VulNerd // Spring 2026 · FIU
A web app that turns raw Nessus scan exports into graded security report cards in plain English — with prioritized remediation steps and a built-in AI assistant that has full context on the uploaded scan.
- Led a 5-person team building VulNerd — raw Nessus exports in, graded plain-English report cards out, with prioritized remediation and an AI chat assistant scoped to the uploaded scan (Python, Google Gemini).
- Delivered industry-specific compliance dashboards mapping findings to HIPAA, PCI DSS, NIST 800-53, FERPA, and CIS Controls, plus breach cost analysis and emailed PDF report cards for non-technical stakeholders.
- Architected and secured the test environment: DVWA in Docker on a Raspberry Pi 5 with MariaDB, every vulnerability class exploitable for team testing, behind Tailscale VPN with zero public exposure.
- Ran Nessus scans (Basic Network, Credentialed, Web App, Advanced Dynamic) and performed manual red team testing across 8 attack modules including SQLi, XSS, and Command Injection.
- Surfaced the headline finding: ~40% of findings — including 3 of 4 critical vulnerabilities — through manual testing that automated scans missed.