Skip to content
View adityavm19's full-sized avatar

Block or report adityavm19

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
adityavm19/README.md

Hi, I'm Aditya 👋

Security Engineering • GRC • Technology Risk • Cyber Assurance

I build practical security projects across control assurance, risk assessment, audit automation, cloud/IaC security and security tooling.

🛡️ GRC & Security Assurance Projects

The assurance projects use one shared fictional financial-services environment — Meridian Trust Financial Services (MTFS) — so the same risks, assets, evidence and underlying issues can be traced consistently across frameworks.

Synthetic project environment: MTFS, its people, systems, evidence, findings and management responses are fictional or synthetic. These repositories demonstrate methodology and are not presented as real client engagements.

Project Focus
Security Assurance Lab Shared MTFS environment, canonical taxonomy, evidence lineage and cross-framework traceability
ISO 27001 Audit Risk-based ISO/IEC 27001:2022 control assurance through findings, remediation and retest
Compliance Evidence Automation Python evidence collection, YAML rules, framework mapping, integrity, reports, tests and CI
Operational Resilience & ICT Risk UK operational resilience plus EEA DORA and third-party ICT risk
NIST CSF 2.0 Assessment Current / Target Profiles, organisational Tier and improvement roadmap
UK GDPR Security Assessment Article 32-led security/control assurance and supporting process reviews

Assurance lifecycle

flowchart LR
    A[Risk & Scope] --> B[Controls / Outcomes]
    B --> C[Evidence]
    C --> D[Testing]
    D --> E[Exceptions]
    E --> F[Findings / Gaps]
    F --> G[Remediation]
    G --> H[Retest]
Loading

Themes: risk-based scoping · design & operating effectiveness · sampling · evidence integrity · findings · remediation · analytics · cross-framework traceability


⚙️ Security Engineering & Automation

Project Focus
Bug Bounty Recon Configurable Python reconnaissance workflow for authorised security testing, including fast, full, stealth and API-focused modes
IaC Security Project Terraform / Infrastructure-as-Code project using separated backend, provider, main and variable definitions
Python automation   → repeatable security workflows
Terraform / IaC     → infrastructure-as-code practice
Recon automation    → structured discovery and probing
Evidence automation → technical evidence mapped to assurance outcomes

🔗 Connecting the technical and assurance layers

flowchart LR
    A[Security Engineering] --> B[Technical Evidence]
    B --> C[Control Validation]
    C --> D[Risk & Assurance]
    D --> E[Findings & Remediation]

    F[Python / Automation] --> B
    G[Cloud / IaC] --> A
    H[Recon Workflows] --> A
Loading

📌 Project index

Areas represented across this GitHub

Security Engineering · GRC · IT Audit · Technology Risk · Cyber Assurance · ISO 27001 · NIST CSF 2.0 · UK GDPR · DORA · Operational Resilience · Python · Audit Automation · Terraform · Infrastructure as Code

Pinned Loading

  1. bug-bounty-recon bug-bounty-recon Public

    Configurable Python reconnaissance workflow for authorised security testing, with fast, full, stealth and API-focused modes.

    Python

  2. security-assurance-lab security-assurance-lab Public

    Cross-framework security assurance project linking risks, controls, evidence, findings and remediation across ISO 27001, NIST CSF 2.0, UK GDPR and operational resilience.

    Python 1

  3. iso27001-audit-demo iso27001-audit-demo Public

    Synthetic ISO/IEC 27001:2022 internal audit and control-assurance project covering risk-based scope, evidence, testing, findings, remediation and retest.

    1

  4. nist-csf-maturity-demo nist-csf-maturity-demo Public

    Synthetic NIST CSF 2.0 programme assessment using Current/Target Profiles, organisational Tier assessment, evidence-backed gaps and improvement roadmap.

    Python 1

  5. operational-resilience-ict-risk-demo operational-resilience-ict-risk-demo Public

    Synthetic UK operational resilience and EEA DORA / third-party ICT risk project covering services, tolerances, dependencies, scenario testing and remediation.

  6. uk-gdpr-control-assessment-demo uk-gdpr-control-assessment-demo Public

    Synthetic UK GDPR security-control assurance project focused on Article 32, evidence-backed testing, supporting process reviews and remediation.

    Python