anil@security:~$

whoami

Anil Kumar Gorthi

Cybersecurity Analyst · SOC & Multi-Cloud Security (AWS/Azure/GCP) · Boston, MA

I assess systems, break things on purpose so no one else has to, and build the infrastructure and documentation that keep security programs running after I leave the room. M.S. in Cybersecurity from Northeastern University.

cat about.md

About

I work across the parts of security that most teams underinvest in: SOC operations, cloud configuration, and the assessments that catch what automated scanners miss. My M.S. in Cybersecurity is backed by hands-on threat detection, incident response, and cloud security monitoring across AWS, Azure, and GCP. I'm currently looking for full-time SOC, GRC, or application security roles.

ls experience/

Experience

Cybersecurity Analyst — Community Dreams Foundation

  • Improved compliance posture by 25% by implementing RBAC, MFA, and PKI/TLS controls while monitoring and triaging SOC alerts for threat detection and incident response across cloud environments
  • Scaled secure cloud capacity by 60% by hardening infrastructure with Terraform-managed KMS encryption, TLS enforcement, VPC segmentation, and firewall controls aligned to CIS Benchmarks and NIST CSF
  • Cut incident response time by 15% by developing and standardizing CSIRT procedures, IR playbooks, and SOPs for audit-ready security operations
  • Surfaced a critical SSRF vulnerability and five high-severity findings by running a gray-box security assessment of the UpSkill platform (Lovable/Supabase), plus a 13-section reconnaissance report and RLS audit on two other production Supabase projects
  • Eliminated a fragmented password-management process by deploying Vaultwarden via Terraform on GCP, after building the technical case against a proposed in-house alternative and authoring the org's password management policy

Security Analyst — Mobile Heartbeat

  • Reduced risk exposure by 35% by triaging 25+ security incidents through behavioral analysis of anomalous activity in Azure Sentinel/Log Analytics (KQL) and EDR tooling, then driving remediation
  • Strengthened security posture by 20% by threat hunting across the environment, surfacing 55+ previously unidentified risks and vulnerabilities
  • Remediated 25+ non-compliant configurations by auditing 100+ Azure resources and prioritizing fixes for the top 3 root causes of security incidents
  • Validated compliance across NIST CSF, GDPR, and HIPAA by correlating cloud configurations against all three frameworks and presenting remediation timelines to senior leadership

Software Developer Intern — Plus Delta

  • Increased platform security by 35% by performing vulnerability assessments and penetration tests across 80+ API endpoints and delivering remediation recommendations
  • Accelerated vulnerability remediation by 25% by developing Python automation that integrated security findings directly into CI/CD pipelines

ls projects/

Projects

Swift Security Scanner

CLI tool

Built a command-line scanner covering the full OWASP Mobile Top 10 (2024 revision) by parsing iOS/Swift codebases for common insecure patterns, giving mobile teams a fast first pass before manual review.

Wireless doorbell replay attack

RF / SDR

Improved IoT threat detection by 15% by reverse-engineering a 433.95 MHz wireless system with a PlutoSDR and GNU Radio, analyzing 1,200+ captured RF bursts, and simulating replay attacks across 15 devices.

Blind remote buffer overflow & reverse shell

Exploit dev

Achieved a 95% exploit hit rate by automating a Python tool for stack layout identification, NOP sled tuning, and payload sizing against a remote target with no local debugging access.

Windows insider threat investigation

Digital forensics

Improved threat detection rate by 20% by conducting digital and browser forensics across a 60GB Windows disk image, uncovering user activity tied to potentially compromised accounts and implementing new detection strategies from the findings.

Vaultwarden on GCP

Infra / Terraform

Built foundational Terraform and GCP infrastructure for a self-hosted Vaultwarden deployment, designed as a portable pattern that could be reused for future password-management rollouts.

ls research/ | sort -k date -r

Research

Evaluation of Risk and Resilience of the MBTA Green Rapid Transit System

arXiv · Dec 2025

Pinpointed five critical network vulnerabilities in infrastructure serving 100,000+ daily riders by modeling the MBTA Green Line's cyber-physical risk with graph theory, network centrality measures, and Model-Based Risk Analysis (MBRA) in Python. Originally written for a Northeastern course, revised and posted publicly.

Read on arXiv

Credit Risk Management using Logistic and Linear Regression

JETIR · Apr 2023

Co-authored a study on modeling credit risk (LGD, PD, EAD) with logistic and linear regression, examining the role of big data and regulatory frameworks in credit risk practice.

Read on JETIR

Alzheimer's Disease Recognition using CNN Model with EfficientNetV2

IEEE ASIANCON · Aug 2022

Co-authored a CNN/EfficientNetV2 approach for classifying Alzheimer's disease from MRI scans, using transfer learning to retrain on a smaller labeled dataset. Presented at the 2022 IEEE Asian Conference on Innovation in Technology.

Read on IEEE Xplore

cat skills.yaml

Skills

detection & SOC

  • SIEM (Azure Sentinel, Log Analytics/KQL, Splunk)
  • Alert triage & threat hunting
  • Incident response & IR playbooks
  • IDS/IPS, EDR, NGFW
  • Vulnerability & threat modeling

cloud & infrastructure

  • AWS, Azure, GCP
  • Terraform (IaC)
  • Zero Trust, WAF, Okta
  • VPC/VNet segmentation
  • KMS / encryption at rest & in transit

offensive security

  • Penetration testing
  • Web application assessments
  • RF / SDR security research
  • Exploit development
  • SAST/DAST integration

governance & compliance

  • NIST CSF, CIS Benchmarks
  • SOC 2, HITRUST
  • GDPR, HIPAA
  • Security policy authorship

scripting & platforms

  • Python, C, Java, PowerShell, SQL
  • Git/GitHub, CI/CD pipeline security
  • Windows, Linux (Ubuntu, Kali, Arch, Tails), macOS
  • TCP/IP, HTTP, DNS, IoT devices

cat education.md

Education & certifications

M.S. Cybersecurity — Northeastern University
B.Tech Computer Science & Engineering — GITAM University
CompTIA Security+ · May 2025 ISC2 Certified in Cybersecurity (CC) · Aug 2025