Projects

Hands-on security work, outside the day job.

Two ongoing projects that push from systems integration into offensive and defensive security practice.

PROJECT 01 — CLOUD SECURITY

Build, Secure, and Protect a Web Application

A cloud application hosting a personal cyber blog, built and hardened end-to-end on Microsoft Azure — covering cloud architecture, networking, cryptography, and network security.

  • Built an Azure Web App and deployed a container to it, with a custom application design.
  • Secured the app with a Key Vault; created and analyzed a self-signed certificate against a trusted one.
  • Protected the app with a Web Application Firewall — configured custom rule sets and remediated Security Center recommendations.
PROJECT 02 — OFFENSIVE SECURITY

Exploit Vulnerabilities — Web App, Linux & Windows Servers (CTF)

A capture-the-flag exercise attacking a fictional organization across three tiers: its web application, Linux servers, and Windows servers.

  • Web app: applied offensive security techniques to identify and exploit vulnerabilities and capture flags.
  • Linux servers: used Nessus for network/vulnerability scanning and Metasploit to gain access and retrieve flags.
  • Windows servers: used Nmap for reconnaissance to find open ports and services, then gained access to capture flags.
Field work

Systems integration, at scale

Outside of formal security projects, day-to-day work is its own kind of applied systems security: designing and integrating CCTV, access control, intercom, and PA/CIS systems across active NYC Transit stations and depots, and standing up enterprise networks with redundant backbones. See the resume for the full project list.

SheetProjects — 03/03
Drawn byM. Berghli
Rev2026.07
ScaleN/A