandon Online
- ›Supported four prerequisite courses — Linux, Information Security, Python Basics, OT Networks.
- ›Moderated discussions, graded assignments, and answered learner questions on course content.
- INC-2021-685RESOLVED· 06/2019 — 05/2021· Mumbai
Consultant — Cyber Risk @ Deloitte
- ›Assessed 10+ web and mobile apps for financial sector clients, mitigating critical vulnerabilities.
- ›QA'd penetration testing deliverables and evaluated control maturity across global teams.
- ›Performed black-box and grey-box tests against CIS, ISO 27001, PCI-DSS, HIPAA, SOX, NIST, GDPR, MITRE ATT&CK.
CORE SECURITY WORK
SOC & Incident Response
Endpoint Security
Cloud & M365 Security
Vulnerability Management
Pentesting & Offensive Security
Security Awareness
Compliance & Governance
AI in Security
CASE FILES // FIELD REPORTS
Phishing Incident Investigation
Investigated a spoofed vendor email targeting finance — validated infrastructure, reconstructed timeline, and tightened email and payment controls.
Endpoint Detection & Response Triage
Triaged EDR alerts across Carbon Black, CrowdStrike, and Defender — correlated process trees and escalated with containment guidance.
Microsoft 365 Security Hardening
Hardened Microsoft 365 — Conditional Access, mailbox security, external sharing review, anti-phishing, and risky sign-in monitoring.
Executive Security Dashboard
Built leadership-friendly dashboards that translate alert trends, vulnerabilities, and phishing metrics into business risk views.
Vulnerability Management Program
Stood up scan cadence, risk-based prioritization, and remediation SLAs across hybrid infrastructure.
SECURITY STACK
SIEM
- AlienVault
- Stellar Cyber
EDR / XDR
- Carbon Black
- CrowdStrike
- Microsoft Defender for Endpoint
Email Security
- Barracuda
- Mimecast
- SPF
- DKIM
- DMARC
Cloud / Identity
- Azure
- Entra ID
- M365
- Conditional Access
- Intune
Vulnerability & Pentest
- Nessus
- Nmap
- Burp Suite
- OWASP ZAP
- Metasploit
Scripting & Automation
- PowerShell
- Python
- Bash
Governance
- Policies
- Procedures
- Questionnaires
- Compliance audits
CREDENTIALS VAULT
OPERATOR BACKGROUND
Doctor of Business Administration — IT Management
Westcliff University
Irvine, CA, US
MS Cybersecurity
New York University
New York, NY, US
BTech Computer Engineering
Veermata Jijabai Technological Institute
Mumbai, MH, India
CONTACT HANDSHAKE
Preferred contact: email or LinkedIn. Open to security engineering, cloud security, and AI security operations opportunities.
[email protected]SEND ▸LinkedInOAUTH