VulNerd // Spring 2026 · FIU
AI-powered vulnerability analysis & compliance reporting (NIST 800-53, PCI-DSS). I led 5 teammates, owned the cloud / lab architecture, and ran the testing methodology.
- Built lab environment supporting an AI tool for vulnerability analysis & compliance reporting against NIST 800-53 and PCI-DSS.
- Deployed DVWA in Docker on a Raspberry Pi 5 with MariaDB at Security Level Low so every vuln class was fully exploitable for the team.
- Locked lab access behind Tailscale VPN — zero public exposure, team-only access enforced for the entire project lifecycle.
- Ran Nessus scans (Basic Network, Credentialed, Web App, Advanced Dynamic) and supported red-team testing across 8 modules: SQLi, XSS, Command Injection, and more.
- Surfaced the headline finding: ~40% of vulnerabilities — incl. 3 of 4 Criticals — were only caught manually, proving the layered approach over automation alone.