Available for security roles & collaborations

Grace Smith — Portfolio /
SecurityEngineer&SOCAnalyst.

Building secure systems, investigating threats, and engineering resilient digital experiences — from SOC monitoring floors to forensic deep-dives.

13
Hands-on projects
23+
Certifications earned
Curiosity for security
scroll ↓
01 — About

Engineering trust into
every system.

I'm Grace — an aspiring security engineer and SOC analyst fascinated by the quiet space between signal and noise. I'm building my foundation in detection, incident response, and forensic tooling — one project, one packet capture, one CTF at a time.

My work lives at the intersection of defensive engineering, OSINT, and curious tinkering. I move with one principle: secure systems are made of careful details, repeated relentlessly.

Security Engineering
SOC Analysis
Incident Response
Forensic Tooling
OSINT & Cyber Defense
13
Hands-on projects
23+
Certifications
8
Job simulations
15+
Security tools
02 — Capabilities

A toolkit forged through
labs, CTFs and curiosity.

The tools and disciplines I actively work with as I grow into security engineering.

Security Monitoring & Threat Detection
Wireshark, CyberChef, Log Analysis, MITRE ATT&CK, VirusTotal, Malware Bazaar, ThreatFox
Incident Response & Digital Forensics
ExifTool, CyberChef, Audacity, Fcrackzip, Steghide
Network & System Security
Active Directory, TCP/IP, VLANs, ACLs, DNS, DHCP, SSH, OSPF, Packet Tracer
Scripting & Automation
Bash, Python — threat detection, OSINT automation, forensic tools
Email & Phishing Analysis
CyberChef, URL analysis, header inspection
Firewalls
FortiGate policy & traffic inspection
+ Always learning
Expanding into SIEM, cloud security & red teaming
03 — Selected Work

Projects that quietly
hold the line.

A selection of security tools, investigations, and labs I've shipped.

Identity & Access/01

Enterprise IAM Governance System

Designed a centralized Identity & Access Management framework for NovaTech Solutions — RBAC, MFA enforcement, JML lifecycle automation, JIT privileged access, and audit logging across cloud-hosted HR, Finance, and Engineering platforms.

RBACMFAZero TrustJML LifecycleAudit Logs
Threat Intelligence/02

SilverTerrier — Threat Actor Profile

TLP:WHITE intelligence report on the Nigerian BEC collective tracked as G0083 — 480+ actors, 81,300+ malware samples, mapped to MITRE ATT&CK with sourcing from Unit 42, CISA, and Interpol.

MITRE ATT&CKUnit 42OSINTCTI
Incident Response/03

Incident Analysis — Malware Execution

Full incident report on an IDS-triggered alert: malicious email attachment executed on a workstation. VirusTotal pivoting, C2 domain analysis, timeline reconstruction, and remediation recommendations.

VirusTotalIDSThreat IntelIR Playbook
Network Forensics/04

Network Forensics — Malware PCAP

Reverse-engineered an AsyncRAT infection from a PCAP: traced the VBScript dropper, decoded a PowerShell payload disguised as mdm.jpg, extracted the executable, and confirmed the family via SHA-256 lookup.

WiresharkCyberChefPowerShellVirusTotal
Digital Forensics/05

Audio Steganography Investigation

Scotland Yard scenario: recovered a deleted partition with PhotoRec, brute-forced a ZIP with fcrackzip + rockyou, extracted a steghide payload from audio, decoded Base58, and pulled GPS coords from a spectrogram.

SteghidePhotoRecfcrackzipAudacityCyberChef
Digital Forensics/06

Image Metadata Forensics

OPSEC-failure case study — extracted EXIF metadata with exiftool, recovered hidden comments and timestamps, then geo-located the suspect to Kathmandu via reverse image search.

ExifToolYandex RISOSINT
Human Risk/07

Phishing Awareness Campaign — Mastercard

Designed and ran a phishing simulation and awareness program as part of the Mastercard job simulation, measuring behavioral risk and crafting targeted training.

GoPhishAwarenessBehavioral Risk
Security Tooling/08

Security Toolkit (Python)

A collection of defensive utilities including a GPG-based cryptography app for symmetric and asymmetric encryption, key management, and secure file sharing — all wrapped in a Python interface.

PythonGnuPGOpenPGP
Infrastructure/09

Active Directory Lab

Deployed AD DS on Windows Server 2019 in VMware: configured DNS, DHCP, joined Windows 10 clients to smith.local, designed OUs, and enforced GPOs (wallpaper, control-panel lockdown, software install).

Windows ServerAD DSGPODNSVMware
IoT Security/10

Smart Home Automation (IoT)

Multi-zone IoT simulation chaining motion, smoke, and water-level sensors to security gates, sprinklers, sirens, and webcams — covering security, smoke detection, and smart irrigation.

Cisco Packet TracerIoTSensors
IoT Security/11

Hotel RFID Access System

Custom RFID-based door access system for a hotel: contactless authentication triggers lighting, HVAC, blinds, and webcam activation — modeling secure, auditable physical access.

RFIDIoTAccess Control
Python/12

Automated Inventory System

Python desktop app for a supermarket (TREATS) backed by a XAMPP database — staff sign-up/sign-in, stock management, and text-to-speech feedback across six dedicated windows.

PythonTkinterMySQLpyttsx3
Networking/13

UniConfig Networking

Multi-site enterprise network design and configuration — VLANs, routing, and inter-campus connectivity built and verified end-to-end.

CiscoVLANRoutingPacket Tracer
04 — Credentials

Certifications &
continuous learning.

A growing library of certifications, job simulations, and specialized training across security operations, forensics, threat intelligence, and OSINT.

Foundation
Google Cybersecurity Professional
Google / Coursera
View
Networking
Network+ (equivalent)
New Horizons
View
Foundation
Security+ (equivalent)
New Horizons
View
Programming
Python for Cybersecurity
Cybrary
View
OSINT
Introduction to OSINT
Cybrary
View
OSINT
OSINT Basics
Cybrary
View
OSINT
Introduction to Dark Web Operations
Cybrary
View
OSINT
Intro to the Dark Web
EC-Council
View
Forensics
Introduction to Digital Forensics
Cybrary
View
Network Analysis
Wireshark Basics
Cybrary
View
Detection
Endpoint Detection & Response
Cybrary
View
Vulnerability Mgmt
Qualys Vulnerability Management Detection & Response
Qualys
View
Threat Intel
Foundations of Operationalizing MITRE ATT&CK
AttackIQ
View
Threat Intel
Intermediate MITRE ATT&CK
AttackIQ
View
Red/Blue
Foundations of Purple Teaming
AttackIQ
View
GRC
Security Program Management & Oversight
Cybrary
View
Foundation
Introduction to Virtual Machines
Cybrary
View
Job Simulation
Cybersecurity Job Simulation
PwC (Forage)
View
Job Simulation
Cybersecurity Job Simulation
Deloitte (Forage)
View
Job Simulation
Cybersecurity Job Simulation
Mastercard (Forage)
View
Job Simulation
Cybersecurity Job Simulation
TATA (Forage)
View
Job Simulation
Cybersecurity Job Simulation
Datacom (Forage)
View
Job Simulation
Cybersecurity Job Simulation
Telstra (Forage)
View
Job Simulation
Legal Technology Job Simulation
DLA Piper (Forage)
View
05 — Journey

From first lab to
first responder.

Hands-on internships and virtual experience programs shaping my security foundation.

Jul 2025 — Sep 2025

Cybersecurity Virtual Experience Programs

Forage · Remote
  • PwC — Cyber Risk Assessment: identified missing controls, ran gap analysis, produced Test of Design & Operating Effectiveness docs, and delivered an executive summary.
  • Deloitte — Security Log Analysis: analyzed web server logs to detect suspicious activity and surface indicators of compromise.
  • Mastercard — Security Awareness: identified phishing threats and proposed targeted awareness training improvements.
  • Telstra — Incident Response: triaged malware, analyzed Spring4Shell-linked firewall logs, wrote a Python-based mitigation rule, and authored the postmortem.
  • Tata (TCS) — Cybersecurity Analyst: worked through an IAM engagement, applied IAM principles aligned to business objectives, and produced client-facing documentation.
  • Datacom — Cybersecurity Risk Analyst: investigated a simulated cyberattack, ran a full risk assessment, and delivered a remediation report.
Mar 2025 — Sep 2025

Cybersecurity Intern

New Horizons · Nigeria (On-site)
  • Configured TCP/IP networks, VLAN segmentation, and OSPF routing in lab-based enterprise simulations.
  • Assisted with Active Directory configuration and user policy management.
  • Performed firewall configuration and log inspection using FortiGate.
  • Developed Python scripts to automate basic security analysis tasks.
  • Completed structured training aligned with CompTIA Network+ and Security+ domains.
  • Practiced subnetting, routing fundamentals, firewall configuration, and access control concepts.
06 — Contact

Let's build something
secure together.

Open to security engineering roles, SOC opportunities, research collaborations, and speaking.