SECURITY PORTFOLIO
SHOURYA SAI MACHA
I'm Shourya, a CIS student at the University of Houston. I work where incident response meets automation: triaging alerts, pulling IOCs, and writing Python and SQL that handles the tedious analysis so a human doesn't have to. I'd rather chase a root cause than patch over it.
SKILLS MATRIX
WHAT I WORK WITH
PROFICIENCY_CHART // HOVER NODES TO INSPECT MODULE
These levels are self assessed, not from an external benchmark.
MODULE_01 // SOC & INCIDENT RESPONSE
MODULE_02 // CYBER THREAT INTELLIGENCE
MODULE_03 // GRC & COMPLIANCE
MODULE_04 // VULNERABILITY MANAGEMENT
MODULE_05 // SIEM & DETECTION ENGINEERING
MODULE_06 // NETWORK & ENDPOINT SECURITY
MODULE_07 // IAM & ACCESS CONTROL
MODULE_08 // CLOUD & INFRASTRUCTURE
MODULE_09 // DEVELOPMENT & AUTOMATION
PROJECTS
SELECTED WORK // SECURITY AND AUTOMATION
MITRE ATT&CK TTP MAPPER
I worked through 1,200+ incident records to automate IOC extraction, indicator enrichment, and correlation of adversary techniques to MITRE ATT&CK across the full CTI lifecycle. It produces kill chain maps and NIST CSF control gap reports, and exports Sigma rules for Splunk, Elastic, and Azure Sentinel. It cut my SOC review time by about 60% and improved detection accuracy by about 25%.
IoT / OT ATTACK SURFACE SCANNER
I ran authenticated and unauthenticated scans with OpenVAS methodology, mapped to MITRE ATT&CK for ICS, to find exposed CVEs, open ports, and misconfigurations. Findings get CVSS scores in the style of a Nessus or Tenable report, and I track each one through patch validation. I followed NIST SP 800 115 for the testing method and surfaced the results in a Next.js dashboard that uses GPT 4o to turn technical risk into prioritized fixes.
EMAIL PHISHING DETECTION TOOL
I automated triage for 500+ .eml files: deobfuscating malicious HTML, pulling hidden URLs, and running SPF, DKIM, and DMARC header forensics. It enriches indicators through the VirusTotal API in real time and maps techniques to MITRE ATT&CK T1566. It cut manual review time by about 40% and raised detection accuracy by about 30%.
SECURE AUDIT LOGGING SYSTEM
I built a tamper evident audit logging system that cryptographically chains events across 50+ endpoints and is designed to stay intact even if part of it fails. It aligns to the NIST SP 800 53 AU and SI control families, SOC 2, and FISMA, so it produces the kind of evidence an ATO needs. I also wrote and tuned the Sigma rules that feed Splunk, Elastic, and Azure Sentinel. It cut forensic analysis time by about 35%.
COMP, CARE OPTIMIZATION AND MEDICATION PROCESSING
Built during a public interest healthcare compliance challenge, where it earned an honorable mention. It applies AI governance ideas to simulate a pre submission insurance medical reviewer: it returns specific named compliance flags with rebuttals drawn from patient history, then drafts approval ready letters and post denial appeal scripts. The aim was to cut roughly 13 hours of documentation work per physician each week.
SENIOR FACILITY ROOM OCCUPANCY SYSTEM
A full stack system for a senior living facility covering 200+ residents and 100+ rooms. I designed role based access control and the full IAM lifecycle, set up least privilege tiers, configured AWS IAM policies, and ran MySQL backed identity workflows on AWS RDS. The REST APIs respond in under 100ms, and I used parameterized queries and input validation to close OWASP A03 injection risks.
EMPLOYMENT RECORD
CURRENT ROLE // UNIVERSITY OF HOUSTON
EMPLOYER: MD ANDERSON LIBRARY // UNIVERSITY OF HOUSTON
STUDENT IT ASSISTANT
LOG_01 // INCIDENT RESPONSE
I handle detection and analysis for 50+ security alerts a day across network, digital, and print systems at the library, following NIST 800 61. I classify severity, run the escalation workflow, then triage, contain, and document each incident. Over two years I have kept the escalation backlog at zero.
LOG_02 // DOCUMENTATION & TRAINING
I wrote 10+ security documents the team still uses: incident response playbooks, access control procedures, and remediation runbooks aligned to NIST SP 800 53. They were adopted across the organization, and I built the training materials new IT staff onboard from.
LOG_03 // IDENTITY & ACCESS MANAGEMENT
I run identity provisioning and access reviews for 100+ accounts on research platforms like JSTOR, ProQuest, and EBSCOhost. I enforce role based access and least privilege, and I have kept 10,000+ physical and digital records intact with no data handling incidents.
LOG_04 // VULNERABILITY & REMEDIATION
I find weak spots across the network and critical systems, then fix them with firewall config changes, network segmentation corrections, and endpoint hardening. I track each finding through to resolution and keep audit ready POA&M style records.
CERTIFICATIONS
CERTIFICATIONS AND EDUCATION // VERIFIED
EDUCATION
University of Houston, B.S. Computer Information Systems
RELEVANT COURSEWORK
GET IN TOUCH
SEND ME A MESSAGE
SHOURYA SAI MACHA // B.S. CIS // UNIVERSITY OF HOUSTON // DEC 2026