CHINMAY DHARAP

  |    |  


WHO AM I?

"A Cyber Ninja: Sharp, Ambitious, Knowledge-Hungry, and Ready to Multitask My Way Through Any Security Challenge!"

My other hobbies include Standup Paddleboarding on the mighty Hudson, Ice Skating, Archery, Bowling, being a Home Barista, Photography and I am big fan of multi-monitor computer setups!


Note - This website serves as an extended version of my resume. For more detailed information about my background, I encourage you to explore it thoroughly. The content is carefully written in clear, straightforward language. To access the PDF version of my resume, please click here


CERTIFICATIONS


WORK EXPERIENCE

Cybersecurity Compliance Analyst

Cuddlytails Inc. | Jersey City, New JerseyApr 2025 - Present

What did I do in my tenure?

  • Reduced enterprise security risk by 25% by aligning 60+ internal policies with NIST SP 800-53, SP 800-171, and NIST CSF, strengthening compliance across IAM, MFA, Patch Management, and OT domains
  • Accelerated SOC 2 readiness and security review efficiency by 40% by conducting end-to-end technical control gap assessments and streamlining design documentation
  • Improved mobile application QA turnaround by 20% by identifying and reporting 25+ security bugs through manual and exploratory testing simulating real-world attacker behaviours
  • Increased regulatory alignment across security protocols by conducting vulnerability analysis and mapping 100% of findings to frameworks like NIST and ISO 27001

Cybersecurity Analyst Intern

Techincal Consulting & Research Inc. | Weston, ConnecticutSep 2024 - Mar 2025

What did I do in my tenure?

  • Contributed to AI/ML security knowledge base by co-authoring a peer-reviewed paper presented at ASEE-NE 2025, advancing best practices for AI-driven privacy, misinformation, and secure digital behavior
  • Increased cybersecurity awareness for 100+ small business participants by leading a Holiday Cybersecurity webinar through Virginia SBDC, covering common threat vectors and secure design principles
  • Produced 3 technical whitepapers improving organizational tool adoption by analysing Azure WAF, Zscaler, and NIST 800-171 implementations and recommending compliance improvements
  • Helped design AI security defenses for LLMs by simulating threats like prompt injection and data exfiltration, applying attacker-centric thinking to support runtime defense strategy development

Information Security Specialist

Stevens Inst of Technology | Hoboken, New JerseyJun 2023 - May 2024

How I got the job:

  • There was an attack on Stevens Community. One of the student's account was compromised and the attacker sent phishing emails from that account to alot of people at Stevnes
  • I also got two emails and I understood that it was phishing so I wrote a brief report about it and sent it to the CISO and VP of IT Division at stevens. Luckily, because of that report they understood the scale of the attack and it was immediately mitigated
  • Then two weeks later I got a call from CISO at Stevens and offered me this position

What did I do in my tenure?

  • Accelerated incident response by monitoring and investigating 45-50 security incidents daily. I utilized Microsoft Defender for Office 365 and Armis to identify threats and respond swiftly.
  • Ensured secure access for nearly 50,000 users by managing user access and authentication processes, leading to improved identity management. This was done through Okta, where I performed log analysis to investigate and resolve authentication-related incidents.
  • Enhanced phishing incident response by being the only Student Worker with Security Administrator (second-highest in org) privileges, enabling faster resolution of access control issues. I assisted in performing soft deletes and managing Access Control Lists (ACLs) during phishing campaigns using elevated access permissions.
  • Boosted security posture by 35% through optimizing vulnerability management. I led weekly vulnerability scans using Qualys and coordinated with the network team to prioritize and implement patches for critical vulnerabilities across on-prem servers and various campus departments.
  • Reduced user account compromises by 60% and improved network security by isolating malicious and compromised devices, which boosted overall security by 65%. I achieved this by contributing to the Protect Stevens Initiative through effective collaboration with security teams.
  • Maintained 100% endpoint compliance by implementing and enforcing endpoint security policies, resulting in enhanced device security. I used Microsoft Intune and Endpoint Central to ensure that Stevens-managed devices adhered to security policies such as Bitlocker compliance.
  • Streamlined cybersecurity operations and improved response time by authoring Incident Response Playbooks and Standard Operating Procedures (SOPs). I created comprehensive documentation that improved team efficiency during incidents.
  • Enhanced security team's ability to stay ahead of emerging threats by conducting research on threat actors and addressing security concerns in alignment with Protect Stevens protocols. I regularly analyzed industry reports and contributed insights to threat hunting efforts.
  • Strengthened cybersecurity defenses by participating in adversary emulation and threat hunting exercises, leading to the mitigation of critical risks. I worked closely with the team to identify and emulate potential attack vectors, refining the organization's defense strategies.

Awards & Recognition 🏆

  • Passion for Technology Graduate Award: Awarded from over 8,000 students across campus for exceptional contribution to Stevens Cybersecurity Team and as one of only 2 students to hold the prestigious Information Security Specialist role

References:

# Name Position Recommendation
1 Jeremy Livingston Chief Information Security Officer Letter of Recommendation  
2 Rafat Azad Cybersecurity Engineer Letter of Recommendation  

Security Architect and Lead Developer

A. P. Shah Institute of Technology | Thane, IndiaJun 2021 - May 2022

What did I do in my tenure?

  • Engineered a secure, CMS-based academic portal using PHP and MySQL, improving accessibility by 60% for 200+ users while ensuring robust protection of academic data and enabling future scalability through modular backend architecture.
  • Architected and implemented role-based access controls (RBAC) across three granular permission tiers, reducing access misconfigurations by 70% and enforcing least privilege principles at the application level to mitigate lateral movement risks.
  • Hardened the web application against common injection attacks by integrating input validation, output sanitization, and parameterized SQL queries, achieving a 90% reduction in the injection attack surface in alignment with OWASP secure coding practices.
  • Developed a custom authentication framework leveraging PHP-native password hashing algorithms and minimized direct DB privileges, reducing the likelihood of credential theft and brute-force attacks by 50% and supporting secure user session management.
  • Refactored the codebase into modular components and optimized SQL queries, reducing backend maintenance efforts by 50% and enabling faster feature deployment and easier security auditing for long-term system maintainability.
  • Led the migration to a CMS-backed content update model, streamlining faculty workflows and reducing manual update errors, while incorporating secure SDLC principles and CI-ready deployment processes to ensure safe and consistent releases.

PROJECTS

Physical Campus Doors Lockdown Automation


Oct 2023 – May 2024


Automated Network Address Comparision



Automated Vulernability Data Cleaning


Jul 2023 – Sep 2023



EDUCATION


Degree Major University
Master of Science (MS) Cybersecurity Stevens Institute of Technology, NJ
Bachelor of Engineering (BE) Information Technology University of Mumbai, India

PUBLICATIONS


  • Piliouras, T., & Crasto, S., & Dharap, C., & Yu, P. L., & Gupta, N. (2025, March), "Teaching Students Essential Survival Skills in the Age of Generative Artificial Intelligence Critical Thinking, Digital Literacy, and Cybersecurity Awareness" Paper presented at 2025 Northeast Section Conference, University of Bridgeport, Bridgeport, CT. 10.18260/1-2-1115.1153-54984  

AWARDS

  • Passion for Technology Graduate Award: Awarded from over 8,000 students across campus for exceptional contribution to Stevens Cybersecurity Team and as one of only 2 students to hold the prestigious Information Security Specialist role

  • Leading by Example Award: Honoured for exemplary service and commitment as a returning peer mentor for 2 consecutive semesters by guiding students through their academic & social integration, demonstrating a strong example for fellow mentors

  • Ultimate Team Player Award: Recognized as being one of 25 mentors from nearly 2,600 students, for mentoring incoming international masters students, to help them transition into Graduate Life at Stevens

VOLUNTEER EXPERIENCE

Hoboken Cove Community BoatHouse

  • Volunteer Since Jun, 2024

    HCCB is an all-volunteer based non-profit 501(c)(3) organization. It is New Jersey's Largest Free Paddling Program to provide free water sports (kayaking, Standup Paddleboarding) and access to local waterways for all to enjoy.

Information Technology Student Association, APSIT Thane

  • President May 2022
  • Secretary Sep 2021
  • Volunteer Jul 2020

    IT Students Association ( ITSA ) is the Student Body of the IT Department @ A. P. Shah Institute of Technology, works for the development of the department as well as the students by giving them opportunity to come forward and nurture themselves while working with ITSA.