From a young age, I was the kid who took apart toy RC cars to figure out how they worked. That curiosity grew into a knack for problem-solving — and the RC cars eventually gave way to computers. By 19, I'd gone from building PCs from scratch to cracking WEP, an outdated WiFi protocol now replaced by WPA.
Fastforward to present day: I started my career as an IT desktop engineer at Ernst & Young, supporting one of the largest professional-services environments in the world, then grew into IT operations and full-time security at Audax Group, a boutique private equity firm. Along the way I owned identity, endpoint, vulnerability management, awareness training, and digital risk protection — first as the sole IT engineer in the NYC office, then as the firm's go-to person for information security hardening, detection, architecture, response and much more.
A decade across IT/Security
Audax Group Private Equity — New York, NY
Dedicated role to build and run the firm's enterprise security operations program. Owned vulnerability management, endpoint hardening, identity controls, cybersecurity awareness, digital risk protection and acted as the technical lead partnering with the firm's MSSP, pentest, and SaaS-security vendors.
Audax Group Private Equity — New York, NY
Sole IT engineer for the New York office and primary technology partner for the firm's senior executives. Owned the Microsoft 365 and identity stack day to day, ran endpoint and network operations across multiple sites, and was the on-the-ground lead for the firm's 22nd floor build out and post-pandemic re-opening.
Ernst & Young — New York, NY
Frontline desktop and infrastructure engineer in one of the largest Big Four environments in the world. Worked across the Windows and Mac estate and partnered directly with the cybersecurity team on vulnerability scans, forensics, and pentesting.
Spinning up Active Directory domain controller, joining client workstations, and seeding the environment with users, OUs, etc.
View screenshots & findingsSimulating an attack after a realistic misconfiguration.
View screenshots & findingsSelected security programs I built and ran
Automated CIS Benchmark and CVE remediation across the Windows endpoint estate
Authored a suite of PowerShell remediation scripts to enforce CIS Benchmark controls and patch known CVE exposures across the firm's Windows environment. Deployed via Intune and Group Policy for consistent, repeatable, and auditable remediation at scale without manual intervention on individual endpoints. Scripts covered disabling SMBv1 (the protocol behind WannaCry and NotPetya), removing unnecessary IIS attack surface, remediating the MS13-098 certificate validation vulnerability across 32-bit and 64-bit registry hives.
Outcome: Controls deployed consistently across the endpoint estate, reducing remediation time from hours to minutes and producing audit-defensible evidence of control enforcement at scale.
60% reduction in organizational attack surface
Took a fragmented scanning footprint and rebuilt it into a unified vulnerability-management architecture aligned to CIS controls. Defined scan cadence and asset coverage, integrated findings into ticketing, and authored automated remediation in PowerShell and Python pushed via Intune and GPO so fixes actually reached endpoints.
Outcome: Sustained 60% reduction in attack surface, measurable repeatable patch compliance, and a defensible posture for SOC 2 and pentest review.
45% drop in phishing click rate over 24 months
Built and ran the firm's awareness program from the ground up — simulated-phishing strategy, training cadence, role-based content, and reporting. Coordinated with HR for onboarding integration and partnered with leadership on metrics that mattered to them.
Outcome: 45% reduction in phishing click rates over 24 months and a measurably more security-aware workforce.
Higher-fidelity alerting, faster triage, fewer false positives
Acted as the firm's technical owner for the MSSP relationship. Reviewed escalations, validated severity and business impact, and partnered with Reliaquest on detection tuning and use-case development. Cut alert noise so escalations added measurable value.
Outcome:Reduced escalation rate by 75% over two years while driving MTTR to approximately one day - converting a high-volume, low-signal alert feed into a focused detection program that gave leadership credible, actionable incident reporting.
Reduced exposed PII and external profiling risk for firm leadership
Stood up an executive DRP program covering the firm's senior leaders. Continuously monitored and reported exposed PII via DeleteMe and monitored brand and exec exposure with Reliaquest DRP. Tied DRP findings into real-time CVE and IOC analysis to assess relevant exposure.
Outcome: Materially smaller external attack surface around firm executives and a documented, repeatable DRP workflow.
Continuous configuration hardening across SaaS platforms
Brought Adaptive Shield in to monitor SaaS configuration drift across the firm's critical SaaS platforms. Worked with application owners to remediate misconfigurations and enforce baseline policies, while tightening identity and conditional access in Entra ID.
Outcome: Continuous SSPM coverage, fewer one-off misconfigurations, and a stronger identity boundary into SaaS.
Real-time visibility into threat, vulnerability, and response posture
Designed an executive-facing reporting framework so leadership could see the security program's posture without wading through tool dashboards. Translated raw signals into a small set of KPIs aligned to NIST CSF functions — identify, protect, detect, respond, recover.
Outcome: A reporting cadence leadership actually used for decision-making and budget conversations.
End-to-end coordination, remediation, and verification
Owned the firm's annual pentest engagements from scoping through verification. Coordinated rules of engagement, evidence handling, finding triage, remediation planning, and re-test verification so findings actually closed instead of aging out.
Outcome: Transformed annual pentests from static reports into a tracked remediation and verification program with measurable follow-through.
Attack Surface Reduction
Phishing Click-Rate Drop
Endpoint Compliance
Years IT & Security
Feedback from annual reviews
"Imran has demonstrated exceptional growth this year, significantly expanding his expertise in vulnerability management, incident response, SIEM log management, and vendor management. Leading bi-weekly meetings with the RQ team, he has driven detection adjustments that increased the efficiency and effectiveness of our capabilities."
"Imran is incredibly efficient and productive with minimal oversight from management. He shares a sense of ownership of the NY office that allows him to prioritize tasks so office requests are not missed. He is resourceful and a self-starter — quick to identify issues and address them promptly."
"Imran is consistent and composed. He communicates clearly, handles feedback well, and maintains a high standard of discretion. His calm, even-keeled approach makes him easy to work with, especially in high-pressure situations."
"Imran takes a 'no task too small' attitude to requests that come his way. He is courteous and patient with any IT request, and on a day-to-day level he is always available and knowledgeable on ways to help."
New York, NY