Summary
Overview
Work History
Education
Skills
Websites
Certification
Projects
Timeline
Generic

Vishwamurti Purushottam

San Jose,CA

Summary

Accomplished and certified IT Security Professional with more than half a decade of experience driving enterprise-wide security initiatives. Proven expertise in automating security processes, enhancing compliance, and implementing robust security solutions. Skilled in incident response, vulnerability management, penetration testing, policy development, and risk assessment, with a strong focus on cloud security and compliance. Leveraged AI and LLM technologies to upgrade existing processes, improve efficiency, and enhance organizational security frameworks.

Overview

6
6
years of professional experience
1
1
Certification

Work History

DEVSEC ENGINEER

Picarro
04.2021 - 11.2024

• Performed day-to-day security operations, including vulnerability assessments, patch

management, and incident response, while managing AWS resources (EC2, RDS, S3,

ALB, Lambda, IAM) with a focus on security and scalability.

• Developed and maintained ISMS frameworks aligned with ISO 27001 and SOC2,

achieving zero audit findings for four consecutive years.

• Conducted annual risk assessments, compliance audits, and third-party vendor

evaluations, identifying gaps and recommending mitigation strategies.

• Automated CIS control deployment for AWS environments and production hardware,

leveraging Python, Ansible, and Pulumi IaC to ensure compliance and security.

• Streamlined user lifecycle management and patch management using AWS Systems

Manager (SSM), while automating JFrog key rotation to enhance supply chain security.

• Refactored Github Dependabot workflows to parse alerts and auto-generate JIRA

tickets using AWS Lambda and RDS, streamlining vulnerability management.

• Implemented AWS Config rules, SCPs, and centralized CloudTrail logging to enforce

compliance and establish guardrails across accounts.

• Built an LLM-powered inference server to automate vulnerability tracking and

communication, aligning remediation with corporate policies.

• Integrated security tools (SAST/DAST) into DevOps pipelines, automated AWS WAF

responses, and utilized ELK and Lacework for proactive threat detection and response.

• Conducted manual web application penetration testing with tools like Burp Suite and

OWASP ZAP to validate and remediate vulnerabilities.

• Authored 44 information security policies and detailed compliance reports to

strengthen organizational security and ensure regulatory adherence.

• Created comprehensive Confluence documentation to standardize processes and

improve knowledge sharing across teams.

• Delivered OWASP Top 10 training sessions, cultivated a security-first culture through

impactful employee programs.

• Spearheaded real-time incident response platforms integrating The Hive, Wazuh IDS,

and Cortex, and proactively addressed high-priority incidents.

• Continuously monitored security trends and exploits, ensuring defenses were updated to mitigate emerging threats.

INFORMATION SECURITY ANALYST, INTERN

Partners Healthcare
01.2019 - 08.2019
  • Leveraged Splunk's machine learning toolkit to identify unauthorized access to PHI and developed custom use cases to detect privacy breaches, phishing, ransomware, and malicious behavior.
  • Automated incident response workflows using Splunk Phantom, improving response times and efficiency.
  • Conducted internal penetration testing to uncover vulnerabilities within the PCI zone and performed forensic analysis on flagged devices using Encase and CrowdStrike Falcon.
  • Configured McAfee MVISION Cloud to streamline log collection and ingestion processes across the organization.
  • Trained IT security interns on network security principles and the effective use of Splunk for threat detection and response.

IT RISK MANAGEMENT, INTERN

Meditology Services LLC
06.2018 - 08.2018

• Inspected and assessed healthcare information systems, security controls, and
operational processes for compliance with corporate policies and regulations.
• Conducted audits across various computing environments, identifying risks,
interpreting results, and documenting findings against defined criteria.
• Performed network penetration testing and recommended controls aligned with SOC2
and HITRUST standards to enhance the organization's security posture.

Education

M.S. - Cybersecurity

Northeastern University
Boston, MA
01.2019

B.E. - Telecommunications

VTU
01.2014

Skills

  • Python
  • Bash
  • C
  • Splunk SPL
  • Kibana KQL
  • MAC OS
  • Windows
  • Linux
  • Splunk
  • Phantom
  • Lacework
  • Wazuh IDS
  • ELK stack
  • Wireshark
  • Crowdstrike Falcon
  • McAfee MVISION
  • Nessus
  • Forescout
  • Problem solving
  • Issue management
  • Attention to detail
  • Time management
  • Verbal communication
  • Strategic planning
  • Administrative
  • Flexibility
  • Teamwork
  • Organizational Skills

Certification

  • AWS Cloud Practitioner
  • AWS Solutions Architect - Associate

Projects

Yocto Software Vulnerability Assessment Tool, Academic, Northeastern University, Boston, MA, 01/19, Created an application to parse the CVE report generated by Yocto. The application categorized vulnerabilities based on the attack vector, CVE base score, available patch status, and impact. TLS/SSL Cleanup, Academic, Northeastern University, Boston, MA, 01/19, Created a script to monitor the state of a TLS/SSL certificate on given servers. The script sent out a slack alert if any of the certificates were found to be in a bad state. The script was designed to run every day. Automated Nessus Scans, Academic, Northeastern University, Boston, MA, 01/18, Created a python script to automate the vulnerability scanning using Nessus REST API and emailed the report to a group of users. IDS for Home Network, Personal, Personal, Boston, MA, 01/17, Installed Snort open-source intrusion detection software on Raspberry Pi to act as an IDS for the home network and generate alerts whenever a user on the network browsed a malicious website.

Timeline

DEVSEC ENGINEER

Picarro
04.2021 - 11.2024

INFORMATION SECURITY ANALYST, INTERN

Partners Healthcare
01.2019 - 08.2019

IT RISK MANAGEMENT, INTERN

Meditology Services LLC
06.2018 - 08.2018

B.E. - Telecommunications

VTU

M.S. - Cybersecurity

Northeastern University
Vishwamurti Purushottam