Sohan Hossain
Security Analyst @ Bionical Solutions
About
I am a highly motivated Security Analyst with a strong foundation in cybersecurity, bolstered by hands-on experience in security operations, risk management, and data protection. Having earned a First Class Honours degree in Cyber Security from the University of Derby, I’ve developed a comprehensive understanding of industry standards such as GDPR, ISO 27001, and NIST.Throughout my academic and professional journey, I’ve gained practical experience through projects, internships, and virtual roles. I conducted thorough risk assessments, and vulnerability analyses, and implemented security policies that enhanced the organization’s overall security posture. My ability to identify critical vulnerabilities and collaborate with stakeholders on remediation strategies has been crucial in mitigating potential threats.I’m also skilled in penetration testing, having identified and remediated key vulnerabilities like SQL injection and anonymous FTP access during a project at the University of Derby. I thrive in dynamic environments, adapting to evolving security challenges while remaining committed to ensuring robust data protection and compliance.With certifications like the EC-Council’s Security Operations Centre (SOC) Analyst and a passion for ongoing learning, I am committed to continuously developing my technical expertise. I look forward to leveraging my skills to support organizations in protecting their critical assets and maintaining a resilient cybersecurity framework
United Kingdom
Derby
Computer Networking
Info Sec, Security Implementation, IT Security Policies, Metasploit, Nmap, Expert Determination, Operational Efficiency, Software Development Life Cycle (SDLC), Mitigation Strategies, Security Controls, Cyber-security, Access Management, Office 365, ISO Standards, IT Compliance, Threat Detection, Sentinel, Incident Response, Security Monitoring, Cyber Threat Hunting (CTH)
Experience

Security Analyst
· Spearheaded technical audits and documentation efforts to achieve and maintain ISO 27001 and Cyber Essentials certifications, ensuring 100% alignment with international security standards. Authored and enforced comprehensive corporate security policies—including Password, VPN, and BYOD to standardise security protocols and reduce human-centric risk factors. · Conducted end-to-end internal and external network penetration tests to identify critical infrastructure weaknesses and simulate real-world attack vectors. Directed the full lifecycle of vulnerability management, from initial discovery to validated remediation, significantly reducing the organization’s attack surface. · Achieved a 43% increase in security posture by implementing rigorous system hardening across some corporate devices. Developed and deployed both manual configuration and PowerShell scripts to automate CIS and Microsoft Benchmark configurations, ensuring consistent, scalable, and error-free security baselines.

Cyber Security Specialist
PwC US (Virtual Internship)
Conducted Risk Assessments to identify potential threats to business processes and IT systems, client advisory scenarios. Reviewed Software Development Lifecycle (SDLC) processes and developed targeted walkthrough questions to assess project compliance and control effectiveness. Created a Controls Testing Summary Presentation, synthesizing audit findings and presenting control gaps and recommendations to client audience.

Incident Analyst
Deloitte Australia (Virtual Internship)
Conducted detailed analysis of web activity logs to identify unusual patterns and potential security threats. Assisted a high-profile client during a cyber security breach, leveraging insights to mitigate risks and secure sensitive data. Responded to inquiries regarding suspicious user activity, enhancing the client's overall cyber threat detection capabilities.

Cyber Security Analyst
Tata Consultancy Services (Virtual Internship)
Collaborated on Identity and Access Management (IAM) initiatives, resulting in a 20% increase in operational efficiency. Developed and maintained comprehensive IAM documentation, leading to a 25% improvement in compliance adherence. Translated complex technical information for stakeholders, facilitating better collaboration and more informed decision-making.

Security Analyst
Conducted thorough Risk Assessments and Vulnerability Analyses, identifying and mitigating security threats within company infrastructure Developed Security Policies and Plans, including password, data usage, VPN policies, Business Continuity Plans, and incident response plans to establish clear guidelines for employees and stakeholders and promote adherence to best security practices Implemented security awareness programs, educating employees on phishing, strong passwords, and cybersecurity best practices Execute the implementation of information security principles and processes, ensuring the safeguarding of sensitive data.

Penetration Tester
Conducted comprehensive penetration testing using Nmap and Metasploit to perform scanning, enumeration, and exploitation of potential vulnerabilities. Employed SQL injection techniques to assess database security and identify potential points of vulnerability. Identified critical vulnerabilities such as anonymous FTP access, lack of HTTPS encryption, easy access to the database using SQL injection, and open remote desktop services. Collaborated with stakeholders to implement remediation strategies, including the disabling of anonymous FTP access, implementing VPN for remote connection and the enforcement of stronger password policies.
Education

Cyber Security
Key Modules: Ethical Hacking, Databases, Risk and Vulnerability Assessment, Security Architecture and Future Trends, Security Management, Communication and Security Protocols, Digital Forensic Investigation. Skills Earned: Hands on experience of Penetration testing and report writing. Conducted thorough third-party risk assessments, identifying and addressing potential vulnerabilities, resulting in enhanced security posture and resilience. Developed and implemented information security policies and procedures, ensuring compliance with industry regulations and standards (ISO 27001, NIST, GDPR etc). Accomplished Real time project using Matlab, Python, C#, Encase, Kali Linux.
Sohan Hossain's Contact Information
Phone
Find the Right Leads
Find Verified Contact Data
What LeadContact does well
Find verified emails, phone numbers, and decision-makers with 98% accuracy.
Find Leads
Find the right people by company, role, industry, location, and more.
925M+ professional profiles

Find Emails
Access verified email addresses for your target contacts.
657M+ emails

Find Phone Numbers
Get cross-validated phone data from multiple top sources.
239M+ phone numbers

More Accurate. Lower Cost.
Find contact data in 1 tool with 98% accuracy
LeadContact integrates leading enrichment tools to deliver more accurate contact data—without paying for each one.
Great conversations start with the right contact.
It’s time to find yours.


