Architecting Resilient Security Systems.

I am 

Leon Kaushik Deka. Building practical security tools and delivering website assurance, cloud hardening, GRC readiness, and incident recovery support.

Explore Services
Open Resume

20+

Mapped Controls

04

Framework Families

ZERO

Intrusive Default Checks

Technical Capabilities

Offensive Ops

Proactive threat hunting and vulnerability exploitation to identify weaknesses before adversaries.

Red Teaming Burp Suite Metasploit AD Attacks

Cloud Defense

Hardening AWS, Azure, and Kubernetes clusters against modern cloud-native threats.

Terraform AWS GuardDuty Docker Security CI/CD Pipelines

Detection Eng.

Building custom SIEM rules, Sigma signatures, and automated response playbooks.

Splunk Python Automation Threat Intel SOAR
ASSESS // FIX // OPERATE // RECOVER

Security services that end in a safer system.

Clear findings are only the beginning. I help growing teams understand the risk, implement the control, collect the evidence, and keep the program working after the audit.

01 // ASSURANCE

Website & Cloud Security Audit

A permission-based review of public exposure, website configuration, cloud architecture, identity, logging, backups, and recovery readiness.

  • Non-intrusive website and DNS baseline
  • Cloudflare, WAF, origin, and rate-limit review
  • Prioritized findings with implementation guidance
02 // READINESS

ISO, SOC 2 & GRC Readiness

Scope the right framework, map existing controls, identify evidence gaps, create accountable treatment plans, and prepare a reviewable audit room.

  • ISO 27001 and SOC 2 readiness support
  • Risk register, policies, controls, and evidence
  • NIST CSF and PCI-aligned implementation mapping
03 // MANAGED GRC

Ongoing GRC Operations

A practical operating rhythm for teams that need governance and compliance outcomes without building a full internal GRC function immediately.

  • Monthly risk, policy, control, and evidence reviews
  • Vendor security and questionnaire support
  • Leadership reporting and audit coordination
04 // HARDENING

Cloudflare & Security Hardening

Turn audit findings into safer edge, identity, cloud, monitoring, backup, and deployment configurations with validation after the change.

  • Managed WAF, bot, DNS, and origin protection
  • MFA, least privilege, and account recovery
  • Logging, backup isolation, and recovery tests
05 // CYBER RESCUE

Website & Cloud Recovery

Rapid triage and recovery coordination for hacked websites, malicious redirects, exposed credentials, account takeover, or unsafe cloud changes.

  • Containment guidance and evidence preservation
  • Clean recovery, credential reset, and monitoring
  • Root-cause review and post-incident hardening
06 // ENGINEERING

Security Automation

Small, inspectable tools that turn recurring checks, evidence, and security operations into repeatable workflows your team can own.

  • Python and Node.js security automation
  • CI/CD controls and machine-readable reports
  • Local-first GRC and evidence workflows

Start with a scoped security baseline.

Share the business objective, systems in scope, and deadline. I will propose a safe assessment and an outcome-focused delivery plan.

Discuss an engagement

Emergency and recovery work is subject to availability, written authorization, safe scope, and required specialist or legal partners. Readiness support does not issue certification or an independent audit opinion.

EC-COUNCIL CODERED // VERIFIED CREDENTIALS

Professional Certifications

Selected Deployments

View Archive →
SECURITY BASELINE // GRC // NODE.JS

TrustHarbor Toolkit

A zero-dependency command-line toolkit for safe website security baselines, ISO/SOC/NIST/PCI control mapping, company assessments, risk registers, evidence hashing, readiness tracking, and HTML/JSON/SARIF reporting.

View on GitHub
OFFENSIVE // GOLANG // CRYPTO

Stealth C2 Framework

Designed for Red Team operations, this lightweight Command & Control framework utilizes encrypted DNS tunneling to bypass enterprise firewalls and proxies. Includes a modular payload system.

View Architecture

Secure
Encrypted Line.

Need a website audit, GRC program, ISO/SOC readiness plan, Cloudflare hardening, or recovery support? Start with a scoped conversation.

ENCRYPTED EMAIL
leonkaushikdeka@gmail.com
LOCATION
Guwahati, Assam, India

Leon Kaushik Deka

Professional Summary

Cybersecurity-focused Computer Science graduate with structured hands-on training across SOC operations, offensive security, and AI-driven security analysis. Strong exposure to web and API penetration testing, adversary emulation, security automation using Python and AWS, and machine learning applications in digital forensics. Seeking entry-level roles in SOC, cybersecurity analysis, or security engineering.

Education

B.Tech. in Computer Science and Engineering (Honors in Cybersecurity)

Assam Skill University, Assam, India

Technical Skills

  • Cybersecurity & SOC: SOC monitoring, alert triage, incident response fundamentals, Blue Team operations, threat detection, adversary emulation
  • Vulnerability Assessment & Pentesting: Web application testing, API security testing (OWASP Top 10, OWASP API Top 10), lab-based exploitation
  • AI / ML for Security: Machine learning for digital forensics, data science for cybersecurity, generative AI security use cases, AI-assisted vulnerability discovery
  • Cloud & Automation: AWS security fundamentals, Python-based security automation, Zero Trust Architecture
  • Tools: Burp Suite, OWASP crAPI, Atomic Red Team, Python
  • Governance & Risk: NIST SP 800-171, ISO 31000 Risk Management

Professional Training & Labs

The Ultimate Cybersecurity Awareness Bundle – CodeRed (70+ hours, 18 courses, labs-based)

  • SOC & Blue Team Operations: SOC workflows, alert analysis, incident handling, and defensive monitoring
  • Red Team & Offensive Security: Attack methodologies, exploitation techniques, and adversary simulation
  • Web & API Penetration Testing: Advanced Burp Suite usage, OWASP Top 10, OWASP API Top 10 (crAPI)
  • Adversary Emulation: Atomic Red Team to simulate real-world attack techniques and validate detections
  • Cybersecurity Attack Lab Design: Built and configured safe penetration testing and attack simulation labs
  • AI & Data Science for Cybersecurity: Machine learning for digital forensics, AI-assisted vulnerability discovery
  • Generative AI for Cybersecurity: Threat simulation, security analysis, and defensive research use cases
  • Security Automation in AWS with Python: Automated defensive and offensive cloud security tasks
  • Zero Trust & Security Architecture: Enterprise security design and access control principles
  • OSINT & Dark Web Intelligence: Deep/Dark web analysis and threat intelligence gathering
  • Risk Management & Compliance: ISO 31000 risk frameworks and NIST SP 800-171 CUI protection

Academic Projects & Practical Exercises

  • Machine Learning for Digital Forensics: Applied ML techniques to analyze forensic data and support investigations
  • AI for Cybersecurity & Bug Bounty Hunting: Explored AI-driven vulnerability discovery and ethical hacking workflows
  • Atomic Red Team Adversary Emulation: Simulated attacker techniques to evaluate detection and response controls
  • Cybersecurity Attack Lab Design: Designed and tested controlled environments demonstrating common cyber-attacks