[ INITIALIZING SYSTEM ]

> LOADING MODULES...

> THREAT INTELLIGENCE DB: OK

> IDENTITY VERIFICATION: OK

> SIGMA RULES ENGINE: OK

> MITRE ATT&CK NAVIGATOR: OK

> SIEM CONNECTION: OK

[ OPERATOR TERMINAL READY ]

SHOURYA SAI MACHA ✦ SECURITY+ CERTIFIED ✦ NETWORK+ CERTIFIED ✦ SOC ANALYST ✦ THREAT INTELLIGENCE ✦ GRC / COMPLIANCE ✦ NIST 800-61 ✦ MITRE ATT&CK ✦ UNIVERSITY OF HOUSTON ✦ DEC 2026 ✦ SHOURYA SAI MACHA ✦ SECURITY+ CERTIFIED ✦ NETWORK+ CERTIFIED ✦ SOC ANALYST ✦ THREAT INTELLIGENCE ✦ GRC / COMPLIANCE ✦ NIST 800-61 ✦ MITRE ATT&CK ✦ UNIVERSITY OF HOUSTON ✦ DEC 2026SHOURYA SAI MACHA ✦ SECURITY+ CERTIFIED ✦ NETWORK+ CERTIFIED ✦ SOC ANALYST ✦ THREAT INTELLIGENCE ✦ GRC / COMPLIANCE ✦ NIST 800-61 ✦ MITRE ATT&CK ✦ UNIVERSITY OF HOUSTON ✦ DEC 2026 ✦ SHOURYA SAI MACHA ✦ SECURITY+ CERTIFIED ✦ NETWORK+ CERTIFIED ✦ SOC ANALYST ✦ THREAT INTELLIGENCE ✦ GRC / COMPLIANCE ✦ NIST 800-61 ✦ MITRE ATT&CK ✦ UNIVERSITY OF HOUSTON ✦ DEC 2026
CTI LIFECYCLE ✦ SPLUNK SPL ✦ SIGMA RULES ✦ VULNERABILITY MANAGEMENT ✦ IDENTITY PROVISIONING ✦ AWS IAM ✦ PYTHON / FASTAPI ✦ DOCKER ✦ OpenVAS ✦ KILL CHAIN MAPPING ✦ CTI LIFECYCLE ✦ SPLUNK SPL ✦ SIGMA RULES ✦ VULNERABILITY MANAGEMENT ✦ IDENTITY PROVISIONING ✦ AWS IAM ✦ PYTHON / FASTAPI ✦ DOCKER ✦ OpenVAS ✦ KILL CHAIN MAPPINGCTI LIFECYCLE ✦ SPLUNK SPL ✦ SIGMA RULES ✦ VULNERABILITY MANAGEMENT ✦ IDENTITY PROVISIONING ✦ AWS IAM ✦ PYTHON / FASTAPI ✦ DOCKER ✦ OpenVAS ✦ KILL CHAIN MAPPING ✦ CTI LIFECYCLE ✦ SPLUNK SPL ✦ SIGMA RULES ✦ VULNERABILITY MANAGEMENT ✦ IDENTITY PROVISIONING ✦ AWS IAM ✦ PYTHON / FASTAPI ✦ DOCKER ✦ OpenVAS ✦ KILL CHAIN MAPPING

OPERATOR // PORTFOLIO // v2.0

SHOURYA SAI MACHA

[ SECURITY ANALYST · CTI · GRC ]

Security-focused CIS student — SOC operations, incident response (NIST 800-61), GRC/compliance, vulnerability management, and cyber threat intelligence. CompTIA Security+ · Network+ certified. Graduating December 2026.

LOC //Sugar Land, TX → Houston, TX
EDU //University of Houston — B.S. CIS
STATUS //IN PROGRESS — AWS Cloud Practitioner
SCROLL TO INITIALIZE
SECTION.02 // CAPABILITIES

SKILLS MATRIX

CAPABILITIES // OPERATOR LOADOUT

PROFICIENCY_CHART // HOVER NODES TO INSPECT MODULE

SKILL MATRIXPROFICIENCY
02468SOC/IRCTIGRCVuln MgmtSIEMNet/EPIAMCloud

MODULE_01 // SOC & INCIDENT RESPONSE

Security MonitoringAlert TriageIOC ExtractionNIST 800-61Incident ClassificationEvidence HandlingContainment & RemediationEscalation WorkflowsDigital ForensicsRoot Cause Analysis

MODULE_02 // CYBER THREAT INTELLIGENCE

TTP ProfilingAdversary Campaign AnalysisCTI LifecycleKill Chain MappingMITRE ATT&CKMITRE ATT&CK for ICSIndicator EnrichmentStatic Artifact AnalysisBehavioral DetectionMalware Triage

MODULE_03 // GRC & COMPLIANCE

RMFNIST SP 800-37NIST SP 800-53SSP DevelopmentATO ProcessPOA&M TrackingISCMHIPAAFISMAFedRAMPCMMCSOC 2PCI-DSSGDPRSOXGLBAISO 27001NIST CSFOWASP Top 10

MODULE_04 // VULNERABILITY MANAGEMENT

OpenVASNessus / TenableCVSS ScoringNIST SP 800-115Patch ValidationOT/ICS Attack SurfacePenetration TestingThreat ModelingBaseline Hardening

MODULE_05 // SIEM & DETECTION ENGINEERING

Splunk (SPL)Elastic / KQLMicrosoft SentinelELK StackWazuhSigma Rule AuthoringCorrelation Rule LifecycleAlert TuningMITRE Navigator

MODULE_06 // NETWORK & ENDPOINT SECURITY

Firewall Log ReviewNetwork SegmentationNmapWiresharkpfSenseIDS/IPSEndpoint HardeningBurp SuiteMetasploit

MODULE_07 // IAM & ACCESS CONTROL

Identity ProvisioningLifecycle ManagementRBACLeast-PrivilegeUser Access ReviewsAuthentication WorkflowsCIA Triad

MODULE_08 // CLOUD & INFRASTRUCTURE

AWS IAMAWS EC2AWS RDSCloudTrailAzure SentinelAzure DefenderDockerKubernetesTerraformLinux AdminDevSecOps
SECTION.03 // OPERATIONS

OPERATIONS LOG

DEPLOYED ASSETS // FIELD OPERATIONS

OP-001

MITRE ATT&CK TTP MAPPER

Automated IOC extraction, indicator enrichment, and adversary TTP correlation across 1,200+ incident records. Managed full Sigma rule lifecycle — SPL/KQL export — for Splunk, Elastic, and Azure Sentinel.

PythonFastAPIStreamlitPlotlyDocker
60% ANALYST TIME ↓25% DETECTION ACCURACY ↑
[ DEPLOYED ][ VIEW REPO ↗ ]
TERMINAL // OP-001
# MITRE ATT&CK TTP Mapper
> python ttp_mapper.py --source incidents.json
Loaded 1,247 incident records...
IOC extraction complete: 3,891 indicators
> python enrich.py --export sigma --target splunk
Sigma rules exported: 47 correlation rules
MITRE Navigator heat map generated: OK
SOC review time reduced: 60%
>
OP-002

IoT / OT ATTACK SURFACE SCANNER

OpenVAS-methodology authenticated/unauthenticated vulnerability scans aligned to MITRE ATT&CK for ICS. CVSS-scored findings. GPT-4o-powered interactive dashboard for remediation briefings.

PythonFastAPINext.jsOpenVASGPT-4o
CVE ENUMERATIONNIST 800-115
[ DEPLOYED ]
TERMINAL // OP-002
# OT Attack Surface Scanner
> openvas-scanner --target 192.168.1.0/24 --auth
Authenticated scan initiated...
CVEs found: 23 | Critical: 4 | High: 9
> python cvss_report.py --framework ics --export pdf
CVSS scores computed (ICS weighting applied)
GPT-4o remediation brief: generated
>
OP-003

EMAIL PHISHING DETECTION TOOL

Automated triage across 500+ .eml files — HTML payload deobfuscation, SPF/DKIM/DMARC forensics, VirusTotal enrichment. Mapped to MITRE ATT&CK T1566.

PythonVirusTotal API
40% REVIEW TIME ↓30% DETECTION ↑
[ DEPLOYED ][ VIEW REPO ↗ ]
TERMINAL // OP-003
# Phishing Detection — T1566
> python phish_detector.py --dir ./emails/ --vt-enrich
Processing 512 .eml files...
Deobfuscated HTML payloads: 38
SPF/DKIM/DMARC failures: 14
VirusTotal hits: 9 malicious indicators
CTI report generated: ATT&CK T1566.001, T1566.002
>
OP-004

SECURE AUDIT LOGGING SYSTEM

Cryptographic chaining audit architecture across 50+ endpoints. Sigma correlation rules for Splunk/Elastic/Sentinel. Aligned to NIST SP 800-53 AU/SI, SOC 2, FISMA, FedRAMP.

PythonFlaskSQLite
35% FORENSIC TIME ↓
[ DEPLOYED ][ VIEW REPO ↗ ]
TERMINAL // OP-004
# Secure Audit Logging — NIST 800-53 AU
> python audit_chain.py --init --endpoints 50
Cryptographic chain initialized (SHA-256)
Tamper-evident log capture: ACTIVE
> python sigma_export.py --target splunk elastic sentinel
Sigma rules exported: 3 SIEM targets
FedRAMP audit trail: COMPLIANT
>
OP-005

COMP — CARE OPTIMIZATION & MEDICATION PROCESSING

AI governance R&D for healthcare compliance. Simulated pre-submission insurance medical reviewer — real-time compliance flags, patient-history rebuttals, approval-ready letters and appeal scripts.

Base44AI
13 HRS/PHYSICIAN/WEEK TARGET
[ HONORABLE MENTION ]
TERMINAL // OP-005
# COMP — Healthcare AI Compliance
> comp-ai review --patient-history ./records.json
Insurance pre-submission review: INITIATED
Compliance flags detected: 3
Patient-history rebuttals: generated
Approval letter: drafted
Documentation burden reduced: ~13 hrs/physician/week
>
OP-006

SENIOR FACILITY ROOM OCCUPANCY SYSTEM

Enterprise RBAC and full IAM lifecycle for 200+ residents and 100+ rooms. REST APIs with sub-100ms latency on AWS RDS. OWASP A03 injection prevention.

PythonFlaskNode.jsMySQLAWS RDS
<100ms QUERY LATENCY200+ RESIDENTS
[ DEPLOYED ][ VIEW REPO ↗ ]
TERMINAL // OP-006
# Room Occupancy — IAM + AWS RDS
> python setup_iam.py --roles admin staff resident --rds
RBAC tiers provisioned: 3 roles
AWS IAM policies applied: OK
> ab -n 1000 -c 50 http://api.facility.local/rooms
Requests/sec: 312 | Avg latency: 87ms
OWASP A03 parameterized queries: VERIFIED
>
SECTION.04 // DEPLOYMENT

EMPLOYMENT RECORD

ACTIVE DEPLOYMENT // FIELD ASSIGNMENT

UNIT: MD ANDERSON LIBRARY // UNIVERSITY OF HOUSTON

STUDENT IT ASSISTANT

TENURE: FEB 2024 — PRESENT

LOG_01 // INCIDENT RESPONSE

Executed Detection & Analysis for 50+ daily security alerts across network, digital, and print systems (NIST 800-61) — classified incident severity, executed structured escalation workflows, performed triage, containment, and documented response actions.

[ 50+ DAILY ALERTS ][ ZERO ESCALATION BACKLOG ][ 2+ YEARS ]

LOG_02 // DOCUMENTATION & TRAINING

Authored 10+ SSP-adjacent security documents — IR playbooks, access control procedures, and remediation runbooks aligned to NIST SP 800-53 — adopted organization-wide. Delivered technical training materials for rotating IT staff cohorts.

[ 10+ SSP DOCUMENTS ][ NIST SP 800-53 ][ ORG-WIDE ADOPTION ]

LOG_03 // IDENTITY & ACCESS MANAGEMENT

Administered identity provisioning and user access reviews for 100+ accounts across JSTOR, ProQuest, EBSCOhost. Enforced RBAC and least-privilege policies. Maintained 10,000+ physical and digital records with zero data-handling incidents.

[ 100+ ACCOUNTS ][ 10,000+ RECORDS ][ ZERO DATA INCIDENTS ]

LOG_04 // VULNERABILITY & REMEDIATION

Diagnosed security weaknesses across network infrastructure and mission-critical systems. Applied firewall configuration adjustments, network segmentation corrections, and endpoint hardening. Maintained audit-ready POA&M-style remediation records.

[ FIREWALL CONFIG ][ NETWORK SEGMENTATION ][ POA&M RECORDS ]
SECTION.05 // CLEARANCES

CERTIFICATIONS

OPERATOR CLEARANCES // VERIFIED

CERT-001

CompTIA

Security+

SY0-701

[ ACTIVE // 2025 ]

CERT-002

CompTIA

Network+

N10-009

[ ACTIVE // 2025 ]

CERT-003

Amazon Web Services

AWS Cloud Practitioner

CLF-C02

[ IN PROGRESS // 2026 ]

PROGRESS:

SECTION.06 // TRANSMISSION

OPEN CHANNEL

INITIATE CONTACT // TRANSMISSION READY

COMPOSE_TRANSMISSION // CHANNEL: EMAIL
LOCATION //Sugar Land, TX → Houston, TX

SHOURYA SAI MACHA // B.S. CIS // UNIVERSITY OF HOUSTON // DEC 2026