SECURITY PROFILE / 2026JUNIOR CYBERSECURITY ANALYST

Het Patel — Junior Cybersecurity Analyst, Cybersecurity Intern — VAPT, Risk & Compliance at Info eShield Cyber Solutions

CYBERSECURITY INTERN — VAPT, RISK & COMPLIANCE
  • SECURITY ENGINEERING
  • VAPT
  • RISK & COMPLIANCE

MANIFESTO

I study how systems fail, and how they can be made harder to break.

VULNERABILITY ASSESSMENT · SECURITY ENGINEERING · RISK & COMPLIANCE

FIELD EXPERIENCE

ONE ROLE · IN PROGRESS

CURRENT
PERIOD
JAN 2026PRESENT
DISCIPLINE
VAPT · GRC · RISK & COMPLIANCE

INFO ESHIELD CYBER SOLUTIONS

CYBERSECURITY INTERN

Testing web applications, and working the compliance side of the same problem — where a finding has to become a control, and a control has to become a document somebody will accept.

TYPE
Internship · ongoing
ALONGSIDE
Final year of the B.E. programme
SCOPE
Assigned client engagements
ATTRIBUTION
Assisted and contributed — not lead
05AREAS OF WORK IN THIS ROLE

SELECTED PROFESSIONAL WORK

INFO ESHIELD CYBER SOLUTIONS · 5 AREAS

AREA

Testing assigned scope with Burp Suite, Nmap and Nikto.

METHOD

  1. 01Worked assigned application scope rather than choosing targets — reconnaissance, enumeration, then request-level testing.
  2. 02Intercepted and replayed requests to establish what an application accepts, and what it returns when it should not.
  3. 03Verified tool output by hand before it was written down. An unverified scanner result is a claim, not a finding.

APPLIED

BURP SUITENMAPNIKTO

WHAT IT CHANGED

A working habit: separate what a tool reported from what I could reproduce, and write the remediation step in the same sitting as the issue. The second half is what makes a report usable by the person who has to fix it.

THE ROLE THIS SITS UNDER IS IN FIELD EXPERIENCE. WORK BUILT OUTSIDE IT IS IN PROJECTS.

PROJECTS

SECURITY CASE ARCHIVE · 15 CASES · 2 STRATA

SELECTED WORKKEEP SCROLLING

SunsetPOST-QUANTUM MIGRATION, PUBLISHED TOOL

OPEN THE RECORD →

ENGAGEMENT WORK IS IN WORK ↑. COMPETITION AND GUIDED-LAB CREDENTIALS ARE IN THE CERTIFICATION ARCHIVE ↓.

PERSONAL PROJECTS

BUILT ALONE · NOT INDEPENDENTLY REVIEWED

09

LAB / RESEARCH

LAB ENVIRONMENTS AND CLOSED SIMULATIONS · NEVER PRODUCTION

06

RESEARCH DIRECTIONS

NOT STARTED · LISTED AS INTENT, NOT AS WORK

  • REF 099CONTROL ASSURANCE LEDGERContinuously prove a control is enforced everywhere, with tamper-evident evidence, instead of a screenshot that was true once.SELECTED · NEXTCOMPLIANCE ENGINEERING
  • REF 100CONTROL-TO-CODE TRACEABILITY MAPPERLink every compliance control to the code and configuration that actually implements it, so the mapping stops living in individual memories.SELECTED · NEXTCOMPLIANCE ENGINEERING
  • REF 101EVIDENCE FRESHNESS MONITORTreat the age of compliance evidence as a first-class risk. A control verified eleven months ago is not a control verified this morning.CONSIDEREDGRC
  • REF 016SECURITY GATE EFFICACY DASHBOARDMeasure which pipeline security gates have ever caught a real vulnerability, and which only spend developer time.CONSIDEREDDEVSECOPS
  • REF 098REMEDIATION FRICTION ANALYZERDiagnose why remediation is slow — ownership, windows, dependencies — rather than reporting that it is.CONSIDEREDVULNERABILITY MANAGEMENT
  • REF 118CONTROL COVERAGE CARTOGRAMRender where controls actually apply, weighted by criticality and exposure, so the missing ten percent stops hiding inside ninety.CONSIDEREDSECURITY PROGRAM
  • REF 119INCIDENT NARRATIVE RECONSTRUCTORTurn correlated events into a readable causal account with evidence linked to every claim.CONSIDEREDINCIDENT RESPONSE

SECURITY PRACTICE

01 / 06
  1. INTERNSHIP + LAB. VAPT methodology, Reconnaissance, Enumeration, Scanning and triage, Post-exploitation — lab only, Manual verification of tool output.
  2. INTERNSHIP. Web application testing, SQL Injection, Cross-site scripting, Burp Suite, Nikto, Misconfiguration identification.
  3. COURSEWORK + LAB. TCP/IP, DNS · DHCP, Subnetting · VLAN · NAT, Network enumeration, Traffic analysis, Insecure protocol identification.
  4. TRYHACKME LABS. Splunk, SPL queries, Log ingestion and analysis, Failed login detection, Suspicious activity analysis, MITRE ATT&CK mapping.
  5. LAB + SELF-DIRECTED. Windows hardening, Linux hardening, Firewall configuration, Privilege control, Security policy enforcement, System administration.
  6. INTERNSHIP. ISO 27001 controls — foundational, Risk assessment support, Compliance mapping, Security documentation, VAPT reporting, Audit support.

ACADEMIC JOURNEY

SEPT 2022 – JUNE 2026

B.E. COMPUTER ENGINEERING

C.K. PITHAWALA COLLEGE OF ENGINEERING AND TECHNOLOGY

2022

PROGRAMME BEGINS

Enrolled on the four-year B.E. Computer Engineering programme at C.K. Pithawala College of Engineering and Technology.

  • SEPT 2022B.E. Computer Engineering — enrolled

RELEVANT COURSEWORK · NOT DATED TO A YEAR

  • NETWORK SECURITYControls, protocols, attack surface
  • CRYPTOGRAPHYPrimitives and their failure modes
  • OPERATING SYSTEMSPrivilege, process, memory
  • COMPUTER NETWORKSTCP/IP, routing, segmentation
  • DATABASE MANAGEMENT SYSTEMSQuery, transaction, access
  • CLOUD COMPUTINGIdentity, configuration, tenancy

CERTIFICATION ARCHIVE

11 ARTIFACTS · 3 ISSUER-VERIFIED · 7 HOSTED COPY · 1 IN PROGRESS

TECHNICAL TOOLKIT

TOOLING · PROTOCOLS · FRAMEWORKS

WHERE EACH OF THESE COMES FROM — INTERNSHIP, LAB, COURSEWORK OR SELF-DIRECTED — IS STATED BY DOMAIN IN SECURITY PRACTICE ↑.

RECON

TRAFFIC

VAPT

SIEM

SYSTEMS

NETWORKING

SCRIPTING

FRAMEWORKS

ABOUT

WRITTEN TO BE CHECKED

TRACING

UNDERSTAND

I work at the intersection of security assessment,

systems, networks, and assurance.

My focus is understanding where systems fail,

how those failures can be demonstrated,

and how they can be reduced.

Most of what I do begins with one question: what does this system assume, and what happens when the assumption is false. Testing a web application answers it directly. Mapping a control to a policy answers it slowly, on paper, with less certainty.

A finding and a control are not the same object. One is a request that returns something it should not. The other is a statement an auditor will accept. Translating between them is the part of the work I have learned the most from.

I am early. The record below is an internship, a completed degree, structured coursework and lab work. It is written to be checked, not to impress.

FOCUS
VAPT · SECURITY ENGINEERING · RISK & COMPLIANCE
CURRENTLY
CYBERSECURITY INTERN — VAPT, RISK & COMPLIANCE, Info eShield Cyber Solutions
BUILDING
THIS PORTFOLIO — PUBLISHED AND DEPLOYED

CONTACT

OPEN TO JUNIOR ROLES

LET'S TALK.