Akash Bhat

Cybersecurity Analyst  ·  Threat Detection & Incident Response  ·  Web Application Security

SOC · Threat Detection OWASP Top 10 · VAPT Microsoft Sentinel · KQL MITRE ATT&CK NIST CSF · Incident Response AWS Cloud Security GRC · Risk Documentation

Cybersecurity analyst with hands-on experience across SOC operations, cloud SIEM, web application security, and incident response. Based in Melbourne - building real skills through real labs.

Available · Melbourne, VIC · Australian Permanent Resident
4+
Cybersecurity
labs built
6+
Verified industry
programmes
2
Live GitHub
project repos
1 week
Notice
period
Background

Engineering precision.
Cybersecurity focus.

I started in Bangalore with a B.Tech in Aeronautical Engineering - spending three years across some of Asia's most demanding engineering environments including Sansera Engineering, Brahmastra Aerospace, and Autodesk. My final year project was a fully functioning obstacle-avoidance drone I built and coded from scratch - writing the C++ algorithm, designing every component in CAD, and integrating four ultrasonic sensors with PID control logic. That project taught me something I carry into cybersecurity: understanding how systems fail is more valuable than knowing how they work.

In 2023 I relocated to Melbourne and pivoted deliberately into cybersecurity. At RMIT I built a genuine technical foundation - vulnerability assessments, pfSense and Snort IDS/IPS configuration, Active Directory security controls, and a complete five-phase NIST CSF incident response plan for a simulated client engagement covering red, blue, and purple team operations.

Since graduating I've been building independently - deploying a Microsoft Sentinel lab in Azure with real KQL threat detection queries, completing cybersecurity programmes with Commonwealth Bank, Mastercard, Deloitte, and TCS, and working operationally at Coles CFC while I target the right cybersecurity role. Everything on this portfolio is real, documented, and defensible in an interview.

🎓
Education
Cert IV Cybersecurity - RMIT University
B.Tech Aeronautical Engineering - Jain University
Notice period
1 week - available immediately
📍
Location
Melbourne, VIC - open to relocate anywhere in Australia
Technical skills

Every tool listed here
has been used hands-on

SIEM & Log Analysis
Microsoft Sentinel (KQL)
Splunk & SPL
Log Analytics Workspace
Windows Security Events
IOC Investigation
Security Event Correlation
Threat Detection & IR
Alert Triage
Incident Response Planning
MITRE ATT&CK Mapping
NIST CSF - all 5 phases
Brute Force Detection
Vulnerability Assessment
Web Application Security
OWASP Top 10
SQL Injection
Cross-Site Scripting (XSS)
OS Command Injection
Burp Suite
Web App Penetration Testing
Network & Firewall
Wireshark Packet Analysis
pfSense Firewall
Snort IDS/IPS
Ettercap
Cisco Packet Tracer
Network Segmentation
Custom IDS Rule Authoring
Offensive Security
Kali Linux
Metasploit
Nmap
Zphisher - Phishing Simulation
ARP Poisoning
SYN Flood Attack
Session Hijacking
Scripting & Query Languages
KQL - Kusto Query Language
SPL - Splunk Query Language
Python
Bash Scripting
PowerShell
Arduino C++
Cloud & Identity
AWS EC2 · Lambda · RDS · S3
AWS IAM & Security Groups
AWS VPC
Azure Virtual Machines
Active Directory & Group Policy
CCProxy Web Filtering
GRC & Documentation
ISO 27001 Fundamentals
Risk Documentation
Security Awareness Training
Threat & Risk Analysis
Stakeholder Reporting
Jira & Confluence
Technical Report Writing
Projects

Built, tested, documented

Every project below represents real hands-on work - each with full documentation, exploitation evidence, and professional-grade reporting.

RMIT University · Cert IV Cybersecurity

End-to-End Threat Simulation & Defence - NIST CSF Incident Response

Led the final implementation session of a full red, blue, and purple team security engagement for a simulated business client. Executed and defended against ARP poisoning, guest Wi-Fi session hijacking, SYN flood, and credential phishing attacks. Deployed CCProxy web filtering to block phishing at proxy level, enforced WPA2 encryption, configured Snort IDS/IPS rules on pfSense, and pushed static ARP policies via Active Directory Group Policy. Produced a five-phase NIST CSF incident response plan and full technical documentation.

Red TeamBlue TeamNIST CSFpfSenseSnort IDS/IPSActive DirectoryWiresharkKali Linux
↗ View on GitHubNov 2025 · RMIT University
Cybersecurity Industry Programme · Forage

Web Application Security Assessment - Commonwealth Bank

Conducted a structured web application security assessment as part of the Commonwealth Bank cybersecurity programme. Identified vulnerabilities across the OWASP Top 10 including SQL injection, OS command injection, broken access control, session management weaknesses, and cryptographic failures. Produced a formal penetration testing report with risk ratings, proof-of-concept evidence, and remediation recommendations aligned to industry standards.

OWASP Top 10Web App TestingSplunkSPLIncident TriageRisk Assessment
↗ View full report↗ PDFFeb 2026 · Verified
Cybersecurity Industry Programme · Forage

Enterprise Phishing Simulation & Security Awareness - Mastercard

Designed an enterprise phishing email simulation targeting employee personas across departments as part of the Mastercard cybersecurity programme. Interpreted simulation results to identify departments with the highest susceptibility and produced a security awareness training recommendation report with targeted risk mitigation strategies.

Phishing SimulationSocial EngineeringSecurity AwarenessRisk Analysis
↗ View certificateApr 2026 · Verified
Cybersecurity Industry Programme · Forage

Cybersecurity Risk & Threat Analysis - Deloitte

Completed Deloitte's cybersecurity virtual programme covering threat analysis, risk identification, and security advisory thinking. Applied structured frameworks to analyse real-world security scenarios, assessed business impact of cyber threats, and produced risk-aligned recommendations - building the consulting and advisory skills relevant to GRC, audit, and professional services cybersecurity roles.

Risk AnalysisThreat AssessmentGRCSecurity AdvisoryBusiness Impact Analysis
↗ View certificateApr 2026 · Verified
Cloud Security · AWS Academy · RMIT University

AWS Cloud Infrastructure & Security - Hands-On Academy Assessment

Completed a structured, assessed AWS Academy programme through RMIT University with timed hands-on modules across core AWS services. Configured EC2 instances with security group policies, applied least-privilege IAM roles and policies, set up RDS databases within VPC private subnets, deployed Lambda functions with scoped execution roles, and managed S3 bucket access controls. Each module was assessed and marked - covering cloud architecture, security best practices, pricing models, and support structures. Awarded the AWS Academy Graduate - Cloud Foundations badge upon completion.

AWS EC2IAMVPCS3RDSLambdaSecurity GroupsCloud Architecture
↗ View badgeDec 2025 · AWS Academy · RMIT
Engineering Build · B.Tech Final Year Project

Obstacle-Avoidance UAV - Hardware & Software Build

Built a functioning quadcopter drone entirely from scratch as a final year B.Tech project. Designed all mechanical components in AutoCAD and SolidWorks, wrote a real-time obstacle avoidance algorithm in Arduino C++ using four ultrasonic sensors and PID control logic, and integrated a KK2.1.5 flight controller. Successfully demonstrated live collision avoidance across all four directional axes during flight testing.

Arduino C++AutoCADSolidWorksEmbedded SystemsPID ControlSensor Integration
Credentials

Certifications & verified programmes

✓ Academic & Cloud
🎓
Certificate IV in Cybersecurity
RMIT University · Feb 2024 - Jan 2025
Completed
☁️
AWS Academy Cloud Foundations
Amazon Web Services · Dec 2025
✓ Industry Programmes - Forage
🏦
Commonwealth Bank
Cybersecurity · Feb 2026
💳
Mastercard
Cybersecurity · Apr 2026
🏢
Deloitte
Cybersecurity · Apr 2026
🔐
Tata Consultancy Services
Cybersecurity Analyst - IAM · Apr 2026
Experience

Where I've worked

Team Member - Part-time
Current
Coles CFC Truganina · Melbourne, VIC
  • Working part-time in a high-volume, fast-paced fulfilment environment - developing operational reliability, shift flexibility, and process discipline that translates directly into SOC and operations roles.
Operations Administrator & Project Research Associate
Aug - Nov 2025
Medilink Australia · Melbourne, VIC
  • Produced structured stakeholder reports translating complex operational findings into clear written communications for both technical and non-technical audiences.
  • Managed sprint tracking across multiple cross-functional teams via Jira and Confluence in a regulated, healthcare-adjacent environment with SOCI compliance requirements.
  • Supported compliance documentation and process validation workflows, gaining practical experience in risk-aware operational practices.
Cybersecurity Analyst - Industry Programme
Feb 2026
Commonwealth Bank Cybersecurity Programme · Remote
  • Analysed application log datasets using Splunk SIEM and SPL queries to detect anomalous activity patterns and surface Indicators of Compromise, replicating L1 SOC alert triage workflows.
  • Built investigative Splunk dashboards for security event visualisation and communicated findings clearly to both technical and non-technical stakeholders.
  • Completed a structured web application penetration test, producing a formal report covering OWASP Top 10 findings with risk ratings and remediation recommendations.
Customer Support Associate
Nov 2024 - Jan 2025
7-Eleven · Melbourne, VIC
  • Maintained consistent performance across extended shift patterns including nights, demonstrating the reliability and adaptability required in 24/7 operations environments.
  • Applied methodical troubleshooting to retail digital system issues under time pressure.
Aerospace & Engineering Internships
2020 - 2023 · India
Pegasus Aerospace · Brahmastra Aerospace · Sansera Engineering · Autodesk · Probots Techno Solutions · Verzeo
  • Industrial aerodynamics simulation using ANSYS at Pegasus Aerospace; embedded systems and IoT development at Probots Techno Solutions.
  • Motor-generator design using Autodesk tools; aerospace structural design and simulation at Brahmastra Aerospace Systems.
  • Summer placement at Sansera Engineering - one of Asia's top aerospace manufacturers - and AutoCAD programme completion at Verzeo.
About me

Hear it directly from me

A quick introduction - who I am, what I've built, and what I'm looking for.

🎥
Video coming soon
Introduction video will be uploaded here
Blog

Thinking out loud about cybersecurity

Short technical write-ups from real lab work - the kind of thinking that gets you hired.

◉ Published

How I Detected Brute Force Attacks Using KQL in Microsoft Sentinel

A walkthrough of setting up a Windows Server VM in Azure, connecting it to Microsoft Sentinel, generating real failed login events, and writing KQL queries to detect brute force patterns - including what the results actually mean from an analyst's perspective.

Microsoft SentinelKQLEvent ID 4625Azure
◉ Published

Red Team vs Blue Team - What a Real Purple Team Engagement Looks Like

From ARP poisoning to phishing defence - a breakdown of how our team attacked and defended a simulated business network, what worked, what didn't, and the key lessons about defence in depth that no textbook explains as clearly as doing it for real.

Red TeamBlue TeamARP PoisoningPhishing DefenceNIST CSF
Coming soon

DVWA OWASP Top 10 - SQL Injection to Full Database Dump

A step-by-step technical write-up of exploiting SQL injection in DVWA - from manual injection to full credential extraction, and the exact remediation steps that fix it. Written for analysts who want to understand both sides of the vulnerability.

SQL InjectionDVWAOWASP Top 10Burp Suite
Coming soon
Coming soon

AWS IAM Done Right - Least Privilege in Practice

Most cloud breaches come down to overpermissioned IAM roles. A practical guide to configuring EC2, Lambda, and RDS with genuinely least-privilege IAM policies - based on hands-on AWS Academy lab work and what the assessors actually tested.

AWS IAMEC2LambdaCloud Security
Coming soon
Contact

Open to the right opportunity

Based in Melbourne and open to opportunities across Australia and New Zealand. Reach out through any of the channels below.