M.S. Cybersecurity
NYU Tandon School of Engineering
Expected Graduation: 2027About Me
IT Analyst / Team Lead specializing in identity and access management — Entra ID, Active Directory, CyberArk, and privileged access governance — alongside endpoint management with Intune and Jamf. I'm currently pursuing an M.S. in Cybersecurity at NYU Tandon, where I've been building hands-on cloud security projects, including an automated SOC pipeline on GCP that uses Gemini, VirusTotal, and live honeypot telemetry for AI-driven threat triage.
My goal is to move deeper into identity and access engineering — combining IAM expertise, automation, and security operations to build access models that scale safely.
Core Expertise
Infrastructure & Networks
Enterprise networking, data-center management, Active Directory administration, DNS/DHCP, and physical systems routing.
Endpoint Management
Microsoft Intune, unified endpoint policies, Group Policy Objects (GPOs), patch management, and hardware compliance auditing.
Cloud & DevOps Sec
Google Cloud Platform (GCP), Terraform infrastructure-as-code, Docker containers, and Cloudflare network routing/tunnels.
AI & Security Automation
LLM orchestration (Gemini API), n8n pipeline orchestration, automated triage playbooks, and threat intelligence ingestion.
Featured Security Projects
NevesSec: Autonomous AI-Powered SOC Analyst
Designed and deployed a 24/7 Security Operations Center pipeline in Google Cloud Platform. The system automatically ingests system logs, malicious URLs, and threat telemetry from live honeypots, forwarding them via webhooks to invoke a Gemini AI L2 Analyst agent in n8n.
The AI agent queries VirusTotal, performs automated threat audits, maps attacks to MITRE ATT&CK, blocks threat IPs in Palo Alto firewalls, and updates the custom SIEM dashboard. Reduces manual alert triage time by 85% and processes up to 100+ telemetry incidents daily.
mock-siem Up 24/7 (Port 8000)
mcp-server Up 24/7 (Port 8500)
threat-generator Up 24/7 (Port 8000)
[ACTION] Firewall IP blocking triggered. Alert RESOLVED.
Pipeline Architecture & How It Works
Interactively Trigger the Live AI Agent:
- Click Open Live Portal above to access your custom SIEM dashboard (
soar.jeannevesit.com). - Under the Indicator Triage tab, select an indicator type (URL, IP Address, or Command), paste a test threat value, and click Submit.
- Alternatively, switch to the Ad-hoc Audit tab, select Phishing Email, paste a suspicious email draft, and click Run AI Audit.
- Watch the Incident Alerts Queue list on the left—the alert will load, invoke the n8n webhook, run the Gemini agent, execute the VirusTotal check, trigger the firewall block, and change to RESOLVED automatically in 10-15 seconds!
Enterprise IAM Lifecycle Automation Toolkit
Developed and implemented a production-grade identity synchronization and user lifecycle automation engine using PowerShell, Active Directory Services, and Microsoft Graph API.
Automates employee provisioning and deprovisioning, scans Entra ID directory states for security compliance, logs access anomalies, and audits group memberships. Replaced manual access review spreadsheets with automated scripts, cutting user onboarding time by 90% and securing Active Directory hygiene.
[INFO] 14 new hires, 3 terminations detected.
[ACTION] Provisioning Entra ID accounts & M365 licenses...
[ACTION] Disabling terminated accounts & revoking sessions...
[REPORT] 0 unauthorized accounts found. Audit log pushed.
Professional Experience
IT Analyst / Team Lead
BTG Pactual • New York, NY
Serve as the primary escalation point for identity, endpoint, and access incidents globally. Administer Microsoft 365, Exchange Online, Teams, SharePoint, Intune, and Entra ID. Lead Autopilot provisioning, policy management, and compliance auditing. Oversee Palo Alto firewalls, GlobalProtect VPN, and Netskope CASB security controls. Manage privileged access via Senha Segura and Azure JIT.
Infrastructure Analyst
SPX Capital • New York, NY
Administered Google Workspace and Microsoft 365 tenants. Managed Intune and Jamf MDM environments for a hybrid Windows/macOS fleet. Maintained inventory compliance logs and enforced least-privilege lifecycle provisioning.
Technology Analyst
Carnegie Hall • New York, NY
Managed macOS/Windows endpoints using Jamf Pro and Intune. Administered hybrid Active Directory synchronizations, OUs, and Group Policies. Secured access control structures using CyberArk PAM, Zscaler secure web gateways, and Barracuda WAF policies.
Monitoring Analyst
Neogrid • Porto Alegre, Brazil
Monitored end-to-end data pipeline integrity, ran Oracle SQL troubleshooting queries, tracked incidents in Jira, and built telemetry dashboards using Grafana.
Certifications & Credentials
Featured Security & Identity
Microsoft SC-300
Identity and Access Administrator Associate
Microsoft • Issued June 2024Okta Certified Professional
Okta Identity Governance & Directory Integration
Okta • Issued June 2024CompTIA CySA+
Cybersecurity Analyst (CS0-004 Exam)
Verification Code: f51bdd56a93a4bf2a0c0cbc14ceceaeb • Issued July 2026CompTIA CSAP
Security Analytics Professional (Security+ / CySA+ Stackable)
Candidate ID: COMP001022998913 • Issued July 2026CompTIA Security+
Core Security Operations & Threat Management
Verification Code: 2d1522ca3e9248cebfeba34447d34898 • Issued March 2026Cisco CCNA
Enterprise Routing & Switching Solutions
Credential ID: 7c6391b3-c02d-455d-acc4-e1e096c262e8 • Valid to Oct 2028Systems, Automation & Foundations
Microsoft MD-102
Endpoint Administrator Associate
Microsoft • Issued June 2024LPI Linux Essentials
Linux System Administration
Issued June 2020Google IT Automation
Python Scripting & Git Version Control
Issued January 2022MTA: Database Fundamentals
SQL Server & Relational Databases
Microsoft • Issued 2020Google Data Analytics
Data Analytics Professional Certificate
Issued March 2022Google IT Support
Network & Operating Systems Admin
Issued August 2020Celonis Foundations
Process Mining & System Telemetry
Issued January 2022