$ whoami
Davindernain Singh Sehgal
Cybersecurity professional | governance, risk and compliance | incident response | security operations | third-party risk
Sole cybersecurity owner for the City of Boston's Boston Public Library: the Central Library, 25 branches and a multi-institution network, reporting directly to the CTO. U.S. municipal-government experience, plus non-profit, startup and consulting work across the USA and India. MS in cybersecurity from Northeastern University, Boston.
resume: GRC and leadership resume: security operations complete CV

$ cat impact.log
$ cat context.txt
The Boston Public Library is not a small-town library. It is a department of the City of Boston and the first large free municipal library in the United States. It also serves the whole state of Massachusetts, runs the state's digital archive for hundreds of libraries and museums, and includes a business innovation center, a national-class map center, rare books and teen makerspaces.
For scale: the largest library in India, the National Library of India in Kolkata, reports roughly 2.2 to 2.5 million books and records. The Boston Public Library's collections, counting maps, prints, manuscripts and more, run past 23 million items.
$ cat education.txt
NUMaster of Science in Cybersecurity
Northeastern University, Boston, USA
Coursework: Software Vulnerabilities and Security, Security Risk Assessment and Audits, Network Security Practices, Security Governance, Risk and Compliance (Cyberlaw), Digital Forensics, Decision Making in Critical Infrastructure.
UMBachelor of Science in Computer Science
University of Mumbai, Mumbai, India
Coursework: Data Structures, Cloud Computing, Ethical Hacking, Information Retrieval.
$ cat experience.log
BPLIT Cybersecurity Analyst and BPL Cybersecurity Officer
City of Boston, Boston Public Library (BPL), Boston, USA
About the organization: the Boston Public Library is the first large free municipal library in the U.S. (1848), with 26 locations, nearly 4 million visits a year, more than 23 million items and a statewide role. What that means, and how it compares with libraries in India.
Sole cybersecurity resource for the City of Boston's Boston Public Library system: the Central Library, all 25 branch locations, and the Metropolitan Boston Library Network (MBLN), a shared network and staffing consortium linking additional public, school, and college libraries across the region. Acts as the bridge between the City of Boston's central Cybersecurity Operations team and BPL leadership, owning security strategy end-to-end with no dedicated security team beneath or above this role at the library level.
highlights
- Held Cybersecurity Officer responsibilities for the library system, reporting directly to the CTO as the single point of accountability for security strategy, incident response, governance, auditing, risk, and cybersecurity metrics reporting across 25+ locations and the Metropolitan Boston Library Network (MBLN), a multi-institution network.
- Secured a $250,000 (about ₹2.4 Cr) FCC Cybersecurity Pilot Program grant by leading research, documentation, and the application with multiple departments, funding network security infrastructure upgrades.
- Established the security evaluation framework for new vendors, products, and acquisitions, and led third-party risk assessments with multiple departments against NIST and CISA guidance, assessing controls, compliance, data protection, cost, and business value before purchase or implementation.
show the other 14 by themeshow fewer
Ownership and accountability
- Coordinated with the City of Boston Cybersecurity Operations team to research, select, and document security best practices, representing BPL in city-level security governance.
- Advised IT leadership on emerging threats, vulnerabilities, and countermeasures, shaping technology decisions before production; tracked the threat landscape through security professional organizations, listservs, forums, and threat intelligence.
Funding, governance and third-party risk
- Documented information security standards and policies aligned with NIST and CISA, guiding procurement, design, maintenance, and retirement decisions across the technology lifecycle; analyzed processes for security risk with the Technology Process Improvement Owner and recommended procedural changes.
Incident response
- Directed incident response for a high monthly volume of security incidents, triaging alerts daily and leading investigation, containment, and remediation across Network, Server, Application, Help Desk, and A/V teams; liaised with law enforcement and City of Boston counterparts on significant incidents.
- Built scenario-specific incident response strategies and playbooks defining the response for each type of incident, along with playbooks for security operations, access management, and endpoint security, standardizing procedures and improving organizational readiness.
Identity, vulnerability management and perimeter defense
- Led organization-wide rollout of MFA and passwordless authentication (Microsoft Authenticator, passkeys), achieving 100% organizational MFA coverage through user guides, training, and enforced controls.
- Led a multi-year initiative to decommission and upgrade end-of-life (EOL) servers and software, bringing 100+ systems to current security standards and materially reducing the attack surface.
- Deployed and tuned a Web Application Firewall (WAF) protecting public-facing infrastructure, reducing malicious bot traffic and automated attack attempts by 70%.
- Led internal vulnerability assessments and penetration testing (Metasploit, Nmap, Burp Suite), identifying critical vulnerabilities in public and staff-facing systems and driving remediation through targeted best-practice fixes.
Security operations and security by design
- Managed core security systems (IDS/IPS, anti-malware, firewalls, encryption) and enterprise asset and license inventories with the Help Desk Manager; designed separate risk-based configurations for public-access versus staff computers across dozens of locations.
- Worked with Server, Network, and Web Services teams to build security into system installation, configuration, and maintenance, and acted as point of contact for external vendors on issues beyond internal scope.
Resilience
- Directed business continuity and disaster recovery planning with the Server and Network teams, documenting, maintaining, and testing recovery procedures.
Awareness and community
- Ran the staff security awareness program with recurring phishing simulations that increased phishing detection and reporting rates by 90% over 8 months; developed training on authentication, phishing, and account protection.
- Designed and taught public cybersecurity literacy sessions with community learning programs for patrons of all ages across BPL branches.
VBBCybersecurity Associate (volunteer)
Village Book Builders (non-profit), Boston, USA
- Spearheaded the development and implementation of security policies using the ISO 27001/27002 compliance framework.
- Conducted in-depth risk assessments with cross-functional teams, identifying potential threats and proposing mitigation strategies that reduced projected impact costs by over $130,000 (about ₹1.25 Cr).
- Led the development and optimization of custom-tailored incident response plans for ransomware attacks and emerging security threats, minimizing potential damage.
show 2 moreshow fewer
- Customized Standard Operating Procedures (SOPs) for seamless adherence to compliance standards throughout the organization.
- Organized company-wide IT risk training sessions, including presentations and quizzes, fostering a security-conscious culture for full-time and part-time employees.
CFNInformation Security Capstone (operational risk)
Commonwealth Financial Network, Waltham, USA
- Built a streamlined operational risk registration and monitoring system using Trello and Jira, improving coordination across 7+ departments.
- Used Agile methodology to meet team sprint deadlines every 3 weeks, ensuring timely completion of project deliverables.
- Authored and presented educational materials and technical documentation for stakeholder training and adoption.
- Used Power BI, Excel, and Microsoft Forms to register and present operational risks statistically, reducing overall operational risk.
YDBIT Security Intern
YourDigitalBro Pvt Ltd, Mumbai, India
- Implemented basic security tooling to monitor and analyze security events, increasing proactive incident detection and response capability by 35%.
- Deployed firewalls and IDS/IPS for increased visibility and security, reducing unauthorized access attempts by 50%.
- Administered infosec policies safeguarding PII for 550+ clients monthly.
show 3 moreshow fewer
- Tracked security incidents for 635 accounts, addressing compromised accounts, email threats, and user errors.
- Configured endpoint security with Intune MDM, secure remote access via VPN, and OS and software hardening against known CVEs.
- Delivered security awareness training for employees, reducing phishing incidents and malware infections by 25%.
IT Consultant (freelance)
Mumbai, India
- Assessed client technical needs and recommended appropriate hardware and software; provided on-site and remote support.
- Helped 87 clients implement strong security controls, including anti-virus, anti-malware, and data encryption.
- Achieved a 95% success rate resolving hardware and software issues within 24 hours, minimizing downtime.
show 2 moreshow fewer
- Educated 50+ clients on strong passwords, two-factor authentication, and security best practices; trained non-technical individuals to recognize phishing and malware.
- Ran IT training sessions, kept support tickets, and escalated issues beyond the scope of support to third-party associates.
$ ls projects/
Graduate work at Northeastern University, plus a self-study threat model. Click a project to read more.
ir-playbookNIST IR, MITRE ATT&CK
While creating this incident response playbook, I considered three scenarios: unauthorized access to data, a SQL injection attack, and a leaked meeting link (for example, a link to an important shareholder Zoom meeting).
I followed the NIST incident response framework and researched the MITRE ATT&CK framework in depth to complete the playbook.
achievement: mapped over 92% of attack techniques and reduced response time by 15 days per stage
passive-reconOSINT, 8+ tools
I carried out extensive passive reconnaissance of two online merchandise stores, TheSouledStore and Youthiyapa.com. The goal was to assess their cybersecurity posture and identify vulnerabilities and weaknesses that could put their operations and customers at risk.
I wrote a research paper outlining the methodology and findings. Using advanced open-source intelligence (OSINT) techniques and 8+ tools, including SpiderFoot, Maltego, Shodan and Dig, I documented open ports, DNS records, Common Vulnerabilities and Exposures (CVEs) and publicly available data about both sites. This gave a clear picture of each site's attack surface and the exposed areas an attacker could exploit.
The paper identifies specific weaknesses and exploitable vulnerabilities, and offers actionable recommendations to help the site owners strengthen their defenses and protect customer information.
risk-assessmentNIST, HGA case study
This project was a thorough risk assessment using both qualitative and quantitative analysis, focused on improving security measures and compliance with federal regulations. It was based on a detailed review of the HGA case study and the NIST framework.
I evaluated the organization's security controls across Management, Operations and Technical (M-O-T) aspects, identifying strengths and areas for improvement, and applied attack prevention and response techniques to develop a security strategy that mitigates potential threats.
Compliance with federal regulations was a primary consideration throughout. I made sure the security measures and risk management practices aligned with relevant regulatory requirements. The assessment gives a holistic view of the organization's security posture, with recommendations to strengthen its defenses, safeguard assets and improve resilience.
achievement: curated threat-vulnerability pairs to assess attack likelihood and documented the potential impact on assets valued at over $600,000
device-forensicsFTK Imager, Autopsy
I conducted forensic investigations on multiple Windows machines and mobile devices with FTK Imager and Autopsy. The goal was to examine files created, opened and stored across four systems and various external devices, and uncover evidence for four scenarios: an insider threat, employee harassment through email, a malware infection, and other potential security incidents.
I applied advanced forensic techniques to extract and preserve evidence, and followed chain of custody strictly so the evidence would be admissible in legal proceedings.
Insider threat: I examined user activity, file access patterns and system logs to find malicious or unauthorized actions. Email harassment: I analyzed emails, attachments and metadata to determine the source and nature of the harassment. Malware infection: I analyzed system artifacts and network logs to trace where the malware came from, how it spread and how far it reached. Other incidents: I looked across the four systems and external devices for suspicious or anomalous activity.
For each scenario I delivered a report with findings, analysis and recommendations, giving the organization what it needs for informed decisions, possible legal action and stronger security measures.
Because of policy restrictions, I can't share the full documents. This is the conclusion page from one of the case studies.

ransomware-grcGRC research paper
This technical paper investigates how to implement a strong governance, risk and compliance (GRC) response to malware, with an emphasis on ransomware. The goal was to develop effective strategies for both technical and non-technical incident scenarios.
I researched how ransomware attacks work in order to build efficient, tailored responses that reduce the impact of an incident. Through that research I refined five or more ransomware prevention methods and incident response strategies, designed to prevent attacks and to keep the business running if one happens.
The paper takes a holistic approach to ransomware by integrating GRC best practices, with insights and recommendations for organizations that want to strengthen their defenses, protect their assets and improve risk management and compliance.
ids-ips-labpfSense, Snort, zero trust
In this project I set up and configured a pfSense firewall and the Snort intrusion detection system (IDS) to enforce zero-trust policies across two local networks. Under zero trust, no device or user gets implicit trust, and all traffic is checked before it can reach network resources.
I used pfSense and Snort to inspect and analyze network packets in real time, which made it possible to spot unusual activity and potential threats quickly. I also analyzed Nmap scans and reviewed network traffic signatures to find vulnerabilities and potential attack vectors and close them before they could be used against the network.
Because of my university's policies, I can't share the entire project or its rules, so I'm sharing the results at the end of each lab to show what I learned.






forensics-papernetwork and mobile forensics
I wrote an extensive research paper on digital forensics, with an emphasis on network and mobile device forensics. It gives an overview of the methods, tools and techniques used in these branches and why they matter in fighting cyber threats.
The project covered three major branches of digital forensics, with strategic improvements aimed at making them more effective at responding to changing cyberspace challenges and supporting investigations.
I also developed and presented a strategic guide for cyber investigators, covering best practices and methods for carrying out digital forensics. After the guide was put in place, new investigators handled later forensics investigations 20% more effectively.
result: 20% improvement in new investigators' ability to handle forensics investigations
threat-modelSTRIDE, NIST 800-53, MITRE ATT&CK
A self-study threat model of a typical multi-branch public library network. It covers the architecture and trust boundaries, a ranked register of fifteen threats mapped to ATT&CK techniques and NIST controls, extra factors from a large library system's wider footprint, and a 30, 90 and later action plan.
This is an illustrative reference model and a learning exercise. It does not describe any real organization's environment.
$ cat skills.conf
- governance
- Risk assessments and audits, third-party and vendor risk, policy and standards, business continuity and disaster recovery, security metrics reporting.
- frameworks
- NIST 800-30 and 800-53, CISA, ISO 27001, MITRE ATT&CK, OWASP, GDPR, HIPAA, HITRUST, PCI DSS, SOC 1, SOX, COBIT, NICE.
- operations
- Incident response and playbooks, threat detection, vulnerability management, penetration testing, WAF, IDS/IPS, firewalls, digital forensics, OSINT.
- identity
- MFA and passwordless authentication, Microsoft Entra ID, Microsoft Authenticator, passkeys.
- tools
- Microsoft Defender, SentinelOne, Splunk, QRadar, Nmap, Wireshark, Metasploit, Burp Suite, Nikto, pfSense, Snort, FTK Imager, Autopsy, SpiderFoot, Maltego, Shodan, AWS.
- languages
- Python, SQL, Java, Bash.
- studying (india)
- Currently studying the regulations that apply to the Indian market: the Digital Personal Data Protection (DPDP) Act, RBI cybersecurity and IT governance guidelines for banks, CERT-In incident reporting directions, and the SEBI cybersecurity framework.
$ cat credentials.txt
- CISSP in progress: self-study completed across all 8 domains.
- Member of (ISC)², SANS and MS-ISAC.
- Hands-on programs: TryHackMe Jr. SOC Analyst (Level 1), AIG Shields Up (incident response team lead), Mastercard (phishing campaign analysis).
- Languages: English, Hindi, Marathi, Punjabi.
$ ./contact.sh