Summary
Overview
Work History
Education
Skills
Projects
Certification
Timeline
Generic

Doniyor Khushvaktov

Van Nuys

Summary

Cybersecurity professional with 3+ years experience in deep understanding of security concepts and best practices.

Experienced in network security, incident response, penetration testing, identifying, and mitigating security vulnerabilities .

Implemented security controls to improve organizational security posture and managed security incidents. Responded to 40+ high-severity incidents by containing, investigating, and remediating.

Aiming to make a measurable impact and enhance the security of organizations served through skills and expertise.

Overview

4
4
years of professional experience
1
1
Certification

Work History

Security Engineer

Cyber-Bro Security LLC
04.2023 - Current
  • Security Performance Reporting: Provide Regular reports on the state of information security to executive management
  • Security Incident Monitoring: Utilize security tools and technologies to monitor network traffic, log files, and system events to detect potential security incidents or breaches
  • Vendor and Third -Party Risk Management: Evaluate the security posture of third-party vendors and service providers, ensuring they meet the company’s security standards and requirements
  • Performing Threat Intelligence on the Reports that Provided by daily follow up with the latest security Trends and feeds from trusted sources
  • Implemented necessary controls and procedures to protect information system assets from intentional or inadvertent modification, disclosure or destruction.

Information Security Analyst

ITF Group
04.2022 - 03.2023
  • Monitor networks, systems, and applications for security breaches and intrusion attempts using SIEM tools like Splunk. Investigate any anomalies or events.
  • Configure firewalls, intrusion detection/prevention systems, and other network security tools to protect systems and data. Vendor tools include Cisco, Palo Alto, Juniper.
  • Respond to security incidents by isolating affected systems, gathering forensic evidence, determining root cause, and implementing fixes.
  • Analyze malware, phishing emails, and other threats. Contain impacted systems.

Intern Cyber Security Analyst ( Remote )

Yandex Go
05.2021 - 09.2021
  • Conducted threat hunting and forensic investigations using industry-leading tools such as FTK and Splunk, resulting in a 10% reduction in mean-time-to-detection of incidents and minimizing threat actor dwell time.
  • Analyzed comprehensive security assessments and vulnerabilities scans to identify potential threat and risks
    and recommended and implemented security solutions that led to 60% reduction in security incidents in the
    first quarter.
  • Coached 5+ junior team members on the security best practices via weekly sessions, reducing security
    vulnerabilities by 35% and saving the company $ 70k in costs.
  • Orchestrated the implementation of advanced network security controls, including antivirus and firewalls,
    across 5 systems, reduced the number of cyber threats by 50% and prevented data breaches in teams of 6.
  • Assessed comprehensive security scans and penetration testing on.
  • Analyze the weekly Security Posture Report, provide to CISO Record, and catalog any lessons learned from
    any critical incident or new threat.

IT Support Specialist

PDP Academy
01.2020 - 06.2020
  • Provided Tier 1 IT support and troubleshooting to resolve IT issue for non-technical internal users through via phone, chat and in person visits
  • Automated employee on-boarding and o-boarding process for faster and consistent setup of accounts,
    permissions, equipments
  • Diagnose and debug hardware, software, network connectivity, audio/video issues using proactive troubleshooting techniques
  • Managed backup and recovery of data assets to safeguard system availability.

Education

Global Humanities and Arts -

Sapienza University
05.2022

Cyber Security And Ethical Hacking Programm -

PDP Academy ( Online )
12.2020

Foundation Year in Finance and Accounting -

Westminster University
06.2020

Skills

  • SIEM
  • Endpoint Security
  • Vulnerability Management
  • Threat Intelligence
  • Malware Analysis
  • Digital Forensics
  • Phishing Analysis
  • Incident Response
  • Penetration Testing
  • Red Teaming
  • Networking Analysis
  • Python
  • Django
  • HTML5
  • PostgreSQL
  • Effective Problem Solving
  • Critical Thinking
  • Lifelong Learning
  • Leadership
  • Communication
  • Teamwork
  • Adaptability

Projects

  • Worked as a team member to develop a contacting section in Python for an ecommerce platform. Contributed to designing the database schema and creating the admin interface.
  • Performed vulnerability scans using Nessus on a legacy web application and recommended remediation. Identified XSS, SQL injection, and out-of-date platform vulnerabilities. Suggested patching vulnerable components and implementing input validation to address findings.
  • Started a new StartUp named Badrun-Cyber in Cybersecurity Field with small team to test system and web application

Certification

  • Certified Red Team Professional ( CRTP ) - Enumeration, Domain Privileges Escalation, Cross Trust Attack, Defense Monitoring
  • Junior Penetration Tester ( eJPT ) - OSINT, Host and Networking Testing, Web Application Testing
  • Certified Blue Team Level 1 ( BTL1 ) - Phishing Analysis, Threat Intelligence, Digital Forensics, SIEM, Incident Response
  • TryHackMe Professional Certificates - Red Teaming, Jr.Pentester, SOC Level 1\2, CompTia Pentest+, Cyber Defense, Offensive Pentesting

Timeline

Security Engineer

Cyber-Bro Security LLC
04.2023 - Current

Information Security Analyst

ITF Group
04.2022 - 03.2023

Intern Cyber Security Analyst ( Remote )

Yandex Go
05.2021 - 09.2021

IT Support Specialist

PDP Academy
01.2020 - 06.2020

Global Humanities and Arts -

Sapienza University

Cyber Security And Ethical Hacking Programm -

PDP Academy ( Online )

Foundation Year in Finance and Accounting -

Westminster University
Doniyor Khushvaktov