IMRAN KHALIQUE

Cybersecurity Operations LeadVulnerability ManagerDetection architectIdentity + Access Practitioner

Imran Khalique

About

From a young age, I was the kid who took apart toy RC cars to figure out how they worked. That curiosity grew into a knack for problem-solving — and the RC cars eventually gave way to computers. By 19, I'd gone from building PCs from scratch to cracking WEP, an outdated WiFi protocol now replaced by WPA.


Fastforward to present day: I started my career as an IT desktop engineer at Ernst & Young, supporting one of the largest professional-services environments in the world, then grew into IT operations and full-time security at Audax Group, a boutique private equity firm. Along the way I owned identity, endpoint, vulnerability management, awareness training, and digital risk protection — first as the sole IT engineer in the NYC office, then as the firm's go-to person for information security hardening, detection, architecture, response and much more.


Experience

A decade across IT/Security

Cybersecurity Operations Engineer/Administrator

Audax Group Private Equity — New York, NY

SEP 2022 – JAN 2026

Dedicated role to build and run the firm's enterprise security operations program. Owned vulnerability management, endpoint hardening, identity controls, cybersecurity awareness, digital risk protection and acted as the technical lead partnering with the firm's MSSP, pentest, and SaaS-security vendors.

Highlights
  • Reduced organizational attack surface by 60% by architecting the firm's enterprise Vulnerability Management (VM) program across Rapid7 InsightVM and Tenable, applying CIS Benchmark-aligned baselines, structured scan cadence, and remediation workflows integrated with change management processes.
  • Cut phishing click-rates 45% over 24 months as designer and administrator of the firm's Security Awareness and Training (SAT) program via KnowBe4; executing simulated phishing campaigns, new-hire onboarding, and leadership-facing behavioral metric reporting.
  • Achieved ~80-90% endpoint hardening compliance by establishing and enforcing a CIS Benchmark security baseline across the Windows endpoint estate via Microsoft Intune MDM and Group Policy Objects (GPOs), eliminating long-standing configuration drift and reducing exploitable attack vectors.
  • Built executive cyber-risk reporting framework aligned to NIST CSF functions - Identify, Protect, Detect, Respond, Recover - translating raw security signals into KPIs that gave leadership real-time visibility into threat posture, vulnerability exposure, and IR effectiveness for governance and budget decisions.
  • Designed and operated a Third-Party Risk Management (TPRM) program to vet, document, and stage approval for on-premises and SaaS application integrations; incorporating SOC 2 control mapping, data-handling validation, and risk scoring to reduce Shadow IT exposure and enforce the firm's information security standards at the point of vendor onboarding.
  • Led MSSP/MDR oversight and detection engineering tuning SIEM detection rules to reduce alert fatigue, deploying SOAR playbook initiatives, and managing log source integration lifecycles across the security stack driving MTTR to approximately 1 day and achieving a 75% reduction in non-actionable escalations.
  • Deployed SaaS Security Posture Management (SSPM) via Adaptive Shield across 20+ enterprise applications continuously monitoring for configuration drift, enforcing least-privilege access controls, managing the vendor relationship end-to-end, and remediating critical misconfigurations including controls relevant to the Microsoft Midnight Blizzard threat campaign.
  • Authored and maintained security governance documentation including Incident Response (IR) playbooks, access control policies, and operational SOPs ensuring controls were auditable, repeatable, and aligned to CIS and NIST CSF. Supported audit readiness by maintaining documented evidence of vulnerability remediation, SSPM configuration controls, and TPRM assessments across the firm's cybersecurity program.
  • Coordinated annual penetration testing engagements by defining scope, managing vendor coordination, triaging findings by risk severity, and driving remediation through to verified closure ensuring the firm's security posture was validated against real-world adversarial techniques.
  • Administered executive Digital Risk Protection (DRP) by leading the transition from ZeroFox to ReliaQuest DRP and deploying DeleteMe for PII removal - reducing the external attack surface and profiling risk for firm leadership through continuous monitoring of brand exposure, data broker presence, and open-source intelligence (OSINT) signals.

IT Operations Engineer/Administrator

Audax Group Private Equity — New York, NY

JAN 2020 – AUG 2022

Sole IT engineer for the New York office and primary technology partner for the firm's senior executives. Owned the Microsoft 365 and identity stack day to day, ran endpoint and network operations across multiple sites, and was the on-the-ground lead for the firm's 22nd floor build out and post-pandemic re-opening.

  • Supported and maintained enterprise IT infrastructure across Windows environments, Microsoft 365, mobile devices, and collaboration platforms, ensuring reliable day-to-day operations for onsite and remote employees.
  • Administered user accounts and endpoint management systems including Active Directory, Entra ID, Intune, Exchange Online, and Teams, improving provisioning efficiency and access management across the organization.
  • Supported Meraki firewalls, switches, and access points across wired and wireless infrastructure.
  • Led asset lifecycle, imaging, patching, and hardware refresh across multiple offices.
  • Delivered white-glove executive support, home-office networking, Meraki, conferencing, and secure remote access.

IT Desktop Engineer

Ernst & Young — New York, NY

JUL 2015 – DEC 2019

Frontline desktop and infrastructure engineer in one of the largest Big Four environments in the world. Worked across the Windows and Mac estate and partnered directly with the cybersecurity team on vulnerability scans, forensics, and pentesting.

  • Resolved Windows and macOS issues across local and remote offices, including Microsoft 365 migration, VMware, Citrix, SCCM, and Avecto.
  • Liaised with the cybersecurity team on vulnerability scans and forensic file retrieval for litigation support.
  • Assisted in ad-hoc penetration-testing engagements using tools such as Reaper and PWNED.
  • Led MDF/IDF closet server debugging and replacement projects.
  • Facilitated WTEY (Welcome to Ernst & Young) seminars, onboarding new hires onto firm hardware and technical resources.
  • Ran asset management against firm retention policies.
  • Maintained Crestron, Cisco VC, and Microsoft Surface Hub conference rooms.

Homelab

Case Studies

Selected security programs I built and ran

Remediation Automation

PowerShell Remediation Scripts

Automated CIS Benchmark and CVE remediation across the Windows endpoint estate

Stack: PowerShell, Windows Registry, CIS Benchmarks, Microsoft Intune, Group Policy

Role: Author and operator

Authored a suite of PowerShell remediation scripts to enforce CIS Benchmark controls and patch known CVE exposures across the firm's Windows environment. Deployed via Intune and Group Policy for consistent, repeatable, and auditable remediation at scale without manual intervention on individual endpoints. Scripts covered disabling SMBv1 (the protocol behind WannaCry and NotPetya), removing unnecessary IIS attack surface, remediating the MS13-098 certificate validation vulnerability across 32-bit and 64-bit registry hives.

Outcome: Controls deployed consistently across the endpoint estate, reducing remediation time from hours to minutes and producing audit-defensible evidence of control enforcement at scale.

Evidence SMBv1 script Remove IIS script MS13-098 script
Vuln Management

Enterprise Vulnerability Management

60% reduction in organizational attack surface

Stack: Rapid7 InsightVM, Tenable, CIS Benchmarks, Intune, GPO, PowerShell

Role: Lead architect and operator

Took a fragmented scanning footprint and rebuilt it into a unified vulnerability-management architecture aligned to CIS controls. Defined scan cadence and asset coverage, integrated findings into ticketing, and authored automated remediation in PowerShell and Python pushed via Intune and GPO so fixes actually reached endpoints.

Outcome: Sustained 60% reduction in attack surface, measurable repeatable patch compliance, and a defensible posture for SOC 2 and pentest review.

Awareness

Cybersecurity Awareness Program

45% drop in phishing click rate over 24 months

Stack: KnowBe4, Microsoft Defender, Mimecast

Role: Program owner

Built and ran the firm's awareness program from the ground up — simulated-phishing strategy, training cadence, role-based content, and reporting. Coordinated with HR for onboarding integration and partnered with leadership on metrics that mattered to them.

Outcome: 45% reduction in phishing click rates over 24 months and a measurably more security-aware workforce.

Detection & Response

MSSP / MDR Oversight & Detection Tuning

Higher-fidelity alerting, faster triage, fewer false positives

Stack: Reliaquest MDR, Exabeam SIEM, Microsoft Defender, CrowdStrike, Darktrace

Role: Internal lead for MSSP partnership and SIEM tuning

Acted as the firm's technical owner for the MSSP relationship. Reviewed escalations, validated severity and business impact, and partnered with Reliaquest on detection tuning and use-case development. Cut alert noise so escalations added measurable value.

Outcome:Reduced escalation rate by 75% over two years while driving MTTR to approximately one day - converting a high-volume, low-signal alert feed into a focused detection program that gave leadership credible, actionable incident reporting.

Executive Protection

Executive Digital Risk Protection

Reduced exposed PII and external profiling risk for firm leadership

Stack: DeleteMe, Reliaquest Digital Risk Protection, threat intel feeds

Role: Program owner for executive protection

Stood up an executive DRP program covering the firm's senior leaders. Continuously monitored and reported exposed PII via DeleteMe and monitored brand and exec exposure with Reliaquest DRP. Tied DRP findings into real-time CVE and IOC analysis to assess relevant exposure.

Outcome: Materially smaller external attack surface around firm executives and a documented, repeatable DRP workflow.

Cloud / SaaS

SaaS Security Posture Management

Continuous configuration hardening across SaaS platforms

Stack: Adaptive Shield, Microsoft Entra ID, Conditional Access, SSO/SAML

Role: Administrator

Brought Adaptive Shield in to monitor SaaS configuration drift across the firm's critical SaaS platforms. Worked with application owners to remediate misconfigurations and enforce baseline policies, while tightening identity and conditional access in Entra ID.

Outcome: Continuous SSPM coverage, fewer one-off misconfigurations, and a stronger identity boundary into SaaS.

Risk Reporting

Executive Cyber Risk Reporting Framework

Real-time visibility into threat, vulnerability, and response posture

Stack: Internal KPI model, Rapid7, Defender, KnowBe4, MSSP outputs

Role: Designer

Designed an executive-facing reporting framework so leadership could see the security program's posture without wading through tool dashboards. Translated raw signals into a small set of KPIs aligned to NIST CSF functions — identify, protect, detect, respond, recover.

Outcome: A reporting cadence leadership actually used for decision-making and budget conversations.

Pentesting

Annual Penetration Testing Program

End-to-end coordination, remediation, and verification

Stack: External pentest vendors, internal ticketing, Rapid7, Tenable

Role: Internal program lead

Owned the firm's annual pentest engagements from scoping through verification. Coordinated rules of engagement, evidence handling, finding triage, remediation planning, and re-test verification so findings actually closed instead of aging out.

Outcome: Transformed annual pentests from static reports into a tracked remediation and verification program with measurable follow-through.

Skills & Tools

Identity & Access Management
Microsoft Entra ID Active Directory Conditional Access SSO / SAML Intune MDM Privileged Access Management
Endpoint Security & Hardening
CrowdStrike Microsoft Defender GPO Hardening Full-Disk Encryption Sophos AV CIS Benchmarks
Vulnerability Management
Rapid7 InsightVM Tenable Nessus CIS Benchmarks CVE / IOC Analysis Pentest Oversight
Detection, Response & SIEM
Exabeam SIEM Reliaquest MDR Darktrace SOAR Automation SIEM Tuning Incident Response
Cloud & SaaS Security
Adaptive Shield (SSPM) Microsoft 365 Zscaler Mimecast SaaS Configuration Management
GRC & Risk Management
NIST CSF SOC 2 Third-Party Risk (TPRM) KnowBe4 DeleteMe Digital Shadows / RQ DRP KPI Reporting
Scripting & Automation
PowerShell Python Microsoft Graph API

Education & Certifications

Bachelor of Arts

CUNY Queens College

CISSP

(ISC)² — Currently preparing for exam

IN PROGRESS · 2026
CompTIA Security+

Pearson VUE

May 2023 · Verify

Rapid7 InsightVM Certified

Rapid7

March 2022 · Verify

CompTIA A+

Pearson VUE

April 2015 · Verify

60%

Attack Surface Reduction

45%

Phishing Click-Rate Drop

80%

Endpoint Compliance

10+

Years IT & Security

Professional Feedback

Feedback from annual reviews

Contact

Location

New York, NY